Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
21.861 exploits
Referência
CVE-2016-0999
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RISCO
abrir
Referência
CVE-2018-16059
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename par
43RISCO
abrir
Referência
CVE-2016-0997
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RISCO
abrir
Referência
CVE-2021-37589
Virtua Cobranca before 12R allows SQL Injection on the login page.
50RISCO
abrir
Referência
CVE-2013-2574
An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /lo
28RISCO
abrir
Referência
CVE-2013-2574
An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /lo
28RISCO
abrir
ReferênciaVexDay Proof
Kjtechforce mailman b1 - Delete Row 'code' SQL Injection
CVE-2009-2164webappsphp
Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote att
23RISCO
abrir
Referência
CVE-2015-2842
Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAu
28RISCO
abrir
ReferênciaVexDay Proof
Sejoong Namo ActiveSquare 6 - 'NamoInstaller.dll' install Method
CVE-2008-0551remotewindows
The NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1 and earlier in Namo Web Editor in Sejoong N
28RISCO
abrir
ReferênciaVexDay Proof
OCS Inventory NG 1.02 - Remote File Disclosure
CVE-2009-2166webappsphp
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to re
23RISCO
abrir
Referência
CVE-2016-8870
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before
60RISCO
abrir
Referência
CVE-2009-1699
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for i
28RISCO
abrir
Referência
CVE-2017-11517
Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote at
43RISCO
abrir
Referência
CVE-2019-1150
Microsoft Graphics Remote Code Execution Vulnerability
46RISCO
abrir
Referência
CVE-2019-1150
Microsoft Graphics Remote Code Execution Vulnerability
46RISCO
abrir
Referência
CVE-2019-7274
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
28RISCO
abrir
Referência
CVE-2018-12327
Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or es
28RISCO
abrir
Referência
CVE-2024-6366
User Profile Builder < 3.11.8 - Unauthenticated Media Upload
68RISCO
abrir
Referência
CVE-2024-12847
NETGEAR DGN setup.cgi OS Command Injection
68RISCO
abrir
Referência
CVE-2024-12847
NETGEAR DGN setup.cgi OS Command Injection
68RISCO
abrir
Referência
CVE-2018-14058
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
43RISCO
abrir
Referência
CVE-2018-14058
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
43RISCO
abrir
Referência
CVE-2011-4642
mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python
43RISCO
abrir
Referência
CVE-2013-3238
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a
43RISCO
abrir
Referência
CVE-2009-3753
Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a fil
23RISCO
abrir
Referência
CVE-2014-6363
vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allo
28RISCO
abrir
ReferênciaVexDay Proof
Fuzzylime CMS 3.03a - Local Inclusion / Arbitrary File Corruption
CVE-2009-2177webappsphp
code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to con
23RISCO
abrir
Referência
CVE-2013-6720
Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX
28RISCO
abrir
Referência
CVE-2016-3324
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
28RISCO
abrir
Referência
CVE-2014-1912
Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.
28RISCO
abrir
anteriorpágina 326 / 729próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.