Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
21.534 exploits
ReferênciaVexDay Proof
mxCamArchive 2.2 - Bypass Configuration Download
CVE-2008-6955webappsphp
mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote a
23RISCO
abrir
ReferênciaVexDay Proof
CodeAvalanche Articles - Database Disclosure
CVE-2008-5900webappsasp
CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows re
23RISCO
abrir
Referência
CVE-2010-0759
Directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Desi
43RISCO
abrir
Referência
CVE-2014-125118
eScan 5.5-2 Web Management Console Command Injection
63RISCO
abrir
Referência
CVE-2009-2344
The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authentica
23RISCO
abrir
Referência
CVE-2019-10963
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from
23RISCO
abrir
Referência
CVE-2010-5194
Stack-based buffer overflow in the Image2PDF function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageViewer2.ocx)
23RISCO
abrir
Referência
CVE-2015-8612
The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users
38RISCO
abrir
Referência
CVE-2015-8612
The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users
38RISCO
abrir
Referência
CVE-2021-45814
Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel
23RISCO
abrir
Referência
CVE-2020-14944
Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can all
23RISCO
abrir
ReferênciaVexDay Proof
DataTrac Activity Console - Denial of Service
CVE-2005-1667doswindows
DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request.
23RISCO
abrir
Referência
CVE-2018-5708
An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticat
23RISCO
abrir
Referência
CVE-2014-125118
eScan 5.5-2 Web Management Console Command Injection
63RISCO
abrir
ReferênciaVexDay Proof
Moodle 1.5.2 - 'moodledata' Remote Session Disclosure
CVE-2007-1647webappsphp
Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides
23RISCO
abrir
ReferênciaVexDay Proof
PcP-Guestbook 3.0 - 'lang' Local File Inclusion
CVE-2007-1933webappsphp
Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execu
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Expose RC35 - Arbitrary File Upload
CVE-2007-3932webappsphp
uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit
23RISCO
abrir
ReferênciaVexDay Proof
PayPal eStore - Admin Password Change
CVE-2008-6535webappsphp
admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the admin
23RISCO
abrir
ReferênciaVexDay Proof
PHPUserBase 1.3b - 'unverified.inc.php' Local File Inclusion
CVE-2008-7240webappsphp
Directory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows rem
23RISCO
abrir
ReferênciaVexDay Proof
Flatnux 2009-01-27 - Remote File Inclusion
CVE-2009-0572webappsphp
PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04,
23RISCO
abrir
Referência
CVE-2012-2919
Directory traversal vulnerability in Upload/engine.php in Chevereto 1.9.1 allows remote attackers to determine the exist
23RISCO
abrir
Referência
CVE-2010-0759
Directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Desi
43RISCO
abrir
Referência
CVE-2019-6192
A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a
33RISCO
abrir
Referência
CVE-2010-0761
SQL injection vulnerability in index.php in CommodityRentals Books/eBooks Rentals Script allows remote attackers to exec
23RISCO
abrir
Referência
CVE-2018-7705
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read e-mai
23RISCO
abrir
ReferênciaVexDay Proof
Envolution 1.1.0 - 'PNSVlang' Remote Code Execution
CVE-2006-6445webappsphp
Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and ex
23RISCO
abrir
Referência
CVE-2022-39195
A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary
48RISCO
abrir
Referência
CVE-2013-1636
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in
23RISCO
abrir
Referência
CVE-2013-1636
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in
23RISCO
abrir
Referência
CVE-2012-4057
Buffer overflow in the Player in Remote-Anything 5.60.15 allows remote attackers to execute arbitrary code via a crafted
23RISCO
abrir
anteriorpágina 197 / 718próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.