Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8.829Nuclei 4.357Metasploit 3.489✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
Joomla! Component ongumatimesheet20 4b - Remote File Inclusion
PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b
28RISCO
abrir ↗Referência✓ VexDay Proof
DevelopItEasy Photo Gallery 1.2 - SQL Injection
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQ
23RISCO
abrir ↗Referência✓ VexDay Proof
BlogPHP 2 - 'id' Cross-Site Scripting / SQL Injection
SQL injection vulnerability in index.php in BlogPHP 2.0 allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir ↗Referência✓ VexDay Proof
Black Ice Software Annotation Plugin - 'BiAnno.ocx' Remote Buffer Overflow
Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows
28RISCO
abrir ↗Referência✓ VexDay Proof
BXCP 0.2.9.9 - 'tid' SQL Injection
SQL injection vulnerability in index.php in BXCP 0.299 allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir ↗Referência✓ VexDay Proof
TurnkeyForms Business Survey Pro 1.0 - 'id' SQL Injection
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers t
23RISCO
abrir ↗Referência✓ VexDay Proof
Online Media Technologies 'AVSMJPEGFILE.DLL 1.1' - Remote Buffer Overflow (PoC)
Buffer overflow in a certain ActiveX control in Online Media Technologies AVSMJPEGFILE.DLL 1.1.1.102 allows remote attac
28RISCO
abrir ↗Referência✓ VexDay Proof
ASP-CMS 1.0 - 'cha' SQL Injection
SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir ↗Referência✓ VexDay Proof
Oracle Internet Directory 10.1.4 - Remote Denial of Service
Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and
28RISCO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin st_newsletter - SQL Injection
SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress al
23RISCO
abrir ↗Referência✓ VexDay Proof
evCal Events Calendar - Database Disclosure
evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows rem
23RISCO
abrir ↗Referência✓ VexDay Proof
MyCal Personal Events Calendar - Database Disclosure
MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which a
23RISCO
abrir ↗Referência✓ VexDay Proof
Social Groupie - 'id' SQL Injection
SQL injection vulnerability in group_index.php in Social Groupie allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir ↗Referência✓ VexDay Proof
Bytehoard 2.1 - 'server.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/webdav/server.php in Bytehoard 2.1 Epsilon/Delta allows remote attac
28RISCO
abrir ↗Referência✓ VexDay Proof
DesignWorks Professional 4.3.1 - '.CCT' File Local Stack Buffer Overflow (PoC)
Stack-based buffer overflow in DesignWorks Professional 4.3.1 and 5.0.7 allows remote attackers to execute arbitrary cod
23RISCO
abrir ↗Referência✓ VexDay Proof
Site@School 2.4.02 - Arbitrary File Upload
Multiple PHP remote file inclusion vulnerabilities in Site@School (S@S) 2.4.02 and earlier allow remote attackers to exe
28RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component NeoReferences 1.3.1 - 'catid' SQL Injection
SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla!
23RISCO
abrir ↗Referência✓ VexDay Proof
Ad Management Java - Authentication Bypass
SQL injection vulnerability in logon.jsp in Ad Server Solutions Ad Management Software Java allows remote attackers to e
23RISCO
abrir ↗Referência✓ VexDay Proof
ITechBids 5.0 - 'item_id' SQL Injection
SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary S
23RISCO
abrir ↗Referência✓ VexDay Proof
Affiliate Software Java 4.0 - Authentication Bypass
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to e
23RISCO
abrir ↗Referência✓ VexDay Proof
Ocean12 Contact Manager Pro - SQL Injection / Cross-Site Scripting / File Disclosure
SQL injection vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
Codefixer MailingListPro - Database Disclosure
CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access c
23RISCO
abrir ↗Referência✓ VexDay Proof
Multi SEO phpBB 1.1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in include/global.php in Multi SEO phpBB 1.1.0 allows remote attackers to execut
23RISCO
abrir ↗Referência✓ VexDay Proof
Calendar MX Professional 2.0.0 - Blind SQL Injection
SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to exe
23RISCO
abrir ↗Referência✓ VexDay Proof
CA BrightStor ARCserve 11.5.2.0 - 'catirpc.dll' RPC Server Denial of Service
The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlie
28RISCO
abrir ↗Referência✓ VexDay Proof
Active Web Helpdesk 2 - 'categoryId' Blind SQL Injection
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attacker
23RISCO
abrir ↗Referência✓ VexDay Proof
Quick Tree View .NET 3.1 - Database Disclosure
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows
23RISCO
abrir ↗Referência✓ VexDay Proof
Rapid Classified 3.1 - Database Disclosure
Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which al
23RISCO
abrir ↗Referência✓ VexDay Proof
Visual Events Calendar 1.1 - 'cfg_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.