Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.724exploits catalogados
35.724CVEs com exploração pública
24.695testados em laboratório
22.492 exploits
ReferênciaVexDay Proof
Hex Workshop 5.1.4 - Color Mapping File Local Buffer Overflow (PoC)
CVE-2008-5756doswindows
Buffer overflow in BreakPoint Software Hex Workshop 5.1.4 allows user-assisted attackers to cause a denial of service an
23RISCO
abrir
ReferênciaVexDay Proof
iPhotoAlbum 1.1 - 'header.php' Remote File Inclusion
CVE-2005-2246webappsphp
Multiple PHP remote file inclusion vulnerabilities in iPhotoAlbum 1.1 allow remote attackers to execute arbitrary code v
23RISCO
abrir
Referência
CVE-2010-1069
SQL injection vulnerability in games/game.php in ProArcadeScript allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir
Referência
CVE-2021-20991
Fibaro Home Center Authenticated remote command execution
48RISCO
abrir
Referência
CVE-2021-24610
TranslatePress < 2.0.9 - Authenticated Stored Cross-Site Scripting
23RISCO
abrir
Referência
CVE-2015-1059
Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute
23RISCO
abrir
Referência
CVE-2019-6213
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3,
23RISCO
abrir
Referência
CVE-2016-7626
An issue was discovered in certain Apple products. iOS before 10.2 is affected. tvOS before 10.1 is affected. watchOS be
23RISCO
abrir
Referência
CVE-2017-4915
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration fil
38RISCO
abrir
ReferênciaVexDay Proof
e107 - 'include()' Remote File Upload
CVE-2004-2262webappsphp
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to
28RISCO
abrir
Referência
CVE-2017-17970
Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1
23RISCO
abrir
Referência
CVE-2017-17970
Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1
23RISCO
abrir
Referência
CVE-2013-5573
Cross-site scripting (XSS) vulnerability in the default markup formatter in Jenkins 1.523 allows remote attackers to inj
23RISCO
abrir
ReferênciaVexDay Proof
JBC Explorer 7.20 RC 1 - Remote Code Execution
CVE-2007-5914webappsphp
Direct static code injection vulnerability in dirsys/modules/config/post.php in JBC Explorer 7.20 RC1 and earlier allows
23RISCO
abrir
ReferênciaVexDay Proof
Apple Mac OSX 10.5.0 (Leopard) - vpnd Remote Denial of Service (PoC)
CVE-2007-6276dososx
The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows
23RISCO
abrir
ReferênciaVexDay Proof
verlihub 0.9.8d-RC2 - Remote Command Execution
CVE-2008-5705remotelinux
The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlie
23RISCO
abrir
Referência
CVE-2017-15662
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The atta
23RISCO
abrir
Referência
CVE-2015-6970
The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows r
23RISCO
abrir
Referência
CVE-2014-1635
Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote a
50RISCO
abrir
Referência
CVE-2006-1595
Cross-site scripting (XSS) vulnerability in document/rqmkhtml.php in Claroline 1.7.4 and earlier allows remote attackers
23RISCO
abrir
Referência
CVE-2023-30350
FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin
41RISCO
abrir
Referência
CVE-2014-3110
Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earli
23RISCO
abrir
Referência
CVE-2010-4280
Multiple SQL injection vulnerabilities in Pandora FMS before 3.1.1 allow remote authenticated users to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
X.Org xorg-server 1.1.1-48.13 - Probe for Files (PoC)
CVE-2007-5958dosmultiple
X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in t
23RISCO
abrir
Referência
CVE-2017-3622
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (C
38RISCO
abrir
Referência
CVE-2013-6627
net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1x
23RISCO
abrir
Referência
CVE-2013-6627
net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1x
23RISCO
abrir
ReferênciaVexDay Proof
CDex 1.70b2 (Windows XP SP3) - '.ogg' Local Buffer Overflow
CVE-2009-1039localwindows
Buffer overflow in CDex 1.70b2 allows remote attackers to execute arbitrary code via a crafted Info header in an Ogg Vor
23RISCO
abrir
Referência
CVE-2012-6506
Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.0 for WordPress allow remote atta
23RISCO
abrir
Referência
CVE-2018-10969
SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute ar
23RISCO
abrir
anteriorpágina 563 / 750próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.