Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.559exploits catalogados
34.978CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.899GitHub PoC 13.960VulnCheck XDB 8.542Nuclei 4.243Metasploit 3.472✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB✓ VexDay Proof
PHP 5.3.x < 5.3.2 - 'ext/phar/stream.c' / 'ext/phar/dirstream.c' Multiple Format String Vulnerabilities
Multiple format string vulnerabilities in the phar extension in PHP 5.3 before 5.3.2 allow context-dependent attackers t
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TYPSoft FTP Server 1.10 - 'RETR' Denial of Service (1)
Typsoft FTP Server 1.11, with "Sub Directory Include" enabled, allows remote attackers to cause a denial of service (cra
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Alert Management System Intel Alert Originator Service - Remote Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management Syst
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Komento 1.0.0 - 'sid' SQL Injection
SQL injection vulnerability in the Konsultasi (com_konsultasi) component 1.0.0 for Joomla! allows remote attackers to ex
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusion
Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Jooml
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Shockwave Player 11.5.6.606 - 'DIR' Multiple Memory Vulnerabilities
Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TomatoCMS 2.0.x - SQL Injection
SQL injection vulnerability in index.php in TomatoCMS before 2.0.5 allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Safari 4.0.5 - 'parent.close()' Memory Corruption Code Execution
Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Saurus CMS 4.7 - 'edit.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus CMS 4.7.0 allows remote authenticated users, with "
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AgentX++ Master - AgentX::receive_agentx Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Ser
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Outlook Express and Windows Mail - Integer Overflow
Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2
28RISCO
abrir ↗Exploit-DB
PHPKB Knowledge Base Software 2.0 - Multilanguage Support Multiple SQL Injections
SQL injection vulnerability in comment.php in PHP Knowledge Base (PHPKB) 1.5 and 2.0 allows remote attackers to execute
23RISCO
abrir ↗Exploit-DB
PHPKB Knowledge Base Software 2.0 - Multilanguage Support Multiple SQL Injections
Multiple SQL injection vulnerabilities in PHPKB Knowledge Base Software 1.5 Professional allow remote attackers to execu
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
tekno.Portal 0.1b - 'makale.php?id' SQL Injection
SQL injection vulnerability in makale.php in tekno.Portal 0.1b allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Exploit-DB
29o3 CMS - 'LibDir' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in 29o3 CMS 0.1 allow remote attackers to execute arbitrary PHP code
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Advanced Poll 2.0 - 'mysql_host' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in misc/get_admin.php in Advanced Poll 2.08 allows remote attackers to inject a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
724CMS Enterprise 4.59 - SQL Injection
SQL injection vulnerability in index.php in 724Networks 724CMS 4.01 and earlier allows remote attackers to execute arbit
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL yaSSL (Linux) - SSL Hello Message Buffer Overflow (Metasploit)
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attacke
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell NetMail 3.52d - IMAP Subscribe Buffer Overflow (Metasploit)
Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated u
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL yaSSL (Windows) - SSL Hello Message Buffer Overflow (Metasploit)
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attacke
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CA BrightStor - HSM Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Kazaa Altnet Download Manager - ActiveX Control Buffer Overflow (Metasploit)
Stack-based buffer overflow in the ADM4 ActiveX control in adm4.dll in Altnet Download Manager 4.0.0.6, as used in (1) K
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
3Com TFTP Service (3CTftpSvc) - 'Mode' Remote Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a d
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WinDVD7 - 'IASystemInfo.dll' ActiveX Control Buffer Overflow (Metasploit)
Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio Ci
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Easy File Sharing FTP Server 2.0 - PASS Overflow (Metasploit)
Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrar
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BigAnt Server 2.2 - Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in the AntServer module (AntServer.exe) in BigAnt IM Server in BigAnt Messenger 2.2 allows r
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GoodTech Telnet Server 5.0.6 - Remote Buffer Overflow (Metasploit)
Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions befor
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mercury/32 Mail Server 4.01a - IMAP RENAME Buffer Overflow (Metasploit)
Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Medal of Honor Allied Assault - getinfo Stack Buffer Overflow (Metasploit)
Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spe
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Services - 'nwwks.dll' (MS06-066) (Metasploit)
Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 al
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.