Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
22.301 exploits
Referência
CVE-2013-1596
An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP pac
28RISCO
abrir
Referência
CVE-2022-29593
relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post reques
38RISCO
abrir
ReferênciaVexDay Proof
Pagode 0.5.8 - 'navigator_ok.php?asolute' Remote File Disclosure
CVE-2007-2200webappsphp
Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and poss
28RISCO
abrir
ReferênciaVexDay Proof
Sun jre1.6.0_X - isInstalled.dnsResolve Function Overflow
CVE-2007-5019dosmultiple
Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attack
28RISCO
abrir
ReferênciaVexDay Proof
docpile:we 0.2.2 - 'INIT_PATH' Remote File Inclusion
CVE-2006-4075webappsphp
Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and ear
28RISCO
abrir
ReferênciaVexDay Proof
Linux Kernel 2.6.21.1 - IPv6 Jumbo Bug Remote Denial of Service
CVE-2008-0352doslinux
The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6
28RISCO
abrir
ReferênciaVexDay Proof
sflog! 0.96 - Remote File Disclosure
CVE-2008-0703webappsphp
Multiple directory traversal vulnerabilities in sflog! 0.96 allow remote attackers to read arbitrary files via a .. (dot
23RISCO
abrir
ReferênciaVexDay Proof
GdPicture Pro - ActiveX 'gdpicture4s.ocx' File Overwrite / Exec
CVE-2008-4453remotewindows
The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro
28RISCO
abrir
ReferênciaVexDay Proof
Mozilla Firefox XSL - Parsing Remote Memory Corruption (PoC) (1)
CVE-2009-1169dosmultiple
The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows r
28RISCO
abrir
Referência
CVE-2010-4701
Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover
35RISCO
abrir
Referência
CVE-2011-3981
PHP remote file inclusion vulnerability in actions.php in the Allwebmenus plugin 1.1.3 for WordPress allows remote attac
28RISCO
abrir
Referência
CVE-2019-16692
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is us
28RISCO
abrir
Referência
CVE-2020-35737
In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information
28RISCO
abrir
Referência
CVE-2011-1546
Multiple SQL injection vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.3 allow remote attackers to exec
23RISCO
abrir
Referência
CVE-2010-1029
Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Saf
28RISCO
abrir
Referência
CVE-2010-1029
Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Saf
28RISCO
abrir
Referência
CVE-2020-6857
CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FT
23RISCO
abrir
Referência
CVE-2017-8770
There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesys
28RISCO
abrir
Referência
CVE-2019-15993
Cisco Small Business Switches Information Disclosure Vulnerability
46RISCO
abrir
Referência
CVE-2026-6594
brikcss merge prototype pollution
33RISCO
abrir
ReferênciaVexDay Proof
DNS Tools (PHP Digger) - Remote Command Execution
CVE-2009-1916webappsphp
dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the
28RISCO
abrir
ReferênciaVexDay Proof
SolidState 0.4 - Multiple Remote File Inclusions
CVE-2006-5020webappsphp
Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbit
28RISCO
abrir
Referência
CVE-2014-2996
XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administr
23RISCO
abrir
Referência
CVE-2009-2934
Multiple stack-based buffer overflows in xaudio.dll in Programmed Integration PIPL 2.5.0 and 2.5.0D allow remote attacke
28RISCO
abrir
Referência
CVE-2019-12922
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
28RISCO
abrir
Referência
CVE-2019-11013
Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow
43RISCO
abrir
Referência
CVE-2021-27878
CVE-2021-27878HIGHsob ataqueransomware
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc
91RISCO
abrir
Referência
CVE-2018-5997
An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a pa
28RISCO
abrir
Referência
CVE-2009-4892
SQL injection vulnerability in Content Management System WEBjump! allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir
ReferênciaVexDay Proof
MyBulletinBoard (MyBB) 1.2.11 - 'private.php' SQL Injection (1)
CVE-2008-0787webappsphp
SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execut
23RISCO
abrir
anteriorpágina 475 / 744próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.