Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8.846Nuclei 4.361Metasploit 3.490✓ só verificadosrecentespopularesrisco
22.573 exploits
Referência
CVE-2014-3004
The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct
23RISCO
abrir ↗Referência
CVE-2010-4737
SQL injection vulnerability in resorts.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência
CVE-2017-17538
MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets.
23RISCO
abrir ↗Referência
CVE-2009-3246
SQL injection vulnerability in spnews.php in MyBuxScript PTC-BUX allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir ↗Referência
ManageEngine OpManager 12.4x - Privilege Escalation / Remote Command Execution (Metasploit)
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewT
23RISCO
abrir ↗Referência
CVE-2014-5116
The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attac
23RISCO
abrir ↗Referência
CVE-2019-10273
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticat
23RISCO
abrir ↗Referência
CVE-2019-10273
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticat
23RISCO
abrir ↗Referência✓ VexDay Proof
RedDot CMS 7.5 - 'LngId' SQL Injection
SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and
23RISCO
abrir ↗Referência
CVE-2017-15012
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the i
23RISCO
abrir ↗Referência✓ VexDay Proof
Web Wiz Guestbook 8.21 - Database Disclosure
Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows rem
23RISCO
abrir ↗Referência
CVE-2005-0575
Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possib
23RISCO
abrir ↗Referência
CVE-2010-4738
Multiple SQL injection vulnerabilities in Rae Media INC Real Estate Single and Multi Agent System 3.0 allow remote attac
23RISCO
abrir ↗Referência
CVE-2016-5840
hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote ad
23RISCO
abrir ↗Referência✓ VexDay Proof
Neat weblog 0.2 - 'articleId' SQL Injection
SQL injection vulnerability in index.php in Neat weblog 0.2 allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir ↗Referência✓ VexDay Proof
Mambo Component nfnaddressbook 0.4 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo
23RISCO
abrir ↗Referência✓ VexDay Proof
Maian Links 3.1 - Insecure Cookie Handling
admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative
23RISCO
abrir ↗Referência✓ VexDay Proof
Dokuwiki 2009-02-14 - Local File Inclusion
inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote att
28RISCO
abrir ↗Referência✓ VexDay Proof
phpMyPortal 3.0.0 RC3 - GLOBALS[CHEMINMODULES] Remote File Inclusion
PHP remote file inclusion vulnerability in inc/articles.inc.php in phpMyPortal 3.0.0 RC3 allows remote attackers to exec
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP 'Perl' Extension - 'Safe_mode' Bypass
The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute ar
23RISCO
abrir ↗Referência✓ VexDay Proof
Charrays CMS 0.9.3 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Charray's CMS 0.9.3 allow remote attackers to execute arbitrary PH
23RISCO
abrir ↗Referência
CVE-2016-5764
Micro Focus Rumba FTP 4.X client buffer overflow makes it possible to corrupt the stack and allow arbitrary code executi
23RISCO
abrir ↗Referência
CVE-2012-1670
admin/index.php in PHP Grade Book before 1.9.5 BETA allows remote attackers to read the database via a SaveSQL action.
23RISCO
abrir ↗Referência
CVE-2009-4541
Multiple PHP remote file inclusion vulnerabilities in IsolSoft Support Center 2.5 allow remote attackers to execute arbi
23RISCO
abrir ↗Referência✓ VexDay Proof
Woltlab Burning Board Addon JGS-Treffen 2.0.2 - SQL Injection
SQL injection vulnerability in jgs_treffen.php in the JGS-XA JGS-Treffen 2.0.2 and earlier addon for Woltlab Burning Boa
23RISCO
abrir ↗Referência
CVE-2018-9035
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPr
23RISCO
abrir ↗Referência
CVE-2014-4138
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISCO
abrir ↗Referência✓ VexDay Proof
Oracle 10g - MDSYS.SDO_TOPO_DROP_FTBL SQL Injection (Metasploit)
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authent
50RISCO
abrir ↗Referência
CVE-2018-1133
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code exec
35RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.