Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.620exploits catalogados
35.647CVEs com exploração pública
24.695testados em laboratório
22.429 exploits
Referência
CVE-2010-4701
Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover
35RISCO
abrir
Referência
CVE-2011-3981
PHP remote file inclusion vulnerability in actions.php in the Allwebmenus plugin 1.1.3 for WordPress allows remote attac
28RISCO
abrir
Referência
CVE-2019-16692
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is us
28RISCO
abrir
Referência
CVE-2020-35737
In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information
28RISCO
abrir
Referência
CVE-2011-1546
Multiple SQL injection vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.3 allow remote attackers to exec
23RISCO
abrir
Referência
CVE-2010-1029
Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Saf
28RISCO
abrir
Referência
CVE-2010-1029
Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Saf
28RISCO
abrir
Referência
CVE-2020-6857
CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FT
23RISCO
abrir
Referência
CVE-2017-8770
There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesys
28RISCO
abrir
Referência
CVE-2019-15993
Cisco Small Business Switches Information Disclosure Vulnerability
46RISCO
abrir
Referência
CVE-2026-6594
brikcss merge prototype pollution
33RISCO
abrir
ReferênciaVexDay Proof
DNS Tools (PHP Digger) - Remote Command Execution
CVE-2009-1916webappsphp
dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the
28RISCO
abrir
ReferênciaVexDay Proof
SolidState 0.4 - Multiple Remote File Inclusions
CVE-2006-5020webappsphp
Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbit
28RISCO
abrir
Referência
CVE-2009-4892
SQL injection vulnerability in Content Management System WEBjump! allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir
Referência
CVE-2013-6935
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a
50RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component com_galeria - SQL Injection
CVE-2008-0833webappsphp
SQL injection vulnerability in index.php in the com_galeria component for Joomla! allows remote attackers to execute arb
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module myTopics - 'articleId' SQL Injection
CVE-2008-0847webappsphp
SQL injection vulnerability in print.php in the myTopics module for XOOPS allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
RunCMS Module MyAnnonces - 'cid' SQL Injection
CVE-2008-0878webappsphp
SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to
23RISCO
abrir
Referência
CVE-2020-5260
malicious URLs may cause Git to present stored credentials to the wrong server
53RISCO
abrir
Referência
CVE-2018-8619
A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly rest
35RISCO
abrir
Referência
CVE-2018-12706
DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.
28RISCO
abrir
Referência
CVE-2017-0263
CVE-2017-0263HIGHsob ataque
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
76RISCO
abrir
Referência
CVE-2010-2919
SQL injection vulnerability in the StaticXT (com_staticxt) component for Joomla! allows remote attackers to execute arbi
23RISCO
abrir
Referência
CVE-2006-0992
Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute ar
60RISCO
abrir
Referência
CVE-2017-17999
SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir
Referência
CVE-2017-5972
The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fa
28RISCO
abrir
Referência
CVE-2014-2223
Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authen
28RISCO
abrir
Referência
CVE-2014-2223
Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authen
28RISCO
abrir
Referência
CVE-2009-3020
win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by r
28RISCO
abrir
Referência
CVE-2015-7245
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remot
50RISCO
abrir
anteriorpágina 549 / 748próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.