Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.620exploits catalogados
35.647CVEs com exploração pública
24.695testados em laboratório
22.407 exploits
Referência
CVE-2018-10956
IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.
50RISCO
abrir
Referência
CVE-2016-9722
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be r
43RISCO
abrir
Referência
CVE-2014-9241
Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allow remote attack
23RISCO
abrir
Referência
CVE-2019-9053
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
Referência
CVE-2014-5289
Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request
28RISCO
abrir
Referência
CVE-2010-3894
Stack-based buffer overflow in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function in /opt/IBM/es/lib/libffq.crypt
28RISCO
abrir
ReferênciaVexDay Proof
xeCMS 1.0.0 RC2 - Insecure Cookie Handling
CVE-2008-6714webappsphp
admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by
28RISCO
abrir
Referência
CVE-2022-1768
RSVPMaker <= 9.3.2 - Unauthenticated SQL Injection
68RISCO
abrir
ReferênciaVexDay Proof
Online Fantasy Football League (OFFL) 0.2.6 - Remote File Inclusion
CVE-2007-4809webappsphp
Multiple PHP remote file inclusion vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 allow remote attackers
35RISCO
abrir
Referência
CVE-2016-5677
NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.
28RISCO
abrir
Referência
CVE-2012-5862
Sinapsi eSolar Hard-Coded Password
53RISCO
abrir
ReferênciaVexDay Proof
Hannon Hill Cascade Server - (Authenticated) Command Execution
CVE-2009-1088webappscgi
Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Jav
28RISCO
abrir
ReferênciaVexDay Proof
Citadel SMTP 7.10 - Remote Overflow
CVE-2008-0394remotewindows
Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCP
28RISCO
abrir
ReferênciaVexDay Proof
MySpace Uploader - 'MySpaceUploader.ocx 1.0.0.4' Remote Buffer Overflow
CVE-2008-0659remotewindows
Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used i
35RISCO
abrir
ReferênciaVexDay Proof
LoveCMS 1.6.2 Final - Remote Code Execution
CVE-2008-3509webappsphp
LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in
23RISCO
abrir
ReferênciaVexDay Proof
Solaris 9 PortBind - XDR-DECODE 'taddr2uaddr()' Remote Denial of Service
CVE-2008-4619dossolaris
The RPC subsystem in Sun Solaris 9 allows remote attackers to cause a denial of service (daemon crash) via a crafted req
28RISCO
abrir
ReferênciaVexDay Proof
WordPress MU < 1.3.2 - 'active_plugins' Code Execution
CVE-2008-5695webappsphp
wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests
28RISCO
abrir
Referência
CVE-2014-3976
Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allow
28RISCO
abrir
Referência
CVE-2014-3976
Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allow
28RISCO
abrir
Referência
CVE-2023-26068
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
68RISCO
abrir
Referência
CVE-2020-1380
CVE-2020-1380HIGHsob ataque
Scripting Engine Memory Corruption Vulnerability
76RISCO
abrir
Referência
CVE-2019-9189
Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when
28RISCO
abrir
Referência
CVE-2018-8947
rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easi
28RISCO
abrir
Referência
CVE-2019-19731
Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary loc
28RISCO
abrir
Referência
CVE-2013-3502
monarch_scan.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to ex
50RISCO
abrir
Referência
CVE-2019-1253
CVE-2019-1253HIGHsob ataqueransomware
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISCO
abrir
Referência
CVE-2010-1957
Directory traversal vulnerability in the Love Factory (com_lovefactory) component 1.3.4 for Joomla! allows remote attack
43RISCO
abrir
Referência
CVE-2019-12276
A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows
50RISCO
abrir
ReferênciaVexDay Proof
MailBee WebMail Pro 4.1 - Remote File Disclosure
CVE-2008-0333webappsasp
Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET all
28RISCO
abrir
ReferênciaVexDay Proof
Apple QuickTime 7.5.5 / iTunes 8.0 - Remote Off-by-One Crash
CVE-2008-4116dosmultiple
Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser cr
28RISCO
abrir
anteriorpágina 538 / 747próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.