Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8.829Nuclei 4.357Metasploit 3.489✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
Toko Instan 7.6 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in index.php in Toko Instan 7.6 allow remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Referência✓ VexDay Proof
XOOPS Module xhresim - SQL Injection
SQL injection vulnerability in index.php in the xhresim module in XOOPS allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
Kwalbum 2.0.2 - Arbitrary File Upload
Unrestricted file upload vulnerability in Kwalbum 2.0.4, 2.0.2, and earlier, when PICS_PATH is located in the web root,
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Carousel Flash Image Gallery - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.jjgallery.php in the Carousel Flash Image Gallery (com_jjgallery) compo
23RISCO
abrir ↗Referência✓ VexDay Proof
verlihub 0.9.8d-RC2 - Remote Command Execution
The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlie
23RISCO
abrir ↗Referência✓ VexDay Proof
Phoenician Casino FlashAX - ActiveX Remote Code Execution
Heap-based buffer overflow in the Phoenician Casino FlashAX ActiveX control 1.0.0.7 allows remote attackers to execute a
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component juser 1.0.14 - Remote File Inclusion
PHP remote file inclusion vulnerability in xajax_functions.php in the JUser (com_juser) 1.0.14 component for Joomla! all
28RISCO
abrir ↗Referência✓ VexDay Proof
FaceBook PhotoUploader 5.0.14.0 - Remote Buffer Overflow
Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to
50RISCO
abrir ↗Referência✓ VexDay Proof
HotScripts Clone Script - SQL Injection
SQL injection vulnerability in software-description.php in HotScripts Clone Script allows remote attackers to execute ar
23RISCO
abrir ↗Referência✓ VexDay Proof
SAWStudio 3.9i - '.prf' Local Buffer Overflow (PoC)
Buffer overflow in SAWStudio 3.9i allows user-assisted remote attackers to cause a denial of service (application crash)
28RISCO
abrir ↗Referência✓ VexDay Proof
Vigile CMS 1.4 - Multiple Vulnerabilities
Directory traversal vulnerability in index.php in VigileCMS 1.4 allows remote attackers to include and execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
Vigile CMS 1.4 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in index.php in VigileCMS 1.4 allows remote attackers to change the admi
23RISCO
abrir ↗Referência✓ VexDay Proof
Softbiz Freelancers Script 1 - SQL Injection
SQL injection vulnerability in search_form.php in Softbiz Freelancers Script 1 allows remote attackers to execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
PowerStrip 3.84 - 'pstrip.sys' Local Privilege Escalation
The NT kernel-mode driver (aka pstrip.sys) 5.0.1.1 and earlier in EnTech Taiwan PowerStrip 3.84 and earlier allows local
23RISCO
abrir ↗Referência✓ VexDay Proof
Mp3 ToolBox 1.0 Beta 5 - 'skin_file' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Mp3 ToolBox 1.0 beta 5 allows remote attackers to execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_phocadocumentation - 'id' SQL Injection
SQL injection vulnerability in the Phoca Documentation (com_phocadocumentation) component for Joomla! allows remote atta
23RISCO
abrir ↗Referência✓ VexDay Proof
StormBoard 1.0.1 - SQL Injection
SQL injection vulnerability in thread.php in stormBoards 1.0.1 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
CMS NetCat 3.12 - 'password_recovery.php' Blind SQL Injection
SQL injection vulnerability in modules/auth/password_recovery.php in AIST NetCat 3.12 and earlier, when magic_quotes_gpc
23RISCO
abrir ↗Referência✓ VexDay Proof
CMS NetCat 3.12 - Multiple Vulnerabilities
Multiple CRLF injection vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to have an unknown impact
23RISCO
abrir ↗Referência✓ VexDay Proof
PGP Desktop 9.0.6 - 'PGPwded.sys' Local Denial of Service
The PGPwded device driver (aka PGPwded.sys) in PGP Corporation PGP Desktop 9.0.6 build 6060 and 9.9.0 build 397 allows l
23RISCO
abrir ↗Referência✓ VexDay Proof
BLOG 1.55B - 'image_upload.php' Arbitrary File Upload
Unrestricted file upload vulnerability in lib/image_upload.php in KafooeyBlog 1.55b allows remote attackers to execute a
28RISCO
abrir ↗Referência✓ VexDay Proof
HP Data Protector 4.00-SP1b43064 - Remote Memory Leak/Denial of Service (Metasploit)
Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express
35RISCO
abrir ↗Referência✓ VexDay Proof
Calendar Script 1.1 - Authentication Bypass
SQL injection vulnerability in index.php in Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to execute arbit
23RISCO
abrir ↗Referência✓ VexDay Proof
Web-MeetMe 3.0.3 - 'play.php' Remote File Disclosure
Multiple directory traversal vulnerabilities in play.php in Web-MeetMe 3.0.3 allow remote attackers to read arbitrary fi
23RISCO
abrir ↗Referência✓ VexDay Proof
Pligg 9.9.5b - Arbitrary File Upload / SQL Injection
SQL injection vulnerability in evb/check_url.php in Pligg CMS 9.9.5 Beta allows remote attackers to execute arbitrary SQ
23RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows Media Player - '.wav' Remote Crash (PoC)
Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, includ
28RISCO
abrir ↗Referência✓ VexDay Proof
Google Chrome - 'ChromeHTML://' Remote Parameter Injection
Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to ex
28RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component OnlineFlashQuiz 1.0.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1
28RISCO
abrir ↗Referência✓ VexDay Proof
LAN Management System (LMS) 1.9.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in lib/language.php in LAN Management System (LMS) 1.9.6 and earlier allows remo
35RISCO
abrir ↗Referência✓ VexDay Proof
VMware - COM API ActiveX Remote Buffer Overflow (PoC)
Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMwar
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.