Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8.883Nuclei 4.361Metasploit 3.493✓ só verificadosrecentespopularesrisco
19.066 exploits
Exploit-DB✓ VexDay Proof
Microsoft SQL Server - Payload Execution (Metasploit)
The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3)
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MHonArc 2.6.16 - Tag Nesting Remote Denial of Service
MHonArc 2.6.16 allows remote attackers to cause a denial of service (CPU consumption) via start tags that are placed wit
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server - Payload Execution (Metasploit)
The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in pla
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component JotLoader 2.2.1 - Local File Inclusion
Directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers t
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mafya Oyun Scrpti - 'profil.php' SQL Injection
SQL injection vulnerability in profil.php in Mafya Oyun Scrpti (aka Mafia Game Script) allows remote attackers to execut
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oto Galery 1.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Oto Galeri Sistemi 1.0 allow remote attackers to execute arbitrary SQL command
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Redmine SCM Repository - Arbitrary Command Execution (Metasploit)
Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attacke
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ero Auktion 2010 - 'item.php' SQL Injection
SQL injection vulnerability in item.php in Ero Auktion 2010 allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.37-rc2 - 'ACPI custom_method' Local Privilege Escalation
drivers/acpi/debugfs.c in the Linux kernel before 3.0 allows local users to modify arbitrary kernel memory locations by
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.37-rc2 - 'ACPI custom_method' Local Privilege Escalation
The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ecava IntegraXor Remote - ActiveX Buffer Overflow (PoC)
Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraX
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Projekt Shop - 'details.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL comma
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PayPal Shop Digital - SQL Injection
SQL injection vulnerability in view_item.php in MH Products Pay Pal Shop Digital allows remote attackers to execute arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Download Center 2.2 - SQL Injection
SQL injection vulnerability in admin/login.php in MHP DownloadScript (aka MH Products Download Center) 2.2 allows remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mafia Game Script - SQL Injection
SQL injection vulnerability in profil.php in Mafya Oyun Scrpti (aka Mafia Game Script) allows remote attackers to execut
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MHP Downloadshop - SQL Injection
SQL injection vulnerability in view_item.php in MH Products MHP Downloadshop allows remote attackers to execute arbitrar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Easy Online Shop - SQL Injection
SQL injection vulnerability in content.php in MH Products Easy Online Shop allows remote attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Win32k Pointer Dereferencement (PoC) (MS10-098)
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate user-
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Radius Manager 3.6 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Radius Manager 3.8.0 allow remote authenticated administrators to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Immo Makler Script - SQL Injection
SQL injection vulnerability in news.php in Immo Makler allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Exim4 < 4.69 - string_format Function Heap Buffer Overflow (Metasploit)
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to exe
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe PDF - Escape EXE Social Engineering (No JavaScript) (Metasploit)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component JRadio - Local File Inclusion
Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to r
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe PDF - Embedded EXE Social Engineering (Metasploit)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Exim4 < 4.69 - string_format Function Heap Buffer Overflow (Metasploit)
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specif
91RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Altap Salamander 2.5 PE Viewer - Local Buffer Overflow (Metasploit)
Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (Englis
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Tivoli Storage Manager (TSM) - Local Privilege Escalation
Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
gitWeb 1.7.3.3 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web s
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'search.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.1.3712 allows remote attack
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 8 - CSS Parser
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in msh
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.