Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8.829Nuclei 4.357Metasploit 3.489✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
Xserver 0.1 Alpha - 'POST' Remote Buffer Overflow (PoC)
Buffer overflow in Nipun Jain xserver 0.1 alpha allows remote attackers to cause a denial of service via a POST request
23RISCO
abrir ↗Referência✓ VexDay Proof
JBlog 1.0 - Create / Delete Admin Authentication Bypass
Multiple cross-site scripting (XSS) vulnerabilities in JBlog 1.0 allow remote attackers to inject arbitrary web script o
23RISCO
abrir ↗Referência✓ VexDay Proof
bwired - 'index.php?newsID' SQL Injection
SQL injection vulnerability in index.php in bwired allows remote attackers to execute arbitrary SQL commands via the new
23RISCO
abrir ↗Referência✓ VexDay Proof
ProQuiz 1.0 - Authentication Bypass
SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir ↗Referência✓ VexDay Proof
Butterfly ORGanizer 2.0.1 - 'id' SQL Injection
SQL injection vulnerability in view.php in Butterfly Organizer 2.0.0 and 2.0.1 allows remote attackers to execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
Pre Job Board - Authentication Bypass
SQL injection vulnerability in Employee/login.asp in Pre ASP Job Board allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
MyTopix 1.3.0 - SQL Injection
SQL injection vulnerability in index.php in MyTopix 1.3.0 and earlier allows remote authenticated users to execute arbit
23RISCO
abrir ↗Referência✓ VexDay Proof
Simple Customer 1.2 - Authentication Bypass
SQL injection vulnerability in login.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL command
23RISCO
abrir ↗Referência✓ VexDay Proof
RSS Simple News - SQL Injection
SQL injection vulnerability in news.php in RSS Simple News (RSSSN), when magic_quotes_gpc is disabled, allows remote att
23RISCO
abrir ↗Referência✓ VexDay Proof
Mazens PHP Chat V3 (basepath) - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Mazen's PHP Chat 3.0.0 allow remote attackers to execute arbitrary
35RISCO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.3 - 'PHP_gd2.dll' imagepsloadfont Local Buffer Overflow (PoC)
Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent at
28RISCO
abrir ↗Referência✓ VexDay Proof
Extract Website - 'Filename' File Disclosure
Directory traversal vulnerability in download.php in eMetrix Extract Website allows remote attackers to read arbitrary f
23RISCO
abrir ↗Referência✓ VexDay Proof
TemaTres 1.0.3 - Blind SQL Injection
Multiple SQL injection vulnerabilities in TemaTres 1.0.3 and 1.031, when magic_quotes_gpc is disabled, allow remote atta
23RISCO
abrir ↗Referência✓ VexDay Proof
Online Keyword Research Tool - 'download.php' File Disclosure
Directory traversal vulnerability in download.php in eMetrix Online Keyword Research Tool allows remote attackers to rea
23RISCO
abrir ↗Referência✓ VexDay Proof
Text Lines Rearrange Script - 'Filename' File Disclosure
Directory traversal vulnerability in download.php in Text Lines Rearrange Script 1.0, when register_globals is enabled,
23RISCO
abrir ↗Referência✓ VexDay Proof
VMware Inc 6.0.0 - 'vielib.dll 2.2.5.42958' Remode Code Execution
Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll 2.2.5.42958 in EMC VMware 6.0.0 allows
28RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Volunteer 2.0 - SQL Injection
SQL injection vulnerability in the Volunteer Management System (com_volunteer) module 2.0 for Joomla! allows remote atta
23RISCO
abrir ↗Referência✓ VexDay Proof
RM Downloader 3.0.0.9 - '.RAM' Local Buffer Overflow
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RISCO
abrir ↗Referência✓ VexDay Proof
SolarCMS 0.53.8 - 'Forum' Remote Cookies Disclosure
SQL injection vulnerability in Forum.php in SolarCMS 0.53.8 and 1.0 allows remote attackers to execute arbitrary SQL com
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component ongumatimesheet20 4b - Remote File Inclusion
PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b
28RISCO
abrir ↗Referência✓ VexDay Proof
BlazeVideo HDTV Player 2.1 - '.PLF' Local Buffer Overflow
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote at
50RISCO
abrir ↗Referência✓ VexDay Proof
Shutter 0.1.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in photos.php in Shutter 0.1.1 allow remote attackers to execute arbitrary SQL co
23RISCO
abrir ↗Referência✓ VexDay Proof
DevelopItEasy Photo Gallery 1.2 - SQL Injection
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQ
23RISCO
abrir ↗Referência✓ VexDay Proof
TurnkeyForms Business Survey Pro 1.0 - 'id' SQL Injection
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers t
23RISCO
abrir ↗Referência✓ VexDay Proof
ASP-CMS 1.0 - 'cha' SQL Injection
SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows XP/2003 - IGMP v3 Denial of Service (MS06-007) (1)
Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang)
35RISCO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin mygallery 1.4b4 - Remote File Inclusion
PHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.4b4 and earlier plugin fo
35RISCO
abrir ↗Referência✓ VexDay Proof
The Recipe Script 5 - Authentication Bypass / Database Backup
Multiple SQL injection vulnerabilities in admin/login.php in Wright Way Services Recipe Script 5 allow remote attackers
23RISCO
abrir ↗Referência✓ VexDay Proof
XOOPS Module cjay content 3 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS a
35RISCO
abrir ↗Referência✓ VexDay Proof
PHPNews 0.93 - 'format_menue' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/inc/change_action.php in Andreas Robertz PHPNews 0.93 allows remote att
35RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.