Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
Limbo CMS Module event 1.0 - Remote File Inclusion
PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to
23RISCO
abrir ↗Referência✓ VexDay Proof
Titan FTP Server 6.26 build 630 - Remote Denial of Service
Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO
50RISCO
abrir ↗Referência✓ VexDay Proof
Back-End CMS 0.7.2.2 - 'BE_config.php' Remote File Inclusion
PHP remote file inclusion vulnerability in BE_config.php in Back-End CMS 0.7.2.1 and earlier allows remote attackers to
23RISCO
abrir ↗Referência✓ VexDay Proof
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code vi
23RISCO
abrir ↗Referência✓ VexDay Proof
Kostenloses Linkmanagementscript - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PHPWAY Kostenloses Linkmanagementscript allow remote attackers to
23RISCO
abrir ↗Referência✓ VexDay Proof
Enthrallweb emates 1.0 - 'newsdetail.asp' SQL Injection
SQL injection vulnerability in newsdetail.asp in Enthrallweb eMates 1.0 allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
Prozilla Hosting Index - 'id' SQL Injection
SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
Feedback and Rating Script 1.0 - 'detail.php' SQL Injection
SQL injection vulnerability in detail.php in Feedback and Rating Script 1.0 allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
KsIRC 1.3.12 - 'PRIVMSG' Remote Buffer Overflow (PoC)
KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to a
28RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft Internet Explorer - Print Table of Links Cross-Zone Scripting
Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows us
28RISCO
abrir ↗Referência✓ VexDay Proof
ForumApp 3.3 - Remote Database Disclosure
ForumApp 3.3 stores sensitive information under the web root with insufficient access control, which allows remote attac
23RISCO
abrir ↗Referência✓ VexDay Proof
Butterfly ORGanizer 2.0.0 - Arbitrary Delete (Category/Account)
Butterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter
23RISCO
abrir ↗Referência✓ VexDay Proof
EgyPlus 7ml 1.0.1 - Authentication Bypass
Multiple SQL injection vulnerabilities in cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier, when magic_quo
23RISCO
abrir ↗Referência✓ VexDay Proof
Internet PhotoShow (Special Edition) - Insecure Cookie Handling
admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentica
23RISCO
abrir ↗Referência✓ VexDay Proof
idautomation bar code - ActiveX Multiple Vulnerabilities
IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEn
23RISCO
abrir ↗Referência✓ VexDay Proof
Kostenloses Linkmanagementscript - SQL Injection
SQL injection vulnerability in Kostenloses Linkmanagementscript allows remote attackers to execute arbitrary SQL command
23RISCO
abrir ↗Referência✓ VexDay Proof
Core Image Fun House 2.0 (OSX) - Arbitrary Code Execution (PoC)
Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows use
23RISCO
abrir ↗Referência✓ VexDay Proof
IMGallery 2.5 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in IMGallery 2.5, when magic_quotes_gpc is disabled, allow remote attackers to ex
23RISCO
abrir ↗Referência✓ VexDay Proof
newsmanager 2.0 - Remote File Inclusion / File Disclosure / SQL Injection
Multiple SQL injection vulnerabilities in News Manager 2.0 allow remote attackers to execute arbitrary SQL commands via
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component xsstream-dm 0.01b - SQL Injection
SQL injection vulnerability in the xsstream-dm (com_xsstream-dm) component 0.01 Beta for Joomla! allows remote attackers
23RISCO
abrir ↗Referência✓ VexDay Proof
ComicShout 2.5 - 'comic_id' SQL Injection
SQL injection vulnerability in index.php in ComicShout 2.5 and earlier allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
LibSPF2 < 1.2.8 - DNS TXT Record Parsing Bug Heap Overflow (PoC)
Heap-based buffer overflow in the SPF_dns_resolv_lookup function in Spf_dns_resolv.c in libspf2 before 1.2.8 allows remo
28RISCO
abrir ↗Referência✓ VexDay Proof
Xomol CMS 1.2 - Authentication Bypass / Local File Inclusion
SQL injection vulnerability in index.php in Xomol CMS 1.20071213, when magic_quotes_gpc is disabled, allows remote attac
23RISCO
abrir ↗Referência✓ VexDay Proof
RoomPHPlanning 1.5 - Arbitrary Add Admin
admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated
23RISCO
abrir ↗Referência✓ VexDay Proof
KwsPHP 1.3.456 Module Galerie - 'id_gal' SQL Injection
SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arb
23RISCO
abrir ↗Referência✓ VexDay Proof
Mega File Hosting Script 1.2 - 'fid' SQL Injection
SQL injection vulnerability in members.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote authe
23RISCO
abrir ↗Referência✓ VexDay Proof
Battle.net Clan Script 1.5.x - SQL Injection
SQL injection vulnerability in members.php in Battle.net Clan Script for PHP 1.5.3 and earlier, when magic_quotes_gpc is
23RISCO
abrir ↗Referência✓ VexDay Proof
QuickUpCMS - Multiple SQL Injections Vulnerabilities
Multiple SQL injection vulnerabilities in Concepts & Solutions QuickUpCMS allow remote attackers to execute arbitrary SQ
23RISCO
abrir ↗Referência✓ VexDay Proof
Advanced Image Hosting (AIH) 2.1 - SQL Injection
SQL injection vulnerability in out.php in YABSoft Advanced Image Hosting (AIH) Script 2.1 and earlier allows remote atta
23RISCO
abrir ↗Referência✓ VexDay Proof
BP Blog 6.0 - 'id' Blind SQL Injection
Multiple SQL injection vulnerabilities in BP Blog 6.0 allow remote attackers to execute arbitrary SQL commands via the (
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.