Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.087exploits catalogados
34.679CVEs com exploração pública
24.695testados em laboratório
21.692 exploits
ReferênciaVexDay Proof
Live for Speed S1/S2/Demo - '.mpr replay' Local Buffer Overflow
CVE-2007-4140localwindows
Buffer overflow in Live for Speed (LFS) S2 ALPHA PATCH 0.5x allows user-assisted remote attackers to execute arbitrary c
23RISCO
abrir
Referência
CVE-2019-10349
A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers
23RISCO
abrir
Referência
CVE-2025-34073
stamparm/maltrail <=0.54 Remote Command Execution
63RISCO
abrir
Referência
CVE-2025-34073
stamparm/maltrail <=0.54 Remote Command Execution
63RISCO
abrir
Referência
CVE-2017-13754
Cross-site scripting (XSS) vulnerability in the "advanced settings - time server" module in Wibu-Systems CodeMeter befor
23RISCO
abrir
Referência
CVE-2009-5137
Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a lo
23RISCO
abrir
ReferênciaVexDay Proof
Web Wiz NewsPad 1.02 - 'sub' Directory Traversal
CVE-2008-0479webappsasp
Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz NewsPad 1.02 allows remote attackers to list arbitr
23RISCO
abrir
ReferênciaVexDay Proof
IntelliTamper 2.07/2.08 - 'ProxyLogin' Local Stack Overflow
CVE-2008-5868localwindows
Stack-based buffer overflow in IntelliTamper 2.07 and 2.08 allows user-assisted attackers to execute arbitrary code via
23RISCO
abrir
ReferênciaVexDay Proof
Web Wiz Forums 9.07 - 'sub' Directory Traversal
CVE-2008-0480webappsasp
Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary
23RISCO
abrir
Referência
CVE-2011-5211
Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbit
23RISCO
abrir
Referência
CVE-2020-26820
SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administra
48RISCO
abrir
Referência
Joomla! Component JE PayperVideo 3.0.0 - 'usr_plan' SQL Injection
CVE-2018-6578webappsphp
SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task
23RISCO
abrir
Referência
Joomla! Component JEXTN Reverse Auction 3.1.0 - SQL Injection
CVE-2018-6579webappsphp
SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request.
23RISCO
abrir
Referência
CVE-2010-3134
Untrusted search path vulnerability in Google Earth 5.1.3535.3218 allows local users, and possibly remote attackers, to
23RISCO
abrir
Referência
CVE-2025-34024
Edimax EW-7438RPn Mini OS Command Injection via mp.asp
48RISCO
abrir
Referência
CVE-2017-11548
The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of servic
23RISCO
abrir
Referência
CVE-2018-9844
The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
23RISCO
abrir
Referência
CVE-2019-17504
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vuln
23RISCO
abrir
Referência
CVE-2021-26078
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before
23RISCO
abrir
ReferênciaVexDay Proof
Mambo Component 'com_a6mambohelpdesk' 18RC1 - Remote File Inclusion
CVE-2006-3930webappsphp
PHP remote file inclusion vulnerability in admin.a6mambohelpdesk.php in a6mambohelpdesk Mambo Component 18RC1 and earlie
23RISCO
abrir
ReferênciaVexDay Proof
AllMyGuests 0.4.1 - 'cfg_serverpath' Remote File Inclusion
CVE-2006-4993webappsphp
Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.4.1 and earlier allow remote attackers to execute ar
23RISCO
abrir
Referência
CVE-2019-12460
Web Port 1.19.1 allows XSS via the /access/setup type parameter.
23RISCO
abrir
ReferênciaVexDay Proof
plusphp url shortening software 1.6 - Remote File Inclusion
CVE-2008-2480webappsphp
PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers t
23RISCO
abrir
ReferênciaVexDay Proof
PHP recommend 1.3 - Authentication Bypass / Remote File Inclusion / Code Injection
CVE-2009-1779webappsphp
PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
Webfwlog 0.92 - 'debug.php' Remote File Disclosure
CVE-2007-0585webappsphp
include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain sour
23RISCO
abrir
Referência
CVE-2014-0476
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a
38RISCO
abrir
Referência
CVE-2014-0476
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a
38RISCO
abrir
Referência
CVE-2017-9124
The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NU
23RISCO
abrir
Referência
CVE-2017-9123
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of se
23RISCO
abrir
Referência
CVE-2012-5897
The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and e
23RISCO
abrir
anteriorpágina 283 / 724próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.