Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.447exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
21.497 exploits
Referência
CVE-2026-9573
itsourcecode Student Transcript Processing System index.php sql injection
33RISCO
abrir
Referência
CVE-2026-9572
GPAC MP4Box media.c Media_GetSample memory leak
33RISCO
abrir
Referência
CVE-2026-9567
GPAC MP4Box isom_intern.c MergeFragment null pointer dereference
33RISCO
abrir
Referência
CVE-2026-9566
teableio teable Sign-up LoginPage.tsx cross site scripting
33RISCO
abrir
ReferênciaVexDay Proof
LoudBlog 0.6.1 - 'parsedpage' Remote Code Execution
CVE-2008-0139webappsphp
Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to exec
28RISCO
abrir
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
CVE-2008-0166remotelinux
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISCO
abrir
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
CVE-2008-0166remotelinux
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISCO
abrir
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH (Ruby)
CVE-2008-0166remotelinux
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISCO
abrir
ReferênciaVexDay Proof
NetRisk 1.9.7 - Cross-Site Scripting / SQL Injection
CVE-2008-0185webappsphp
SQL injection vulnerability in index.php in NetRisk 1.9.7 and possibly earlier versions allows remote attackers to execu
23RISCO
abrir
Referência
CVE-2011-0519
SQL injection vulnerability in gallery.php in Gallarific PHP Photo Gallery script 2.1 and possibly other versions allows
23RISCO
abrir
Referência
CVE-2026-8785
projectworlds hospital-management-system-in-php GET Parameter update_info.php getAllPatientDetail sql injection
33RISCO
abrir
ReferênciaVexDay Proof
QuickTime Player 7.3.1.70 - 'RTSP' Remote Buffer Overflow
CVE-2008-0234remotewindows
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allo
28RISCO
abrir
ReferênciaVexDay Proof
StreamAudio ChainCast ProxyManager - 'ccpm_0237.dll' Remote Buffer Overflow
CVE-2008-0248remotewindows
Buffer overflow in an ActiveX control in ccpm_0237.dll for StreamAudio ChainCast ProxyManager allows remote attackers to
28RISCO
abrir
ReferênciaVexDay Proof
Microsoft Visual InterDev 6.0 SP6 - '.sln' Local Buffer Overflow
CVE-2008-0250localwindows
Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a St
28RISCO
abrir
ReferênciaVexDay Proof
Xforum 1.4 - 'topic' SQL Injection
CVE-2008-0279webappsphp
SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitr
23RISCO
abrir
Referência
CVE-2026-8254
Devs Palace ERP Online sales_save cross site scripting
33RISCO
abrir
ReferênciaVexDay Proof
DomPHP 0.81 - Remote Add Administrator
CVE-2008-0282webappsphp
SQL injection vulnerability in welcome/inscription.php in DomPHP 0.81 and earlier allows remote attackers to execute arb
23RISCO
abrir
Referência
CVE-2011-0642
Cross-site request forgery (CSRF) vulnerability in news/admin.php in N-13 News 3.4, 3.7, and 4.0 allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
ImageAlbum 2.0.0b2 - 'id' SQL Injection
CVE-2008-0288webappsphp
Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir
ReferênciaVexDay Proof
DigitalHive 2.0 RC2 - 'user_id' SQL Injection
CVE-2008-0290webappsphp
Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitra
23RISCO
abrir
Referência
CVE-2011-0643
Cross-site request forgery (CSRF) vulnerability in admin/conf_users_edit.php in PHP Link Directory (phpLD) 4.1.0 allows
23RISCO
abrir
ReferênciaVexDay Proof
RichStrong CMS - 'cat' SQL Injection
CVE-2008-0291webappsasp
SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir
ReferênciaVexDay Proof
FaScript FaPersian Petition - SQL Injection
CVE-2008-0325webappsphp
SQL injection vulnerability in show.php in FaScript FaPersian Petition allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
FaScript FaPersianHack 1.0 - SQL Injection
CVE-2008-0326webappsphp
SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
Aria 0.99-6 - 'page' Local File Inclusion
CVE-2008-0332webappsphp
Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute
23RISCO
abrir
ReferênciaVexDay Proof
PHP-RESIDENCE 0.7.2 - 'Search' SQL Injection
CVE-2008-0353webappsphp
SQL injection vulnerability in visualizza_tabelle.php in php-residence 0.7.2 and 1.0 allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
PHPEcho CMS 2.0 - 'id' SQL Injection
CVE-2008-0355webappsphp
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote
23RISCO
abrir
ReferênciaVexDay Proof
Small Axe 0.3.1 - 'cfile' Remote File Inclusion
CVE-2008-0376webappsphp
PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute
35RISCO
abrir
ReferênciaVexDay Proof
Crystal Reports XI Release 2 (Enterprise Tree Control) - ActiveX Buffer Overflow (Denial of Service) (PoC)
CVE-2008-0379doswindows
Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release
23RISCO
abrir
ReferênciaVexDay Proof
Digital Data Communications - 'RtspVaPgCtrl' Class Remote Buffer Overflow
CVE-2008-0380remotewindows
Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows re
28RISCO
abrir
anteriorpágina 189 / 717próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.