Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.652exploits catalogados
34.545CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.581GitHub PoC 13.708VulnCheck XDB 8.225Nuclei 4.228Metasploit 3.467✓ só verificadosrecentespopularesrisco
21.581 exploits
Referência✓ VexDay Proof
Berylium2 2003-08-18 - 'beryliumroot' Remote File Inclusion
PHP remote file inclusion vulnerability in berylium-classes.php in Berylium2 2003-08-18 allows remote attackers to execu
23RISCO
abrir ↗Referência✓ VexDay Proof
YourFreeScreamer 1.0 - 'serverPath' Remote File Inclusion
PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attack
23RISCO
abrir ↗Referência✓ VexDay Proof
BoastMachine 3.1 - 'mail.php' id SQL Injection
SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execut
23RISCO
abrir ↗Referência✓ VexDay Proof
EVA-Web 1.1 < 2.2 - 'index.php3' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in index.php3 in EVA-Web 1.1 through 2.2 allow remote attackers to ex
23RISCO
abrir ↗Referência✓ VexDay Proof
2532/Gigs 1.2.2 Stable - Multiple Vulnerabilities
Unrestricted file upload vulnerability in upload_flyer.php in 2532designs 2532|Gigs 1.2.2 Stable allows remote attackers
23RISCO
abrir ↗Referência
CVE-2015-2791
The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts
28RISCO
abrir ↗Referência
CVE-2018-11525
The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.
23RISCO
abrir ↗Referência
CVE-2018-11526
The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
23RISCO
abrir ↗Referência✓ VexDay Proof
PowerPoint Viewer OCX 3.2 - ActiveX Control Denial of Service
Multiple stack-based buffer overflows in the PowerPointOCX ActiveX control in PowerPointViewer.ocx 3.1.0.3 allow remote
23RISCO
abrir ↗Referência
CVE-2019-0863
An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Erro
71RISCO
abrir ↗Referência
CVE-2018-18805
Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.
23RISCO
abrir ↗Referência
CVE-2018-18805
Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.
23RISCO
abrir ↗Referência
CVE-2007-2821
SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! 1.5 Beta1/Beta2/RC1 - SQL Injection
administrator/index.php in the installer component (com_installer) in Joomla! 1.5 Beta1, Beta2, and RC1 allows remote au
23RISCO
abrir ↗Referência
CVE-2024-11237
TP-Link VN020 F3v(T) DHCP DISCOVER Packet Parser TP-Thumper stack-based overflow
41RISCO
abrir ↗Referência
CVE-2012-1790
Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a fu
23RISCO
abrir ↗Referência
CVE-2012-1790
Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a fu
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPizabi 0.848b C1 HFP1 - Arbitrary File Upload
Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitr
23RISCO
abrir ↗Referência
CVE-2019-16383
MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 a
23RISCO
abrir ↗Referência
CVE-2014-7280
Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web s
23RISCO
abrir ↗Referência
CVE-2014-1944
Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web scr
23RISCO
abrir ↗Referência
CVE-2017-11120
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor repo
23RISCO
abrir ↗Referência✓ VexDay Proof
SugarCRM Community Edition 4.5.1/5.0.0 - File Disclosure
Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to rea
23RISCO
abrir ↗Referência
CVE-2017-11120
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor repo
23RISCO
abrir ↗Referência
CVE-2021-25155
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in v
28RISCO
abrir ↗Referência
CVE-2017-1000364
An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficie
38RISCO
abrir ↗Referência
CVE-2010-1945
Multiple PHP remote file inclusion vulnerabilities in openMairie Openfoncier 2.00, when register_globals is enabled, all
23RISCO
abrir ↗Referência
CVE-2010-1945
Multiple PHP remote file inclusion vulnerabilities in openMairie Openfoncier 2.00, when register_globals is enabled, all
23RISCO
abrir ↗Referência
CVE-2019-16223
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
23RISCO
abrir ↗Referência✓ VexDay Proof
Libxine 1.14 - MPEG Stream Buffer Overflow (PoC)
Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, a
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.