Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8.829Nuclei 4.357Metasploit 3.489✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
Ocean12 Mailing List Manager Gold - File Disclosure / SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Mailing List Manager Gold allows remote attackers to
23RISCO
abrir ↗Referência✓ VexDay Proof
Jetik Emlak ESA 2.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Jetik Emlak Sistem A (ESA) 2.0 allow remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 6 - 'mshtml.dll' Null Pointer Dereference
Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denia
28RISCO
abrir ↗Referência✓ VexDay Proof
QuickTime Player 7.3.1.70 - 'RTSP' Remote Buffer Overflow
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allo
28RISCO
abrir ↗Referência✓ VexDay Proof
webcp 0.5.7 - 'filelocation' Remote File Disclosure
Absolute path traversal vulnerability in sendfile.php in web-cp 0.5.7, when register_globals is enabled, allows remote a
23RISCO
abrir ↗Referência✓ VexDay Proof
BookMarks Favourites Script - 'id' SQL Injection
SQL injection vulnerability in view_group.php in QuidaScript BookMarks Favourites Script (APB) allows remote attackers t
23RISCO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin Download Manager 0.2 - Arbitrary File Upload
Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress a
28RISCO
abrir ↗Referência✓ VexDay Proof
SG Real Estate Portal 2.0 - Blind SQL Injection
SQL injection vulnerability in index.php in SG Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Referência✓ VexDay Proof
SG Real Estate Portal 2.0 - Blind SQL Injection / Local File Inclusion
SQL injection vulnerability in index.php in SG Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Referência✓ VexDay Proof
phpskelsite 1.4 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
PHP remote file inclusion vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled
28RISCO
abrir ↗Referência✓ VexDay Proof
XNova 0.8 sp1 - 'xnova_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in an older version of Xnova, possibly 0.8 sp1,
23RISCO
abrir ↗Referência✓ VexDay Proof
XNova 0.8 sp1 - 'xnova_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in a newer version of Xnova, possibly 0.8 sp1,
23RISCO
abrir ↗Referência✓ VexDay Proof
Fez 1.3/2.0 RC1 - 'list.php' SQL Injection
SQL injection vulnerability in list.php in University of Queensland Library Fez 1.3 and 2.0 RC1 allows remote attackers
23RISCO
abrir ↗Referência✓ VexDay Proof
Agares phpAutoVideo 2.21 - 'articlecat' SQL Injection (1)
SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
BuzzyWall 1.3.1 - 'search' SQL Injection
SQL injection vulnerability in search.php in BuzzyWall 1.3.1 and earlier, when magic_quotes_gpc is disabled, allows remo
23RISCO
abrir ↗Referência✓ VexDay Proof
WSN Links Free 4.0.34P - 'comments.php' Blind SQL Injection
SQL injection vulnerability in comments.php in WSN Links Free 4.0.34P allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Referência✓ VexDay Proof
WSN Links 2.20 - 'comments.php' SQL Injection
SQL injection vulnerability in comments.php in WSN Links 2.20 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP-Post 1.0 - Cookie Modification Privilege Escalation
PHP-Post 0.21 and 1.0, and possibly earlier versions, when auto-login is enabled, allows remote attackers to bypass secu
28RISCO
abrir ↗Referência✓ VexDay Proof
AvailScript Article Script - 'view.php' SQL Injection
SQL injection vulnerability in view.php in AvailScript Article Script allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Referência✓ VexDay Proof
DomPHP 0.81 - 'cat' SQL Injection
Multiple SQL injection vulnerabilities in DomPHP 0.81 allow remote attackers to execute arbitrary SQL commands via the c
23RISCO
abrir ↗Referência✓ VexDay Proof
TaskFreak! 0.6.1 - SQL Injection
SQL injection vulnerability in index.php in TaskFreak! 0.6.1 and earlier allows remote authenticated users to execute ar
23RISCO
abrir ↗Referência✓ VexDay Proof
Total Video Player 1.03 - '.m3u' File Local Buffer Overflow
Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers t
28RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component JoomlaDate 1.2 - 'user' SQL Injection
SQL injection vulnerability in the JoomlaDate (com_joomladate) component 1.2 for Joomla! allows remote attackers to exec
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Daily Message 1.0.3 - 'id' SQL Injection
SQL injection vulnerability in the Daily Message (com_dailymessage) 1.0.3 component for Joomla! allows remote attackers
23RISCO
abrir ↗Referência✓ VexDay Proof
Simple Customer 1.2 - 'contact.php' SQL Injection
SQL injection vulnerability in contact.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir ↗Referência✓ VexDay Proof
Iamma Simple Gallery 1.0/2.0 - Arbitrary File Upload
Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers
23RISCO
abrir ↗Referência✓ VexDay Proof
Camera Life 2.6.2b4 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in album.php in Camera Life 2.6.2b4 allows remote attackers to execute arbitrary SQL command
23RISCO
abrir ↗Referência✓ VexDay Proof
DigitalHive 2.0 RC2 - 'user_id' SQL Injection
Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitra
23RISCO
abrir ↗Referência✓ VexDay Proof
RichStrong CMS - 'cat' SQL Injection
SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir ↗Referência✓ VexDay Proof
T-Dreams Job Career Package 3.0 - Insecure Cookie Handling
Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access b
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.