Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.772exploits catalogados
35.760CVEs com exploração pública
24.695testados em laboratório
22.523 exploits
Referência
CVE-2013-2143
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update
50RISCO
abrir
Referência
CVE-2025-5640
PX4-Autopilot TRAJECTORY_REPRESENTATION_WAYPOINTS Message mavlink_receiver.cpp stack-based overflow
33RISCO
abrir
Referência
CVE-2014-7186
The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial o
35RISCO
abrir
Referência
CVE-2014-7200
Cross-site scripting (XSS) vulnerability in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extensi
23RISCO
abrir
ReferênciaVexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
CVE-2009-1028doswindows
Stack-based buffer overflow in ediSys eZip Wizard 3.0 allows remote attackers to execute arbitrary code via a crafted .z
50RISCO
abrir
ReferênciaVexDay Proof
WordPress MU < 2.7 - 'HOST' HTTP Header Cross-Site Scripting
CVE-2009-1030webappsphp
Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPr
23RISCO
abrir
ReferênciaVexDay Proof
FreeBSD 7.0/7.1 - 'ktimer' Local Privilege Escalation
CVE-2009-1041localfreebsd
The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel
23RISCO
abrir
ReferênciaVexDay Proof
Bloginator 1a - SQL Injection / Command Injection (via Cookie Bypass )
CVE-2009-1049webappsphp
SQL injection vulnerability in articleCall.php in Bloginator 1A allows remote attackers to execute arbitrary SQL command
23RISCO
abrir
ReferênciaVexDay Proof
eXeScope 6.50 - Local Buffer Overflow
CVE-2009-1063localwindows
Buffer overflow in eXeScope 6.50 allows user-assisted remote attackers to execute arbitrary code via a crafted executabl
23RISCO
abrir
ReferênciaVexDay Proof
BS.Player 2.34 Build 980 - '.bsl' Local Buffer Overflow (SEH)
CVE-2009-1068localwindows
Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote
28RISCO
abrir
ReferênciaVexDay Proof
Icarus 2.0 - '.pgn' Local Stack Overflow (SEH)
CVE-2009-1071localwindows
Stack-based buffer overflow in Icarus 2.0 allows remote attackers to cause a denial of service (application crash) or ex
23RISCO
abrir
ReferênciaVexDay Proof
PPLive 1.9.21 - '/LoadModule' URI Handlers Argument Injection
CVE-2009-1087remotewindows
Multiple argument injection vulnerabilities in PPLive.exe in PPLive 1.9.21 and earlier allow remote attackers to execute
23RISCO
abrir
Referência
CVE-2005-2428
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hid
60RISCO
abrir
Referência
CVE-2023-46805
CVE-2023-46805HIGHsob ataqueransomware
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RISCO
abrir
Referência
CVE-2023-22527
CVE-2023-22527CRITICALsob ataqueransomware
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISCO
abrir
Referência
CVE-2026-10062
TRENDnet TEW-432BRP formSetRoute stack-based overflow
41RISCO
abrir
Referência
CVE-2013-2684
Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web
23RISCO
abrir
Referência
CVE-2013-2748
Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.
28RISCO
abrir
ReferênciaVexDay Proof
Aqua CMS - 'Username' SQL Injection
CVE-2009-1317webappsphp
Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
Jamroom 4.0.2 - 't' Local File Inclusion
CVE-2009-1318webappsphp
Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions
23RISCO
abrir
Referência
CVE-2009-4726
Directory traversal vulnerability in download.php in Quickdev 4 PHP allows remote attackers to read arbitrary files via
23RISCO
abrir
ReferênciaVexDay Proof
ASX to MP3 Converter - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1324doswindows
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RISCO
abrir
ReferênciaVexDay Proof
ASX to MP3 Converter 3.0.0.7 - '.m3u' Universal Stack Overflow
CVE-2009-1324localwindows
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RISCO
abrir
Referência
CVE-2013-3739
Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read
23RISCO
abrir
Referência
CVE-2013-4103
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
23RISCO
abrir
Referência
CVE-2024-45519
CVE-2024-45519CRITICALsob ataque
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISCO
abrir
Referência
CVE-2015-0936
Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remot
60RISCO
abrir
Referência
CVE-2009-4751
SQL injection vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary SQ
23RISCO
abrir
ReferênciaVexDay Proof
CoolPlayer Portable 2.19.1 - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1437doswindows
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows rem
28RISCO
abrir
ReferênciaVexDay Proof
CoolPlayer Portable 2.19.1 - '.m3u' Local Buffer Overflow (1)
CVE-2009-1437localwindows
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows rem
28RISCO
abrir
anteriorpágina 586 / 751próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.