Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.902exploits catalogados
34.597CVEs com exploração pública
24.695testados em laboratório
21.624 exploits
ReferênciaVexDay Proof
JBlog 1.0 - Create / Delete Admin Authentication Bypass
CVE-2007-3973webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in JBlog 1.0 allow remote attackers to inject arbitrary web script o
23RISCO
abrir
ReferênciaVexDay Proof
RealPlayer 11 - '.au' Denial of Service
CVE-2007-6235doswindows
A certain ActiveX control in RealNetworks RealPlayer 11 allows remote attackers to cause a denial of service (applicatio
23RISCO
abrir
ReferênciaVexDay Proof
AGENCY4NET WEBFTP 1 - 'download2.php' File Disclosure
CVE-2008-0091webappsphp
Directory traversal vulnerability in download2.php in AGENCY4NET WEBFTP 1 allows remote attackers to read and delete arb
23RISCO
abrir
ReferênciaVexDay Proof
Wysi Wiki Wyg 1.0 - Local File Inclusion / Cross-Site Scripting / PHPInfo
CVE-2008-3205webappsphp
Directory traversal vulnerability in index.php in Easy-Script Wysi Wiki Wyg 1.0 allows remote attackers to read arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
IDM-OS 1.0 - 'Filename' File Disclosure
CVE-2008-0431webappsphp
Directory traversal vulnerability in administrator/download.php in IDMOS (aka Phoenix) 1.0 allows remote attackers to re
23RISCO
abrir
ReferênciaVexDay Proof
BbZL.php 0.92 - Insecure Cookie Handling
CVE-2008-4708webappsphp
BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admi
23RISCO
abrir
ReferênciaVexDay Proof
sCssBoard (Multiple Versions) - 'pwnpack' Remote s
CVE-2008-5576webappsphp
admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain adminis
23RISCO
abrir
ReferênciaVexDay Proof
asp-project 1.0 - Insecure Cookie Method
CVE-2009-0280webappsasp
Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting th
23RISCO
abrir
ReferênciaVexDay Proof
S-CMS 1.1 Stable - Insecure Cookie Handling / Mass Page Delete
CVE-2009-0864webappsphp
S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for t
23RISCO
abrir
ReferênciaVexDay Proof
PAD Site Scripts 3.6 - Insecure Cookie Handling
CVE-2009-1739webappsphp
PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including admi
23RISCO
abrir
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
CVE-2008-0166remotelinux
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISCO
abrir
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
CVE-2008-0166remotelinux
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISCO
abrir
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH (Ruby)
CVE-2008-0166remotelinux
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISCO
abrir
ReferênciaVexDay Proof
NetRisk 1.9.7 - Cross-Site Scripting / SQL Injection
CVE-2008-0185webappsphp
SQL injection vulnerability in index.php in NetRisk 1.9.7 and possibly earlier versions allows remote attackers to execu
23RISCO
abrir
Referência
CVE-2011-0519
SQL injection vulnerability in gallery.php in Gallarific PHP Photo Gallery script 2.1 and possibly other versions allows
23RISCO
abrir
ReferênciaVexDay Proof
QuickTime Player 7.3.1.70 - 'RTSP' Remote Buffer Overflow
CVE-2008-0234remotewindows
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allo
28RISCO
abrir
ReferênciaVexDay Proof
StreamAudio ChainCast ProxyManager - 'ccpm_0237.dll' Remote Buffer Overflow
CVE-2008-0248remotewindows
Buffer overflow in an ActiveX control in ccpm_0237.dll for StreamAudio ChainCast ProxyManager allows remote attackers to
28RISCO
abrir
ReferênciaVexDay Proof
Microsoft Visual InterDev 6.0 SP6 - '.sln' Local Buffer Overflow
CVE-2008-0250localwindows
Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a St
28RISCO
abrir
ReferênciaVexDay Proof
Binn SBuilder - 'nid' Blind SQL Injection
CVE-2008-0253webappsphp
SQL injection vulnerability in full_text.php in Binn SBuilder allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2026-8289
Open5GS SMF nsmf-handler.c smf_nsmf_handle_update_data_in_vsmf denial of service
33RISCO
abrir
Referência
CVE-2026-8288
Open5GS SMF gsm-handler.c denial of service
33RISCO
abrir
Referência
CVE-2026-6433
Custom CSS JS PHP <= 2.0.7 - Unauthenticated SQL Injection to RCE
56RISCO
abrir
Referência
CVE-2026-8276
bettercap MySQL Server mysql_server.go integer coercion
33RISCO
abrir
Referência
CVE-2026-8272
D-Link DNS-320 webfile_mgr.cgi chown os command injection
33RISCO
abrir
ReferênciaVexDay Proof
TutorialCMS 1.02 - 'Username' SQL Injection
CVE-2008-0254webappsphp
SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disa
23RISCO
abrir
Referência
CVE-2011-0611
CVE-2011-0611HIGHsob ataque
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; A
100RISCO
abrir
ReferênciaVexDay Proof
ASP Photo Gallery 1.0 - Multiple SQL Injections
CVE-2008-0256webappsasp
Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
Agares phpAutoVideo 2.21 - 'articlecat' SQL Injection (1)
CVE-2008-0262webappsphp
SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
Agares phpAutoVideo 2.21 - 'articlecat' SQL Injection (2)
CVE-2008-0262webappsphp
SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
TaskFreak! 0.6.1 - SQL Injection
CVE-2008-0270webappsphp
SQL injection vulnerability in index.php in TaskFreak! 0.6.1 and earlier allows remote authenticated users to execute ar
23RISCO
abrir
anteriorpágina 247 / 721próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.