Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.697exploits catalogados
36.715CVEs com exploração pública
24.695testados em laboratório
23.051 exploits
ReferênciaVexDay Proof
e107 Plugin ZoGo-Shop 1.15.4 - 'product' SQL Injection
CVE-2008-6114webappsphp
SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attack
23RISCO
abrir
Referência
CVE-2017-11873
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709
35RISCO
abrir
Referência
CVE-2014-0257
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it
50RISCO
abrir
Referência
CVE-2014-0257
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it
50RISCO
abrir
Referência
CVE-2011-3176
Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allo
60RISCO
abrir
Referência
CVE-2025-48827
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RISCO
abrir
Referência
CVE-2011-1567
Multiple stack-based buffer overflows in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Grap
50RISCO
abrir
ReferênciaVexDay Proof
Full PHP Emlak Script - 'arsaprint.php' SQL Injection
CVE-2008-6133webappsphp
SQL injection vulnerability in arsaprint.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
Referência
CVE-2012-5900
Multiple SQL injection vulnerabilities in SAMEDIA LandShop 0.9.2 allow remote attackers to execute arbitrary SQL command
23RISCO
abrir
Referência
Visual Tools DVR VX16 4.2.28.0 - OS Command Injection (Unauthenticated)
CVE-2021-42071webappsmultiple
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharac
50RISCO
abrir
ReferênciaVexDay Proof
phpMyAdmin - '/scripts/setup.php' PHP Code Injection
CVE-2009-1151CRITICALsob ataquewebappsphp
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RISCO
abrir
ReferênciaVexDay Proof
Particle Gallery 1.0.1 - SQL Injection
CVE-2007-3065webappsphp
SQL injection vulnerability in viewimage.php in Particle Soft Particle Gallery 1.0.1 and earlier allows remote attackers
23RISCO
abrir
Referência
CVE-2012-5896
The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not prope
50RISCO
abrir
Referência
CVE-2012-5896
The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not prope
50RISCO
abrir
ReferênciaVexDay Proof
Acoustica Beatcraft 1.02 Build 19 - '.bcproj' Local Buffer Overflow
CVE-2008-4087localwindows
Stack-based buffer overflow in Acoustica Beatcraft 1.02 Build 19 allows user-assisted attackers to cause a denial of ser
23RISCO
abrir
Referência
CVE-2019-9193
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
Referência
CVE-2019-10867
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/c
50RISCO
abrir
Referência
CVE-2019-10867
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/c
50RISCO
abrir
Referência
CVE-2017-8646
Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in t
35RISCO
abrir
Referência
CVE-2017-8640
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary cod
35RISCO
abrir
Referência
CVE-2017-8645
Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in t
35RISCO
abrir
Referência
CVE-2018-8631
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet
35RISCO
abrir
Referência
CVE-2017-11802
ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker
35RISCO
abrir
ReferênciaVexDay Proof
Yourownbux 3.1/3.2 Beta - SQL Injection
CVE-2008-4093webappsphp
SQL injection vulnerability in memberstats.php in YourOwnBux 3.1 and 3.2 beta, when magic_quotes_gpc is disabled, allows
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows - 'WRITE_ANDX' SMB Command Handling Kernel Denial of Service (Metasploit)
CVE-2008-4114doswindows
srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1
50RISCO
abrir
Referência
CVE-2022-22960
CVE-2022-22960HIGHsob ataque
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due t
98RISCO
abrir
Referência
CVE-2022-22960
CVE-2022-22960HIGHsob ataque
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due t
98RISCO
abrir
ReferênciaVexDay Proof
The Personal FTP Server 6.0f - RETR Denial of Service
CVE-2008-4136doswindows
Michael Roth Software Personal FTP Server (PFT) 6.0f allows remote attackers to cause a denial of service (service crash
23RISCO
abrir
ReferênciaVexDay Proof
OwenPoll 1.0 - Insecure Cookie Handling
CVE-2008-6143webappsphp
OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account na
23RISCO
abrir
ReferênciaVexDay Proof
E-PHP CMS - 'article.php' SQL Injection
CVE-2008-4142webappsphp
SQL injection vulnerability in article.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir
anteriorpágina 49 / 769próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.