Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.899GitHub PoC 13.937VulnCheck XDB 8.510Nuclei 4.239Metasploit 3.468✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB
html-edit CMS - Multiple Vulnerabilities
Html-edit CMS 3.1.8 allows remote attackers to obtain sensitive information via a direct request to (1) pages.php and (2
23RISCO
abrir ↗Exploit-DB
Habari Blog - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Habari 0.6.5, when register_globals is enabled, allow remote atta
23RISCO
abrir ↗Exploit-DB
Hycus CMS - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in index.php in Hycus CMS 1.0.3, when magic_quotes_gpc is disabled, allow remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MHonArc 2.6.16 - Tag Nesting Remote Denial of Service
MHonArc 2.6.16 allows remote attackers to cause a denial of service (CPU consumption) via start tags that are placed wit
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server - Payload Execution (Metasploit)
The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in pla
60RISCO
abrir ↗Exploit-DB
Hycus CMS - Multiple Vulnerabilities
Multiple directory traversal vulnerabilities in Hycus CMS 1.0.3 allow remote attackers to include and execute arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server - Payload Execution (Metasploit)
The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3)
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component JotLoader 2.2.1 - Local File Inclusion
Directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers t
38RISCO
abrir ↗Exploit-DB
PHP Web Scripts Ad Manager Pro 3.0 - SQL Injection
SQL injection vulnerability in website-page.php in PHP Web Scripts Ad Manager Pro 3.0 allows remote attackers to execute
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mafya Oyun Scrpti - 'profil.php' SQL Injection
SQL injection vulnerability in profil.php in Mafya Oyun Scrpti (aka Mafia Game Script) allows remote attackers to execut
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oto Galery 1.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Oto Galeri Sistemi 1.0 allow remote attackers to execute arbitrary SQL command
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Redmine SCM Repository - Arbitrary Command Execution (Metasploit)
Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attacke
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.37-rc2 - 'ACPI custom_method' Local Privilege Escalation
drivers/acpi/debugfs.c in the Linux kernel before 3.0 allows local users to modify arbitrary kernel memory locations by
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Projekt Shop - 'details.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL comma
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mafia Game Script - SQL Injection
SQL injection vulnerability in profil.php in Mafya Oyun Scrpti (aka Mafia Game Script) allows remote attackers to execut
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ero Auktion 2010 - 'item.php' SQL Injection
SQL injection vulnerability in item.php in Ero Auktion 2010 allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PayPal Shop Digital - SQL Injection
SQL injection vulnerability in view_item.php in MH Products Pay Pal Shop Digital allows remote attackers to execute arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Download Center 2.2 - SQL Injection
SQL injection vulnerability in admin/login.php in MHP DownloadScript (aka MH Products Download Center) 2.2 allows remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.37-rc2 - 'ACPI custom_method' Local Privilege Escalation
The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ecava IntegraXor Remote - ActiveX Buffer Overflow (PoC)
Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraX
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Easy Online Shop - SQL Injection
SQL injection vulnerability in content.php in MH Products Easy Online Shop allows remote attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MHP Downloadshop - SQL Injection
SQL injection vulnerability in view_item.php in MH Products MHP Downloadshop allows remote attackers to execute arbitrar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Win32k Pointer Dereferencement (PoC) (MS10-098)
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate user-
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Immo Makler Script - SQL Injection
SQL injection vulnerability in news.php in Immo Makler allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir ↗Exploit-DB
Radius Manager 3.8.0 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Radius Manager 3.8.0 allow remote authenticated administrators to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Radius Manager 3.6 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Radius Manager 3.8.0 allow remote authenticated administrators to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Exim4 < 4.69 - string_format Function Heap Buffer Overflow (Metasploit)
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to exe
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Altap Salamander 2.5 PE Viewer - Local Buffer Overflow (Metasploit)
Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (Englis
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe PDF - Embedded EXE Social Engineering (Metasploit)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe PDF - Escape EXE Social Engineering (No JavaScript) (Metasploit)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.