Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
22.233 exploits
Referência
CVE-2018-6941
A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remot
23RISCO
abrir
Referência
CVE-2007-0843
The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions
23RISCO
abrir
Referência
CVE-2016-0891
Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM before 3.7 allow remo
23RISCO
abrir
Referência
CVE-2010-1315
Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1
38RISCO
abrir
Referência
CVE-2019-12905
FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman&section=do&page=up URI. This issue has been fixed
23RISCO
abrir
ReferênciaVexDay Proof
OpenDock Easy Blog 1.4 - 'doc_directory' File Inclusion
CVE-2006-5244webappsphp
Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Blog 1.4 and earlier, when register_globals is enabl
23RISCO
abrir
ReferênciaVexDay Proof
CPCommerce 1.1.0 - Cross-Site Scripting / Local File Inclusion
CVE-2008-1908webappsphp
Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
PHP Visit Counter 0.4 - 'datespan' SQL Injection
CVE-2008-2556webappsphp
SQL injection vulnerability in read.php in PHP Visit Counter 0.4 and earlier allows remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
Tizag Countdown Creator 3 - Insecure Upload
CVE-2008-6492webappsphp
Unrestricted file upload vulnerability in process.php in Tizag Countdown Creator 3 allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
ReVou Twitter Clone - Arbitrary File Upload
CVE-2008-6751webappsphp
Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows
23RISCO
abrir
Referência
CVE-2022-29851
documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Inj
48RISCO
abrir
Referência
CVE-2017-17721
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, ass
23RISCO
abrir
Referência
CVE-2017-17721
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, ass
23RISCO
abrir
Referência
CVE-2016-0143
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RISCO
abrir
ReferênciaVexDay Proof
GeBlog 0.1 (Windows) - GLOBALS[tplname] Local File Inclusion
CVE-2007-1577webappsphp
Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary lo
23RISCO
abrir
Referência
CVE-2020-9371
Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php
23RISCO
abrir
Referência
CVE-2016-7384
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RISCO
abrir
ReferênciaVexDay Proof
PostNuke pnFlashGames Module 1.5 - SQL Injection
CVE-2007-2427webappsphp
SQL injection vulnerability in index.php in the pnFlashGames 1.5 module for PostNuke allows remote attackers to execute
23RISCO
abrir
Referência
CVE-2017-8471
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2,
23RISCO
abrir
ReferênciaVexDay Proof
TLM CMS 3.2 - Multiple SQL Injections
CVE-2007-4808webappsphp
Multiple SQL injection vulnerabilities in TLM CMS 3.2 allow remote attackers to execute arbitrary SQL commands via (1) t
23RISCO
abrir
Referência
CVE-2010-1335
Multiple PHP remote file inclusion vulnerabilities in Insky CMS 006-0111, when register_globals is enabled, allow remote
23RISCO
abrir
ReferênciaVexDay Proof
427bb 2.3.1 - SQL Injection / Cross-Site Scripting
CVE-2008-2560webappsphp
SQL injection vulnerability in showpost.php in 427BB 2.3.1 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
Power Phlogger 2.2.5 - 'css_str' SQL Injection
CVE-2008-2562webappsphp
SQL injection vulnerability in edCss.php in PowerPhlogger 2.2.5 and earlier allows remote authenticated users to execute
23RISCO
abrir
ReferênciaVexDay Proof
YouTube blog 0.1 - Remote File Inclusion / SQL Injection / Cross-Site Scripting
CVE-2008-3305webappsphp
Cross-site scripting (XSS) vulnerability in mensaje.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
Libc - 'libc:fts_*()' Local Denial of Service
CVE-2009-0537dosbsd
Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0
23RISCO
abrir
Referência
CVE-2014-3210
SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for Wo
23RISCO
abrir
Referência
CVE-2015-2528
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RISCO
abrir
Referência
CVE-2015-2528
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RISCO
abrir
Referência
CVE-2017-14266
tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related
23RISCO
abrir
ReferênciaVexDay Proof
phpEventMan 1.0.2 - 'level' Remote File Inclusion
CVE-2007-0702webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpEventMan 1.0.2 allow remote attackers to execute arbitrary PHP
23RISCO
abrir
anteriorpágina 439 / 742próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.