Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.724exploits catalogados
35.724CVEs com exploração pública
24.695testados em laboratório
22.492 exploits
ReferênciaVexDay Proof
TOWeLS 0.1 - 'scripture.php' Remote File Inclusion
CVE-2007-5628webappsphp
PHP remote file inclusion vulnerability in src/scripture.php in The Online Web Library Site (TOWels) 0.1 allows remote a
28RISCO
abrir
ReferênciaVexDay Proof
BBPortalS 2.0 - Blind SQL Injection
CVE-2007-5630webappsphp
SQL injection vulnerability in tnews.php in BBsProcesS BBPortalS 1.5.10 through 2.0 allows remote attackers to execute a
23RISCO
abrir
ReferênciaVexDay Proof
PHP Project Management 0.8.10 - Multiple Local/Remote File Inclusions
CVE-2007-5641webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers t
35RISCO
abrir
Referência
CVE-2007-5649
Cross-site scripting (XSS) vulnerability in lostpwd.php in Creative Digital Resources SocketMail 2.2.1 allows remote att
23RISCO
abrir
Referência
CVE-2023-3219
EventON < 2.1.2 - Unauthenticated Post Access via IDOR
38RISCO
abrir
ReferênciaVexDay Proof
Litespeed Web Server 3.2.3 - Source Code Disclosure
CVE-2007-5654remotemultiple
LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00
35RISCO
abrir
ReferênciaVexDay Proof
InstaGuide Weather Script 1.0 - 'index.php' Local File Inclusion
CVE-2007-5674webappsphp
Directory traversal vulnerability in index.php in InstaGuide Weather (aka Weather for PHP) 1.0, when magic_quotes_gpc is
23RISCO
abrir
Referência
CVE-2007-5679
SQL injection vulnerability in index.php in DeeEmm.com DM CMS 0.7.0.Beta allows remote attackers to execute arbitrary SQ
23RISCO
abrir
ReferênciaVexDay Proof
PHP Image 1.2 - Multiple Remote File Inclusions
CVE-2007-5697webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHP Image 1.2 allow remote attackers to execute arbitrary PHP code
23RISCO
abrir
ReferênciaVexDay Proof
Sony CONNECT Player 4.x - '.m3u' Local Stack Overflow
CVE-2007-5709localwindows
Stack-based buffer overflow in Sony SonicStage CONNECT Player (CP) 4.3 allows remote attackers to execute arbitrary code
28RISCO
abrir
ReferênciaVexDay Proof
ProfileCMS 1.0 - Arbitrary File Upload
CVE-2007-5720webappsphp
Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and ex
23RISCO
abrir
ReferênciaVexDay Proof
Jakarta Slide 2.1 RC1 - Remote File Disclosure
CVE-2007-5731remotemultiple
Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read
23RISCO
abrir
Referência
CVE-2017-9413
Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attacke
23RISCO
abrir
Referência
CVE-2017-9430
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RISCO
abrir
Referência
CVE-2017-9730
SQL injection vulnerability in rdr.php in nuevoMailer version 6.0 and earlier allows remote attackers to execute arbitra
23RISCO
abrir
Referência
CVE-2017-9769
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpe
60RISCO
abrir
Referência
CVE-2017-9791
CVE-2017-9791CRITICALsob ataque
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RISCO
abrir
Referência
CVE-2018-0296
CVE-2018-0296HIGHsob ataque
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISCO
abrir
Referência
CVE-2018-0296
CVE-2018-0296HIGHsob ataque
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISCO
abrir
Referência
CVE-2018-0710
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe
28RISCO
abrir
Referência
CVE-2018-0710
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe
28RISCO
abrir
Referência
CVE-2018-0748
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and
23RISCO
abrir
Referência
CVE-2018-0752
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RISCO
abrir
Referência
CVE-2018-0823
The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege
23RISCO
abrir
Referência
CVE-2018-0838
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RISCO
abrir
ReferênciaVexDay Proof
Flatnuke 3 - Remote Cookie Manipulation / Privilege Escalation
CVE-2007-5771webappsphp
Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie.
23RISCO
abrir
ReferênciaVexDay Proof
Flatnuke 3 - Remote Command Execution / Privilege Escalation
CVE-2007-5773webappsphp
Cross-site request forgery (CSRF) vulnerability in index.php in the File Manager module in Flatnuke 3 allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
emagiC CMS.Net 4.0 - 'emc.asp' SQL Injection
CVE-2007-5783webappsasp
SQL injection vulnerability in emc.asp in emagiC CMS.Net 4.0 allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
ReferênciaVexDay Proof
GuppY 4.6.3 - 'index.php?selskin' Remote File Inclusion
CVE-2007-5845webappsphp
Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include an
23RISCO
abrir
ReferênciaVexDay Proof
ASP Message Board 2.2.1c - SQL Injection
CVE-2007-5887webappsasp
SQL injection vulnerability in boards/printer.asp in ASP Message Board 2.2.1c allows remote attackers to execute arbitra
23RISCO
abrir
anteriorpágina 568 / 750próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.