Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
Microsoft Windows Wordpad - '.doc' File Local Denial of Service (PoC)
The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows r
35RISCO
abrir ↗Referência✓ VexDay Proof
Sepal SPBOARD 4.5 - 'board.cgi' Remote Command Execution
board.cgi in Sepal SPBOARD 4.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the fil
23RISCO
abrir ↗Referência✓ VexDay Proof
Maran PHP Shop - 'prodshow.php' SQL Injection
SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
Groone's GLink ORGanizer 2.1 - 'cat' Blind SQL Injection
SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
YourFreeWorld Reminder Service - SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Reminder Service Script allows remote attackers to execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
YourFreeWorld Blog Blaster - 'tr.php' SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Blog Blaster Script allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
Amaya Web Editor 11.0 - XML / HTML Parser
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary
50RISCO
abrir ↗Referência✓ VexDay Proof
YourFreeWorld Classifieds Hosting - SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arb
23RISCO
abrir ↗Referência✓ VexDay Proof
YourFreeWorld Scrolling Text Ads - SQL Injection
SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arb
23RISCO
abrir ↗Referência✓ VexDay Proof
NetRisk 2.0 - Cross-Site Scripting / SQL Injection
Cross-site scripting (XSS) vulnerability in error.php in NetRisk 2.0 and earlier allows remote attackers to inject arbit
23RISCO
abrir ↗Referência✓ VexDay Proof
YourFreeWorld Downline Builder - 'tr.php' SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
Logz podcast CMS 1.3.1 - 'art' SQL Injection
SQL injection vulnerability in fichiers/add_url.php in Logz podcast CMS 1.3.1, when magic_quotes_gpc is disabled, allows
23RISCO
abrir ↗Referência✓ VexDay Proof
YourFreeWorld Classifieds Blaster - SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Blaster Script allows remote attackers to execute arb
23RISCO
abrir ↗Referência✓ VexDay Proof
Article Publisher PRO 1.5 - Authentication Bypass
SQL injection vulnerability in admin/admin.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
Article Publisher PRO - 'userid' SQL Injection
SQL injection vulnerability in contact_author.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
RX Maxsoft - 'fotoID' SQL Injection
SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
Visagesoft eXPert PDF ViewerX - 'VSPDFViewerX.ocx' File Overwrite
Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remo
23RISCO
abrir ↗Referência✓ VexDay Proof
DjVu - ActiveX Control 3.0 ImageURL Property Overflow
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers
50RISCO
abrir ↗Referência✓ VexDay Proof
MW6 Aztec - ActiveX 'Aztec.dll' Remote Insecure Method
Multiple insecure method vulnerabilities in MW6 Technologies Aztec ActiveX control (AZTECLib.MW6Aztec, Aztec.dll) 3.0.0.
23RISCO
abrir ↗Referência✓ VexDay Proof
MW6 Barcode - ActiveX 'Barcode.dll' Insecure Method
Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.
23RISCO
abrir ↗Referência✓ VexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to inject arbitrar
23RISCO
abrir ↗Referência✓ VexDay Proof
ProFTPd - 'mod_mysql' Authentication Bypass
SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL co
45RISCO
abrir ↗Referência✓ VexDay Proof
MW6 Datamatrix - ActiveX 'Datamatrix.dll' Insecure Method
Multiple insecure method vulnerabilities in MW6 Technologies DataMatrix ActiveX control (DATAMATRIXLib.MW6DataMatrix, Da
23RISCO
abrir ↗Referência✓ VexDay Proof
MW6 PDF417 - ActiveX 'MW6PDF417.dll' Remote Insecure Method
Multiple insecure method vulnerabilities in MW6 Technologies PDF417 ActiveX control (MW6PDF417Lib.PDF417, MW6PDF417.dll)
23RISCO
abrir ↗Referência✓ VexDay Proof
U-Mail Webmail 4.91 - 'edit.php' Arbitrary File Write
webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files v
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPX 3.5.16 - 'news_id' SQL Injection
SQL injection vulnerability in admin/includes/news.inc.php in PHPX 3.5.16, when magic_quotes_gpc is disabled, allows rem
23RISCO
abrir ↗Referência✓ VexDay Proof
Bloggie Lite 0.0.2 Beta - Insecure Cookie Handling / SQL Injection
SQL injection vulnerability in genscode.php in myWebland Bloggie Lite 0.0.2 beta allows remote attackers to execute arbi
23RISCO
abrir ↗Referência✓ VexDay Proof
FTP Now 2.6 Server - Response Remote Crash (PoC)
Heap-based buffer overflow in Network-Client FTP Now 2.6, and possibly other versions, allows remote FTP servers to caus
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component JooBlog 0.1.1 - 'PostID' SQL Injection
SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbi
23RISCO
abrir ↗Referência✓ VexDay Proof
DevelopItEasy Membership System 1.3 - Authentication Bypass
Multiple SQL injection vulnerabilities in Develop It Easy Membership System 1.3 allow remote attackers to execute arbitr
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.