Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8.883Nuclei 4.361Metasploit 3.493✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
TWiki 4.2.0 - 'configure' Remote File Disclosure
Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide
23RISCO
abrir ↗Referência✓ VexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
PHP remote file inclusion vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote atta
28RISCO
abrir ↗Referência✓ VexDay Proof
FreeBSD 7.0-RELEASE - Telnet Daemon Privilege Escalation
sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a metho
23RISCO
abrir ↗Referência✓ VexDay Proof
Simple PHP News 1.0 - Remote Command Execution
Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
opensurveypilot 1.2.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in administration/user/lib/group.inc.php in OpenSurveyPilot (osp) 1.2.1 and earl
23RISCO
abrir ↗Referência✓ VexDay Proof
Data Dynamics ActiveBar - ActiveX 'actbar3.ocx 3.1' Insecure Methods
The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite
23RISCO
abrir ↗Referência✓ VexDay Proof
TPTEST 3.1.7 - Stack Buffer Overflow (PoC)
Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remo
28RISCO
abrir ↗Referência✓ VexDay Proof
Web Content System 2.7.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in manage/javascript/formjavascript.php in Ay System Solutions Web Content Syste
23RISCO
abrir ↗Referência✓ VexDay Proof
Bea Weblogic Apache Connector - Code Execution / Denial of Service
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10
60RISCO
abrir ↗Referência✓ VexDay Proof
Adobe Acrobat Reader - JBIG2 Local Buffer Overflow (PoC) (2)
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitra
60RISCO
abrir ↗Referência✓ VexDay Proof
eCentrex VOIP Client module - 'uacomx.ocx 2.0.1' Remote Buffer Overflow
Buffer overflow in the IUAComFormX ActiveX control in uacomx.ocx 2.0.1 in the eCentrex VOIP Client module allows remote
23RISCO
abrir ↗Referência✓ VexDay Proof
dotCMS 1.6 - 'id' Local File Inclusion
Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (
23RISCO
abrir ↗Referência✓ VexDay Proof
Advanced Electron Forum 1.0.6 - Remote Code Execution
Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code em
23RISCO
abrir ↗Referência✓ VexDay Proof
Sejoong Namo ActiveSquare 6 - 'NamoInstaller.dll' ActiveX Buffer Overflow
Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo
23RISCO
abrir ↗Referência✓ VexDay Proof
Maian Recipe 1.2 - Insecure Cookie Handling
admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component ionFiles 4.4.2 - File Disclosure
Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remo
43RISCO
abrir ↗Referência✓ VexDay Proof
Coppermine Photo Gallery 1.4.18 - Local File Inclusion / Remote Code Execution
Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gall
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.4 ionCube - 'ioncube_read_file' Safe Mode / disable_functions Bypass
ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_funct
23RISCO
abrir ↗Referência✓ VexDay Proof
WSN Guest 1.23 - 'Search' SQL Injection
SQL injection vulnerability in search.php in WSN Guest 1.23 allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir ↗Referência✓ VexDay Proof
phpAuction GPL Enhanced 2.51 - 'profile.php' SQL Injection
SQL injection vulnerability in profile.php in PHPAuction GPL Enhanced 2.51 allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
PowerNews 2.5.4 - 'newsid' SQL Injection
SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remot
23RISCO
abrir ↗Referência✓ VexDay Proof
SimpleBlog 3.0 - 'comments_get.asp?id' SQL Injection
SQL injection vulnerability in comments_get.asp in SimpleBlog 3.0 allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir ↗Referência✓ VexDay Proof
Rising AntiVirus Online Scanner - Insecure Method Flaw
Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner all
28RISCO
abrir ↗Referência✓ VexDay Proof
Symphony 1.7.01 (non-patched) - Remote Code Execution
SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attack
23RISCO
abrir ↗Referência✓ VexDay Proof
events Calendar 1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in panel/common/theme/default/header_setup.php in WebBiscuits Software Events Ca
23RISCO
abrir ↗Referência✓ VexDay Proof
YapBB 1.2 - 'forumID' Blind SQL Injection
SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL co
23RISCO
abrir ↗Referência✓ VexDay Proof
webSPELL 4.2.0e - 'page' Blind SQL Injection
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to inc
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPBasket - 'pro_id' SQL Injection
SQL injection vulnerability in product.php in PHPBasket allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir ↗Referência✓ VexDay Proof
Dyncms Release 6 - 'x_admindir' Remote File Inclusion
PHP remote file inclusion vulnerability in 0_admin/modules/Wochenkarte/frontend/index.php in DynCMS 6 and earlier allows
23RISCO
abrir ↗Referência✓ VexDay Proof
Hex Workshop 6.0 - '.hex' Local Code Execution
Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions all
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.