Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.724exploits catalogados
35.724CVEs com exploração pública
24.695testados em laboratório
22.492 exploits
Referência
CVE-2009-2361
SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arb
23RISCO
abrir
Referência
CVE-2018-16517
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a deni
23RISCO
abrir
Referência
CVE-2018-16517
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a deni
23RISCO
abrir
Referência
CVE-2018-8817
Wampserver before 3.1.3 has CSRF in add_vhost.php.
23RISCO
abrir
Referência
CVE-2008-1247
The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts,
23RISCO
abrir
ReferênciaVexDay Proof
VRNews 1.1.1 - 'admin.php' Remote Security Bypass
CVE-2007-3611webappsphp
admin.php in VRNews 1.1.1, and possibly other 1.x versions, does not require authentication, which allows remote attacke
23RISCO
abrir
Referência
CVE-2011-1974
NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Serve
23RISCO
abrir
Referência
CVE-2015-2553
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RISCO
abrir
Referência
CVE-2015-2553
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RISCO
abrir
ReferênciaVexDay Proof
PUMA 1.0 RC 2 - 'config.php' Remote File Inclusion
CVE-2006-4713webappsphp
PHP remote file inclusion vulnerability in config.php in PSYWERKS PUMA 1.0 RC2 allows remote attackers to execute arbitr
23RISCO
abrir
Referência
CVE-2010-2018
Directory traversal vulnerability in downlot.php in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to read arbitrar
38RISCO
abrir
ReferênciaVexDay Proof
compteur 2.0 - 'param_editor.php' Remote File Inclusion
CVE-2006-5259webappsphp
PHP remote file inclusion vulnerability in param_editor.php in Compteur 2 allows remote attackers to execute arbitrary P
23RISCO
abrir
Referência
CVE-2015-7901
Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execut
23RISCO
abrir
ReferênciaVexDay Proof
Segue CMS 1.5.8 - 'themesdir' Remote File Inclusion
CVE-2006-5497webappsphp
PHP remote file inclusion vulnerability in themes/program/themesettings.inc.php in Segue CMS 1.5.8 and earlier, when reg
23RISCO
abrir
Referência
CVE-2015-10137
Website Contact Form With File Upload <= 1.3.4 - Arbitrary File Upload
63RISCO
abrir
ReferênciaVexDay Proof
a-ConMan 3.2b - 'common.inc.php' Remote File Inclusion
CVE-2006-6078webappsphp
PHP remote file inclusion vulnerability in common.inc.php in a-ConMan 3.2 beta allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
CM68 News 12.02.06 - 'addpth' Remote File Inclusion
CVE-2006-6462webappsphp
PHP remote file inclusion vulnerability in engine/oldnews.inc.php in CM68 News 12.02.06 allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
Macromedia Flash 8 (Flash8b.ocx) Internet Explorer 7 - Denial of Service
CVE-2006-6827doswindows
Flash8b.ocx in Macromedia Flash 8 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a
23RISCO
abrir
ReferênciaVexDay Proof
shibby shop 2.2 - Multiple Vulnerabilities
CVE-2008-2882webappsphp
upgrade.asp in sHibby sHop 2.2 and earlier does not require administrative authentication, which allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
emuCMS 0.3 - 'cat_id' SQL Injection
CVE-2008-2891webappsphp
SQL injection vulnerability in index.php in eMuSOFT emuCMS 0.3 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows Vista - Access Violation from Limited Account (Blue Screen of Death)
CVE-2008-4510doswindows
Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page
23RISCO
abrir
ReferênciaVexDay Proof
Zeeways PHOTOVIDEOTUBE 1.1 - Authentication Bypass
CVE-2008-5042webappsphp
Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks
23RISCO
abrir
Referência
CVE-2022-36551
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.
23RISCO
abrir
Referência
CVE-2015-5889
rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors inv
38RISCO
abrir
Referência
CVE-2016-3989
The NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME
23RISCO
abrir
Referência
CVE-2017-3629
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RISCO
abrir
Referência
CVE-2017-3629
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RISCO
abrir
Referência
CVE-2020-25901
Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious we
23RISCO
abrir
Referência
CVE-2012-5452
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web
23RISCO
abrir
Referência
CVE-2012-5452
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web
23RISCO
abrir
anteriorpágina 575 / 750próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.