Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.020exploits catalogados
35.276CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.446Referência 22.166GitHub PoC 14.080VulnCheck XDB 8.604Nuclei 4.251Metasploit 3.473✓ só verificadosrecentespopularesrisco
22.166 exploits
Referência✓ VexDay Proof
yaplap 0.6.1b - 'ldap.php' Remote File Inclusion
PHP remote file inclusion vulnerability in ldap.php in Brian Drawert Yet Another PHP LDAP Admin Project (yaplap) 0.6 and
23RISCO
abrir ↗Referência
CVE-2015-0313
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RISCO
abrir ↗Referência✓ VexDay Proof
Wireshark 1.0.6 - PN-DCP Format String (PoC)
Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attacker
28RISCO
abrir ↗Referência✓ VexDay Proof
PrecisionID Datamatrix - ActiveX Arbitrary File Overwrite
Multiple insecure method vulnerabilities in PRECIS~2.DLL in the PrecisionID Datamatrix ActiveX control (DMATRIXLib.Datam
23RISCO
abrir ↗Referência✓ VexDay Proof
vsp stats processor 0.45 - 'gamestat.php?gameID' SQL Injection
SQL injection vulnerability in vsp-core/pub/themes/bismarck/gamestat.php in vsp stats processor 0.45 allows remote attac
23RISCO
abrir ↗Referência✓ VexDay Proof
Check Point Firewall-1 - PKI Web Service HTTP Header Remote Overflow
NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI
23RISCO
abrir ↗Referência✓ VexDay Proof
Arcadwy Arcade Script - 'Username' Static Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in register.php in Arcadwy Arcade Script CMS allows remote attackers to inject
23RISCO
abrir ↗Referência✓ VexDay Proof
Mozilla Firefox 3.0.x - XML Parser Memory Corruption / Denial of Service (PoC)
Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption
23RISCO
abrir ↗Referência✓ VexDay Proof
Opera 9.64 - 7400 nested elements XML Parsing Remote Crash
Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a lon
23RISCO
abrir ↗Referência✓ VexDay Proof
Apple Mac OSX xnu 1228.x - 'hfs-fcntl' Kernel Privilege Escalation
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space
23RISCO
abrir ↗Referência✓ VexDay Proof
Apple Mac OSX xnu 1228.3.13 - 'zip-notify' Remote Kernel Overflow (PoC)
Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and e
23RISCO
abrir ↗Referência✓ VexDay Proof
Apple Mac OSX xnu 1228.3.13 - 'macfsstat' Local Kernel Memory Leak/Denial of Service
Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a den
23RISCO
abrir ↗Referência✓ VexDay Proof
Apple Mac OSX xnu 1228.3.13 - 'Profil' Kernel Memory Leak/Denial of Service (PoC)
Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a den
23RISCO
abrir ↗Referência✓ VexDay Proof
Apple Mac OSX xnu 1228.x - 'vfssysctl' Local Kernel Denial of Service (PoC)
Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows
23RISCO
abrir ↗Referência✓ VexDay Proof
FlexCMS Calendar - 'itemID' Blind SQL Injection
SQL injection vulnerability in FlexCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the ItemId para
23RISCO
abrir ↗Referência✓ VexDay Proof
UltraISO 9.3.3.2685 - CCD/IMG Universal Buffer Overflow
Heap-based buffer overflow in Magic ISO Maker 5.5 build 0274 allows remote attackers to cause a denial of service (crash
28RISCO
abrir ↗Referência✓ VexDay Proof
UltraISO 9.3.3.2685 - CCD/IMG Universal Buffer Overflow
Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of ser
50RISCO
abrir ↗Referência✓ VexDay Proof
WebFileExplorer 3.1 - Authentication Bypass
body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the s
28RISCO
abrir ↗Referência
CVE-2015-0493
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.1, 8.5.0, and 8.
23RISCO
abrir ↗Referência
CVE-2015-0554
The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6 does not properly rest
50RISCO
abrir ↗Referência
CVE-2009-4728
SQL injection vulnerability in the administrative interface in Questions Answered 1.3 allows remote attackers to execute
23RISCO
abrir ↗Referência
CVE-2024-45519
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISCO
abrir ↗Referência
CVE-2015-0565
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
28RISCO
abrir ↗Referência
CVE-2015-0565
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
28RISCO
abrir ↗Referência
CVE-2015-0779
Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11
60RISCO
abrir ↗Referência
CVE-2014-8361
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClien
100RISCO
abrir ↗Referência
CVE-2026-49127
Music Player Daemon < 0.24.11 Stack Buffer Overflow via pcm_unpack_24be
41RISCO
abrir ↗Referência✓ VexDay Proof
SH-News 0.93 - 'misc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in misc.php in SH-News 0.93, when register_globals is enabled, allows remote att
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.