Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
21.797 exploits
Referência
CVE-2025-34515
Ilevia EVE X1 Server 4.7.18.0.eden Root Privilege Escalation
48RISCO
abrir
Referência
CVE-2021-3355
A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Tit
23RISCO
abrir
Referência
CVE-2009-3335
SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQ
23RISCO
abrir
ReferênciaVexDay Proof
HP-UX 11i - 'swask' Format String Privilege Escalation
CVE-2006-5558localhp-ux
Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to exec
23RISCO
abrir
Referência
CVE-2009-3336
SQL injection vulnerability in auction_details.php in PHP Pro Bid allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir
ReferênciaVexDay Proof
Ourgame GLWorld 2.x - 'hgs_startNotify()' ActiveX Buffer Overflow
CVE-2008-0647remotewindows
Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.
23RISCO
abrir
ReferênciaVexDay Proof
LoveCMS 1.6.2 Final (Simple Forum 3.1d) - Change Admin Password
CVE-2008-5308webappsphp
The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which
23RISCO
abrir
Referência
CVE-2018-12522
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ pro
23RISCO
abrir
ReferênciaVexDay Proof
Check Point Firewall-1 - PKI Web Service HTTP Header Remote Overflow
CVE-2009-1227doshardware
NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI
23RISCO
abrir
Referência
CVE-2013-4885
The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote s
23RISCO
abrir
Referência
CVE-2017-15879
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCS
23RISCO
abrir
Referência
CVE-2017-15879
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCS
23RISCO
abrir
Referência
CVE-2017-7046
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir
ReferênciaVexDay Proof
PPStream - 'PowerPlayer.dll 2.0.1.3829' ActiveX Remote Overflow
CVE-2007-4748remotewindows
Buffer overflow in the PowerPlayer.dll ActiveX control in PPStream 2.0.1.3829 allows remote attackers to execute arbitra
23RISCO
abrir
Referência
CVE-2022-40319
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a
41RISCO
abrir
Referência
CVE-2018-10255
A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level pri
23RISCO
abrir
Referência
CVE-2018-10255
A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level pri
23RISCO
abrir
Referência
CVE-2009-3355
Cross-site scripting (XSS) vulnerability in profile.php in Datetopia Buy Dating Site 1.0 allows remote attackers to inje
23RISCO
abrir
Referência
CVE-2017-6359
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands vi
28RISCO
abrir
Referência
CVE-2010-4055
Stack consumption vulnerability in solid.exe in IBM solidDB 6.5.0.3 and earlier allows remote attackers to cause a denia
23RISCO
abrir
Referência
CVE-2010-4057
solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon recei
23RISCO
abrir
Referência
CVE-2014-9350
TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attack
23RISCO
abrir
Referência
CVE-2014-9350
TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attack
23RISCO
abrir
Referência
CVE-2012-0292
The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.
23RISCO
abrir
Referência
CVE-2014-3418
config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via she
23RISCO
abrir
Referência
CVE-2009-3356
SQL injection vulnerability in index.php in Image voting 1.0 allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
Referência
CVE-2015-5533
SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote
23RISCO
abrir
Referência
CVE-2015-5533
SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote
23RISCO
abrir
Referência
CVE-2021-21276
Privilege escalation in Polr
48RISCO
abrir
Referência
CVE-2016-15048
AMTT HiBOS Command Injection RCE via server_ping.php
48RISCO
abrir
anteriorpágina 306 / 727próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.