Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
21.899 exploits
ReferênciaVexDay Proof
Prozilla Forum Service - 'forum' SQL Injection
CVE-2008-1789webappsphp
SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
My Gaming Ladder 7.5 - 'ladderid' SQL Injection
CVE-2008-1791webappsphp
SQL injection vulnerability in ladder.php in My Gaming Ladder 7.5 and earlier allows remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
Dragoon 0.1 - 'lng' Local File Inclusion
CVE-2008-1798webappsphp
Directory traversal vulnerability in forum/kietu/libs/calendrier.php in Dragoon 0.1 allows remote attackers to include a
23RISCO
abrir
ReferênciaVexDay Proof
rdesktop 1.5.0 - 'process_redirect_pdu()' BSS Overflow (PoC)
CVE-2008-1802doslinux
Buffer overflow in the process_redirect_pdu (rdp.c) function in rdesktop 1.5.0 allows remote attackers to execute arbitr
28RISCO
abrir
ReferênciaVexDay Proof
BosClassifieds 3.0 - 'index.php' SQL Injection
CVE-2008-1838webappsphp
SQL injection vulnerability in BosClassifieds Classified Ads System 3.0 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
PHPAddressBook 2.11 - 'view.php' SQL Injection
CVE-2008-1847webappsphp
SQL injection vulnerability in view.php in CoronaMatrix phpAddressBook 2.11 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component JoomlaXplorer 1.6.2 - Remote s
CVE-2008-1849webappsphp
Directory traversal vulnerability in index.php in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 an
23RISCO
abrir
Referência
CVE-2015-2878
Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijac
23RISCO
abrir
Referência
CVE-2009-2787
Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, an
23RISCO
abrir
Referência
CVE-2009-2787
Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, an
23RISCO
abrir
Referência
CVE-2018-4230
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "NVIDIA Grap
23RISCO
abrir
Referência
CVE-2022-0847
CVE-2022-0847HIGHsob ataque
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
Referência
CVE-2012-0984
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web
23RISCO
abrir
Referência
CVE-2012-0984
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web
23RISCO
abrir
Referência
CVE-2022-0847
CVE-2022-0847HIGHsob ataque
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
Referência
CVE-2012-1124
SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Referência
CVE-2012-6667
Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows r
23RISCO
abrir
ReferênciaVexDay Proof
PHPMyInventory 2.8 - 'global.inc.php' Remote File Inclusion
CVE-2007-3270webappsphp
PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to exec
23RISCO
abrir
Referência
CVE-2018-7703
Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitr
23RISCO
abrir
Referência
CVE-2013-7136
The UPC Ireland Cisco EPC 2425 router (aka Horizon Box) does not have a sufficiently large number of possible WPA-PSK pa
23RISCO
abrir
Referência
CVE-2017-12954
The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of
23RISCO
abrir
Referência
CVE-2017-12953
The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial
23RISCO
abrir
ReferênciaVexDay Proof
WordPress Plugin Wordspew - SQL Injection
CVE-2008-0682webappsphp
SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers
23RISCO
abrir
Referência
CVE-2014-6312
Cross-site request forgery (CSRF) vulnerability in the Login Widget With Shortcode (login-sidebar-widget) plugin before
23RISCO
abrir
ReferênciaVexDay Proof
PostcardMentor - 'cat_fldAuto' SQL Injection
CVE-2008-2132webappsasp
SQL injection vulnerability in step1.asp in Systementor PostcardMentor allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Referência
CVE-2018-5980
SQL Injection exists in the Solidres 2.5.1 component for Joomla! via the direction parameter in a hub.search action.
23RISCO
abrir
Referência
CVE-2018-6180
A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password fo
23RISCO
abrir
Referência
CVE-2018-6180
A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password fo
23RISCO
abrir
Referência
CVE-2014-0894
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows context-de
23RISCO
abrir
Referência
CVE-2018-19915
DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.
38RISCO
abrir
anteriorpágina 335 / 730próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.