Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
21.797 exploits
Referência
CVE-2009-3196
Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech PHP Video Script allows remote attackers to inject arb
23RISCO
abrir
Referência
CVE-2015-2125
Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote authenticated users to by
23RISCO
abrir
ReferênciaVexDay Proof
MiGCMS 2.0.5 - Multiple Remote File Inclusions
CVE-2008-2888webappsphp
Multiple PHP remote file inclusion vulnerabilities in MiGCMS 2.0.5, when register_globals is enabled, allow remote attac
23RISCO
abrir
Referência
CVE-2017-16902
On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or logi
23RISCO
abrir
Referência
CVE-2009-3203
SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
Referência
CVE-2009-3205
SQL injection vulnerability in main.php in CBAuthority allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
ReferênciaVexDay Proof
Mini Web Calendar 1.2 - File Disclosure / Cross-Site Scripting
CVE-2008-5062webappsphp
Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read ar
23RISCO
abrir
Referência
CVE-2008-4178
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RISCO
abrir
Referência
CVE-2008-4178
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RISCO
abrir
Referência
CVE-2008-4178
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RISCO
abrir
Referência
CVE-2017-14086
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated u
23RISCO
abrir
Referência
CVE-2017-14086
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated u
23RISCO
abrir
Referência
CVE-2016-9813
The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of ser
23RISCO
abrir
Referência
CVE-2009-3226
SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds Ads Enterprise and Almond Affiliate Network Cl
23RISCO
abrir
Referência
CVE-2018-13042
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com
23RISCO
abrir
Referência
CVE-2004-1720
The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sens
23RISCO
abrir
Referência
CVE-2014-7910
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISCO
abrir
ReferênciaVexDay Proof
RunCMS 1.5.2 - 'debug_show.php' SQL Injection
CVE-2007-2539webappsphp
The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existe
23RISCO
abrir
Referência
CVE-2022-30525
CVE-2022-30525CRITICALsob ataque
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISCO
abrir
Referência
CVE-2022-30525
CVE-2022-30525CRITICALsob ataque
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISCO
abrir
Referência
CVE-2022-30525
CVE-2022-30525CRITICALsob ataque
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISCO
abrir
Referência
CVE-2022-30525
CVE-2022-30525CRITICALsob ataque
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISCO
abrir
Referência
CVE-2022-30781
Gitea before 1.16.7 does not escape git fetch remote.
60RISCO
abrir
Referência
CVE-2016-3986
Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a
23RISCO
abrir
ReferênciaVexDay Proof
Collabtive 0.4.8 - Cross-Site Scripting / Authentication Bypass / Arbitrary File Upload
CVE-2008-6948webappsphp
Unrestricted file upload vulnerability in Collabtive 0.4.8 allows remote authenticated users to execute arbitrary code b
23RISCO
abrir
Referência
CVE-2016-6256
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML
23RISCO
abrir
Referência
CVE-2015-1376
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remot
50RISCO
abrir
Referência
CVE-2016-6256
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML
23RISCO
abrir
Referência
CVE-2013-5223
CVE-2013-5223MEDIUMsob ataque
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated use
75RISCO
abrir
Referência
CVE-2023-0386
CVE-2023-0386HIGHsob ataque
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir
anteriorpágina 303 / 727próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.