Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8.883Nuclei 4.361Metasploit 3.493✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
Webmin 1.910 - 'Package Updates' Remote Command Execution (Metasploit)
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISCO
abrir ↗Referência✓ VexDay Proof
Guestbara 1.2 - Change Admin Login and Password
admin/configuration.php in Guestbara 1.2 and earlier allows remote attackers to modify the e-mail, name, and password of
23RISCO
abrir ↗Referência✓ VexDay Proof
NetVIOS Portal - 'page.asp' SQL Injection
SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
NewsReactor 20070220 - Article Grabbing Remote Buffer Overflow (1)
Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via
23RISCO
abrir ↗Referência✓ VexDay Proof
NewsReactor 20070220 - Article Grabbing Remote Buffer Overflow (2)
Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via
23RISCO
abrir ↗Referência✓ VexDay Proof
News Bin Pro 4.32 - Article Grabbing Remote Unicode Buffer Overflow
Stack-based buffer overflow in NewsBin Pro 4.32 allows remote attackers to cause a denial of service or execute arbitrar
23RISCO
abrir ↗Referência✓ VexDay Proof
Mercur IMAPD 5.00.14 (Windows x86) - Remote Denial of Service
Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, a
28RISCO
abrir ↗Referência✓ VexDay Proof
Mercur Messaging 2005 (Windows 2000 SP4) - IMAP 'Subscribe' Remote Overflow
Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSC
35RISCO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.0 (OSX) - 'header()' Space Trimming Buffer Underflow
Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by pas
23RISCO
abrir ↗Referência✓ VexDay Proof
MPM Chat 2.5 - 'view.php?logi' Local File Inclusion
Directory traversal vulnerability in view.php in MPM Chat 2.5 allows remote attackers to include and execute arbitrary l
23RISCO
abrir ↗Referência✓ VexDay Proof
ScriptMagix Lyrics 2.0 - 'index.php?recid' SQL Injection
SQL injection vulnerability in index.php in ScriptMagix Lyrics 2.0 and earlier allows remote attackers to execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
ScriptMagix Recipes 2.0 - 'index.php?catid' SQL Injection
SQL injection vulnerability in index.php in ScriptMagix Recipes 2.0 and earlier allows remote attackers to execute arbit
23RISCO
abrir ↗Referência✓ VexDay Proof
ScriptMagix Photo Rating 2.0 - SQL Injection
SQL injection vulnerability in viewcomments.php in ScriptMagix Photo Rating 2.0 and earlier allows remote attackers to e
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP DB Designer 1.02 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PHP DB Designer 1.02 and earlier allow remote attackers to execute
28RISCO
abrir ↗Referência✓ VexDay Proof
Active Photo Gallery - 'catid' SQL Injection
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Photo Gallery allows remote attackers to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke Module Eve-Nuke 0.1 - 'mysql.php' Remote File Inclusion
PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remot
23RISCO
abrir ↗Referência✓ VexDay Proof
Kaqoo Auction - 'install_root' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to exec
23RISCO
abrir ↗Referência✓ VexDay Proof
Picture-Engine 1.2.0 - 'wall.php?cat' SQL Injection
SQL injection vulnerability in wall.php in Picture-Engine 1.2.0 and earlier allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
XOOPS Module RM+Soft Gallery 1.0 - Blind SQL Injection
SQL injection vulnerability in categos.php in the RM+Soft Gallery (rmgallery) 1.0 module for Xoops allows remote attacke
23RISCO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Kshop 1.17 - 'id' SQL Injection
SQL injection vulnerability in product_details.php in the Kshop 1.17 and earlier module for Xoops allows remote attacker
23RISCO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Tiny Event 1.01 - 'id' SQL Injection
SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 and earlier module for Xoops allows remote a
23RISCO
abrir ↗Referência✓ VexDay Proof
BT-sondage 1.12 - 'gestion_sondage.php' Remote File Inclusion
PHP remote file inclusion vulnerability in utilitaires/gestion_sondage.php in BT-Sondage 112 allows remote attackers to
23RISCO
abrir ↗Referência✓ VexDay Proof
XOOPS Module MyAds Bug Fix 2.04jp - 'index.php' SQL Injection
SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to exe
23RISCO
abrir ↗Referência✓ VexDay Proof
Really Simple PHP and Ajax (RSPA) 2007-03-23 - Remote File Inclusion
Multiple directory traversal vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 allow remote attackers to i
23RISCO
abrir ↗Referência✓ VexDay Proof
Pathos CMS 0.92-2 - 'warn.php' Remote File Inclusion
PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attac
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP121 Instant Messenger 2.2 - Local File Inclusion
PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbi
23RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft Word 2007 - Multiple Vulnerabilities
Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application cr
28RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows - '.hlp' Local HEAP Overflow (PoC)
Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a cr
28RISCO
abrir ↗Referência✓ VexDay Proof
Beryo 2.0 - 'downloadpic.php?chemin' Remote File Disclosure
Directory traversal vulnerability in downloadpic.php in Beryo 2.0, and possibly other versions including 2.4, allows rem
23RISCO
abrir ↗Referência✓ VexDay Proof
SmodCMS 2.10 - Slownik ssid SQL Injection
SQL injection vulnerability in index.php in the slownik module in SmodCMS 2.10 and earlier allows remote attackers to ex
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.