Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8.843Nuclei 4.358Metasploit 3.489✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
asg-sentry 7.0.0 - Multiple Vulnerabilities
The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote at
23RISCO
abrir ↗Referência✓ VexDay Proof
Cerulean Portal System 0.7b - Remote File Inclusion
PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
BBS E-Market - 'postscript.php?p_mode' Remote File Inclusion
PHP remote file inclusion vulnerability in postscript/postscript.php in BBS E-Market allows remote attackers to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
WEBBDOMAIN Post Card 1.02 - 'catid' SQL Injection
SQL injection vulnerability in choosecard.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02, 1.01, and earlier allows
23RISCO
abrir ↗Referência✓ VexDay Proof
HP Compaq Notebooks - ActiveX Remote Code Execution
The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 i
23RISCO
abrir ↗Referência✓ VexDay Proof
ashNews 0.83 - 'pathtoashnews' Remote File Inclusion
PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbit
23RISCO
abrir ↗Referência✓ VexDay Proof
eXV2 Module MyAnnonces - 'lid' SQL Injection
SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
eXV2 Module WebChat 1.60 - 'roomid' SQL Injection
SQL injection vulnerability in index.php in the WebChat 1.60 module for eXV2 allows remote attackers to execute arbitrar
23RISCO
abrir ↗Referência✓ VexDay Proof
WEBBDOMAIN Petition 1.02/2.0/3.0 - Authentication Bypass
SQL injection vulnerability in getin.php in WEBBDOMAIN Petition 1.02, 2.0, and 3.0 allows remote attackers to execute ar
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component LMO 1.0b2 - Remote File Inclusion
PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows r
23RISCO
abrir ↗Referência✓ VexDay Proof
WEBBDOMAIN Polls 1.01 - Authentication Bypass
SQL injection vulnerability in getin.php in WEBBDOMAIN Polls (aka Poll) 1.0 and 1.01 allows remote attackers to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
RoomPHPlanning 1.5 - Multiple SQL Injections
SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idro
23RISCO
abrir ↗Referência✓ VexDay Proof
UNAK-CMS 1.5 - 'dirroot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitra
23RISCO
abrir ↗Referência✓ VexDay Proof
CWB PRO 1.5 - 'INCLUDE_PATH' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers
23RISCO
abrir ↗Referência✓ VexDay Proof
XnView 1.92.1 - 'FontName' Slideshow Buffer Overflow
Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code vi
23RISCO
abrir ↗Referência✓ VexDay Proof
ASPapp Knowledge Base - 'CatId' SQL Injection (1)
SQL injection vulnerability in links.asp in ASPapp allows remote attackers to execute arbitrary SQL commands via the Cat
23RISCO
abrir ↗Referência✓ VexDay Proof
SysInfo 1.21 - 'sysinfo.cgi' Remote Command Execution
Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows
23RISCO
abrir ↗Referência✓ VexDay Proof
Shader TV (Beta) - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to execute arbitrar
23RISCO
abrir ↗Referência✓ VexDay Proof
Simple Web Content Management System - SQL Injection
SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbit
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Alberghi 2.1.3 - 'id' SQL Injection
SQL injection vulnerability in the Alberghi (com_alberghi) 2.1.3 and earlier component for Mambo and Joomla! allows remo
23RISCO
abrir ↗Referência✓ VexDay Proof
FluentCMS - 'view.php' SQL Injection
SQL injection vulnerability in view.php in DotContent FluentCMS 4.x allows remote attackers to execute arbitrary SQL com
23RISCO
abrir ↗Referência✓ VexDay Proof
Bitweaver 1.3 - 'tmpImagePath' Attachment mod_mime
Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remot
23RISCO
abrir ↗Referência✓ VexDay Proof
Eznet 3.5.0 - Remote Stack Overflow / Denial of Service
Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare
35RISCO
abrir ↗Referência✓ VexDay Proof
SkaDate Online 5.0/6.0 - Remote File Disclosure
Multiple directory traversal vulnerabilities in SkaDate 5.0 and 6.0, and possibly later versions such as 6.482, allow re
23RISCO
abrir ↗Referência✓ VexDay Proof
Ktools Photostore 3.5.2 - Multiple SQL Injections
SQL injection vulnerability in crumbs.php in Ktools PhotoStore 3.4.3 and 3.5.2 allows remote attackers to execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
OneCMS 2.5 - Blind SQL Injection
SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the s
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Webhosting - 'catid' Blind SQL Injection
SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joo
23RISCO
abrir ↗Referência✓ VexDay Proof
Foxit Reader 2.0 - 'PDF' Remote Denial of Service
Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
23RISCO
abrir ↗Referência✓ VexDay Proof
Opera Web Browser 9.00 - 'iframe' Remote Denial of Service
Opera 9 allows remote attackers to cause a denial of service (crash) via a crafted web page that triggers an out-of-boun
23RISCO
abrir ↗Referência✓ VexDay Proof
Opera 9.2 - '.torrent' Remote Denial of Service
The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and app
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.