Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.104GitHub PoC 15.075VulnCheck XDB 8.883Nuclei 4.365Metasploit 3.493✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
Chaussette 080706 - '_BASE' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Chaussette 080706 and earlier allow remote attackers to execute ar
28RISCO
abrir ↗Referência✓ VexDay Proof
KML share 1.1 - 'region.php?layer' Remote File Disclosure
Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .
23RISCO
abrir ↗Referência✓ VexDay Proof
SFS EZ Hot or Not - 'phid' SQL Injection
SQL injection vulnerability in viewcomments.php in Scripts For Sites (SFS) EZ Hot or Not allows remote attackers to exec
23RISCO
abrir ↗Referência✓ VexDay Proof
MyPHP Forum 3.0 - Edit Topics / Blind SQL Injection
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL co
23RISCO
abrir ↗Referência✓ VexDay Proof
POWERGAP 2003 - 's0x.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in POWERGAP allow remote attackers to execute arbitrary PHP code via
28RISCO
abrir ↗Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.5 (Windows x86) - Admin Reset Password
The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before
23RISCO
abrir ↗Referência✓ VexDay Proof
Google Chrome 0.2.149.27 - Denial of Service
Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a den
23RISCO
abrir ↗Referência✓ VexDay Proof
phpBB Garage 1.2.0 Beta3 - SQL Injection
SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Referência✓ VexDay Proof
Rayzz Script 2.0 - Local/Remote File Inclusion
PHP remote file inclusion vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote
23RISCO
abrir ↗Referência✓ VexDay Proof
RealPlayer 11 - '.au' Denial of Service
A certain ActiveX control in RealNetworks RealPlayer 11 allows remote attackers to cause a denial of service (applicatio
23RISCO
abrir ↗Referência✓ VexDay Proof
tellmatic 1.0.7 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in tellmatic 1.0.7 allow remote attackers to execute arbitrary PHP co
23RISCO
abrir ↗Referência✓ VexDay Proof
Snitz Forums 2000 - 'Active.asp' SQL Injection
SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Referência✓ VexDay Proof
Mambo Component bigAPE-Backup 1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allow
23RISCO
abrir ↗Referência✓ VexDay Proof
Texas Imperial Software WFTPD 3.23 - 'SIZE' Remote Buffer Overflow
Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands.
50RISCO
abrir ↗Referência✓ VexDay Proof
OpenSSL < 0.9.7l/0.9.8d - SSLv2 Client Crash
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier
28RISCO
abrir ↗Referência✓ VexDay Proof
Empire CMS 3.7 - 'checklevel.php' Remote File Inclusion
PHP remote file inclusion vulnerability in e/class/CheckLevel.php in Phome Empire CMS 3.7 and earlier allows remote atta
23RISCO
abrir ↗Referência✓ VexDay Proof
SerWeb 2.0.0 dev1 2007-02-20 - Multiple Local/Remote File Inclusion Vulnerabilities
Multiple PHP remote file inclusion vulnerabilities in SerWeb 2.0.0 dev1 and earlier allow remote attackers to execute ar
23RISCO
abrir ↗Referência✓ VexDay Proof
HP Compaq Notebooks - ActiveX Remote Code Execution
The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 i
23RISCO
abrir ↗Referência✓ VexDay Proof
XChat 2.6.7 (Windows) - Remote Denial of Service
Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via un
23RISCO
abrir ↗Referência✓ VexDay Proof
Web3news 0.95 - 'PHPSECURITYADMIN_PATH' Remote File Inclusion
PHP remote file inclusion vulnerability in security/include/_class.security.php in Web3news 0.95 and earlier, when regis
23RISCO
abrir ↗Referência✓ VexDay Proof
ClamAV 0.91.2 - libclamav MEW PE Buffer Overflow
Integer overflow in libclamav in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MEW
28RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! / Mambo Component rsgallery 2.0b5 - 'catid' SQL Injection
SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and
23RISCO
abrir ↗Referência✓ VexDay Proof
SineCMS 2.3.4 - Calendar SQL Injection
Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and earlier allow remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Referência✓ VexDay Proof
BadBlue 2.72 - PassThru Remote Buffer Overflow
Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attacker
50RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Plugin tinybrowser 1.5.12 - Arbitrary File Upload / Execution
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
50RISCO
abrir ↗Referência✓ VexDay Proof
GrapAgenda 0.1 - 'page' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, a
23RISCO
abrir ↗Referência✓ VexDay Proof
BinGo News 3.01 - 'bnrep' Remote File Inclusion
PHP remote file inclusion vulnerability in bp_ncom.php in BinGo News (BP News) 3.01 and earlier allows remote attackers
23RISCO
abrir ↗Referência✓ VexDay Proof
webSPELL 4.01.01 - Database Backup Download
src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authe
23RISCO
abrir ↗Referência✓ VexDay Proof
Anon Proxy Server 0.1000 - Remote Command Execution
Anon Proxy Server 0.100, and probably 0.101, allows remote attackers to execute arbitrary commands via shell metacharact
23RISCO
abrir ↗Referência✓ VexDay Proof
Form Tools 1.5.0b - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Form tools 1.5.0b allow remote attackers to execute arbitrary PHP
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.