Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.282exploits catalogados
35.464CVEs com exploração pública
24.695testados em laboratório
22.301 exploits
Referência
CVE-2016-8810
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RISCO
abrir
Referência
CVE-2017-0144
CVE-2017-0144HIGHsob ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Referência
CVE-2017-0146
CVE-2017-0146HIGHsob ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Referência
CVE-2017-0285
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RISCO
abrir
Referência
CVE-2017-0286
Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RISCO
abrir
Referência
CVE-2017-0288
Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RISCO
abrir
Referência
CVE-2017-0289
Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RISCO
abrir
Referência
CVE-2021-44529
CVE-2021-44529CRITICALsob ataqueransomware
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RISCO
abrir
Referência
CVE-2021-44529
CVE-2021-44529CRITICALsob ataqueransomware
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RISCO
abrir
Referência
CVE-2021-44596
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an
28RISCO
abrir
Referência
Online Magazine Management System 1.0 - SQLi Authentication Bypass
CVE-2021-44653webappsphp
Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel auth
23RISCO
abrir
Referência
Online Pre-owned/Used Car Showroom Management System 1.0 - SQLi Authentication Bypass
CVE-2021-44655webappsphp
Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. A
23RISCO
abrir
Referência
CVE-2021-44848
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques
43RISCO
abrir
Referência
CVE-2021-45092
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection vi
50RISCO
abrir
Referência
CVE-2021-46379
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust
43RISCO
abrir
Referência
CVE-2021-46398
A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor use
23RISCO
abrir
Referência
CVE-2021-46417
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege
50RISCO
abrir
Referência
CVE-2021-46417
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege
50RISCO
abrir
Referência
CVE-2021-46422
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISCO
abrir
Referência
CVE-2021-46422
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISCO
abrir
Referência
CVE-2022-0847
CVE-2022-0847HIGHsob ataque
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
Referência
Sophos XG115w Firewall 17.0.10 MR-10 - Authentication Bypass
CVE-2022-1040CRITICALsob ataquewebappshardware
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISCO
abrir
Referência
CVE-2017-12500
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found
28RISCO
abrir
Referência
CVE-2022-1163
Cross-site Scripting (XSS) - Stored in mineweb/minewebcms
33RISCO
abrir
Referência
CVE-2022-1388
CVE-2022-1388CRITICALsob ataqueransomware
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
Referência
CVE-2022-1388
CVE-2022-1388CRITICALsob ataqueransomware
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
Referência
CVE-2017-12635
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISCO
abrir
Referência
WordPress Core 5.8.2 - 'WP_Query' SQL Injection
CVE-2022-21661HIGHwebappsphp
SQL injection in WordPress
78RISCO
abrir
Referência
Servisnet Tessa - Add sysAdmin User (Unauthenticated) (Metasploit)
CVE-2022-22831webappsmultiple
An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Auth
28RISCO
abrir
Referência
CVE-2022-22832
An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/u
28RISCO
abrir
anteriorpágina 466 / 744próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.