Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.304exploits catalogados
34.831CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.797GitHub PoC 13.876VulnCheck XDB 8.484Nuclei 4.237Metasploit 3.467✓ só verificadosrecentespopularesrisco
21.797 exploits
Referência
CVE-2010-3856
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use
43RISCO
abrir ↗Referência
CVE-2010-3856
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use
43RISCO
abrir ↗Referência
CVE-2017-15965
The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in
23RISCO
abrir ↗Referência
CVE-2016-2087
Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary
23RISCO
abrir ↗Referência
CVE-2016-2087
Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary
23RISCO
abrir ↗Referência
CVE-2015-3203
Unrestricted file upload vulnerability in h5ai before 0.25.0 allows remote attackers to execute arbitrary code by upload
23RISCO
abrir ↗Referência
CVE-2012-2208
Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute a
23RISCO
abrir ↗Referência
CVE-2010-2507
Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! all
38RISCO
abrir ↗Referência
CVE-2010-2507
Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! all
38RISCO
abrir ↗Referência✓ VexDay Proof
SunShop Shopping Cart 3.5 - 'abs_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote
23RISCO
abrir ↗Referência
CVE-2015-0009
The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, W
23RISCO
abrir ↗Referência✓ VexDay Proof
Firefly 1.1.01 - 'doc_root' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow remote attackers to execute arbitrary PHP cod
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.0 (Windows x86) - 'PHP_iisfunc.dll' Local Buffer Overflow
Multiple buffer overflows in php_iisfunc.dll in the iisfunc extension for PHP 5.2.0 and earlier allow context-dependent
23RISCO
abrir ↗Referência✓ VexDay Proof
Mantis Bug Tracker 1.1.1 - Code Execution / Cross-Site Scripting / Cross-Site Request Forgery
Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to
23RISCO
abrir ↗Referência✓ VexDay Proof
Gravity GTD 0.4.5 - Local File Inclusion / Remote Code Execution
Eval injection vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remo
23RISCO
abrir ↗Referência
CVE-2010-2004
Stack-based buffer overflow in BS.Global BS.Player 2.51 Build 1022 Free, and possibly other versions, allows user-assist
23RISCO
abrir ↗Referência
CVE-2022-26149
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an ex
23RISCO
abrir ↗Referência
CVE-2019-14347
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an ad
23RISCO
abrir ↗Referência
CVE-2015-3704
runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly dro
23RISCO
abrir ↗Referência
CVE-2015-3704
runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly dro
23RISCO
abrir ↗Referência
CVE-2016-1336
goform/Docsis_system on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a
23RISCO
abrir ↗Referência
CVE-2016-1328
goform/WClientMACList on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a
23RISCO
abrir ↗Referência✓ VexDay Proof
Page Manager CMS 2006-02-04 - Arbitrary File Upload
Unrestricted file upload vulnerability in upload.php in Page Manager 2006-02-04 allows remote attackers to execute arbit
23RISCO
abrir ↗Referência
CVE-2017-6994
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISCO
abrir ↗Referência
CVE-2019-12279
Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). N
23RISCO
abrir ↗Referência✓ VexDay Proof
AFGB Guestbook 2.2 - 'Htmls' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in AFGB GUESTBOOK 2.2 allow remote attackers to execute arbitrary PHP
23RISCO
abrir ↗Referência✓ VexDay Proof
Winamp GEN_MSN Plugin - Heap Buffer Overflow (PoC)
Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
Cyberfolio 2.0 RC1 - 'av' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Cyberfolio 2.0 RC1 and earlier, when register_globals is enabled,
23RISCO
abrir ↗Referência
CVE-2006-3683
PHP remote file inclusion vulnerability in poll.php in Flipper Poll 1.1 and earlier allows remote attackers to execute a
23RISCO
abrir ↗Referência✓ VexDay Proof
IP3 NetAccess < 4.1.9.6 - Arbitrary File Disclosure
Directory traversal vulnerability in portalgroups/portalgroups/getfile.cgi in IP3 NetAccess before firmware 4.1.9.6 allo
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.