Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.211exploits catalogados
36.421CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.464Referência 23.022GitHub PoC 15.027VulnCheck XDB 8.846Nuclei 4.361Metasploit 3.491✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
Nortel SSL VPN Linux Client 6.0.3 - Local Privilege Escalation
The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 10
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke 8.0 Final - HTTP Referers SQL Injection
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" blo
35RISCO
abrir ↗Referência✓ VexDay Proof
News Bin Pro 5.33 - '.nbi' Local Buffer Overflow
Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
TurboFTP Server 5.30 Build 572 - 'newline/LIST' Multiple Remote Denial of Service Vulnerabilities
TurboFTP 5.30 Build 572 allows remote servers to cause a denial of service (CPU consumption) via a response with a large
23RISCO
abrir ↗Referência✓ VexDay Proof
Photoshop CS2/CS3 / Paint Shop Pro 11.20 - '.png' Local Buffer Overflow
Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a craf
35RISCO
abrir ↗Referência✓ VexDay Proof
News-Letterman 1.1 - 'eintrag.php?sqllog' Remote File Inclusion
PHP remote file inclusion vulnerability in eintrag.php in Weltennetz News-Letterman 1.1 allows remote attackers to execu
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.1 - 'substr_compare()' Information Leak
Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sens
23RISCO
abrir ↗Referência✓ VexDay Proof
XOOPS Module WF-Links 1.03 - 'cid' SQL Injection
SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote att
23RISCO
abrir ↗Referência✓ VexDay Proof
TinyIdentD 2.2 - Remote Buffer Overflow
Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long s
50RISCO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke Module splattforum 4.0 RC1 - Local File Inclusion
Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allo
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPGlossar 0.8 - 'format_menue' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PHPGlossar 0.8 allow remote attackers to execute arbitrary PHP cod
23RISCO
abrir ↗Referência✓ VexDay Proof
CA BrightStor Backup 11.5.2.0 - 'caloggderd.exe' Denial of Service
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RISCO
abrir ↗Referência✓ VexDay Proof
CA BrightStor Backup 11.5.2.0 - 'Mediasvr.exe' Denial of Service
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RISCO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Core - 'viewcat.php' SQL Injection
SQL injection vulnerability in viewcat.php in the Core module for Xoops allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Library - 'viewcat.php' SQL Injection
SQL injection vulnerability in viewcat.php in the Library module for Xoops allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Tutoriais - 'viewcat.php' SQL Injection
SQL injection vulnerability in viewcat.php in the Tutoriais module for Xoops allows remote attackers to execute arbitrar
23RISCO
abrir ↗Referência✓ VexDay Proof
MySpeach 3.0.7 - Local/Remote File Inclusion
Directory traversal vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier allows remote attackers to inclu
23RISCO
abrir ↗Referência✓ VexDay Proof
MyBloggie 2.1.6 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Referência✓ VexDay Proof
Winamp 5.3 - '.wmv' Remote Denial of Service
Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a
23RISCO
abrir ↗Referência✓ VexDay Proof
AimStats 3.2 - 'process.php?update' Remote Code Execution
Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into confi
35RISCO
abrir ↗Referência✓ VexDay Proof
Mozzers SubSystem final - 'subs.php' Remote Code Execution
Static code injection vulnerability in add.php in Mozzers SubSystem 1.0 allows remote attackers to inject PHP code into
23RISCO
abrir ↗Referência✓ VexDay Proof
WEBInsta FM 0.1.4 - 'login.php' absolute_path Remote File Inclusion
PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attack
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP-Ring Webring System 0.9 - SQL Injection
SQL injection vulnerability in index.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9 allows remote attackers
23RISCO
abrir ↗Referência✓ VexDay Proof
LeadTools Raster Variant - 'LTRVR14e.dll' Remote File Overwrite
A certain ActiveX control in LeadTools Raster Variant Object Library (LTRVR14e.dll) 14.5.0.44 allows remote attackers to
23RISCO
abrir ↗Referência✓ VexDay Proof
Virtual CD 9.0.0.2 - 'vc9api.DLL' Remote Shell Commands Execution
The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitra
23RISCO
abrir ↗Referência✓ VexDay Proof
BtiTracker 1.4.1 - Become Admin SQL Injection
Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to e
23RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 6 / Ademco co. ltd. ATNBaseLoader100 Module - Remote Buffer Overflow
Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6,
35RISCO
abrir ↗Referência✓ VexDay Proof
FlaP 1.0b - 'pachtofile' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary P
23RISCO
abrir ↗Referência✓ VexDay Proof
vBulletin vBGSiteMap 2.41 - 'root' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 f
23RISCO
abrir ↗Referência✓ VexDay Proof
OpenBASE 0.6a - 'root_prefix' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.