Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8.843Nuclei 4.358Metasploit 3.489✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
Data Dynamics ActiveBar (Actbar3.ocx 3.2) - Multiple Insecure Methods
The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite
23RISCO
abrir ↗Referência✓ VexDay Proof
CA BrightStor ARCserve Backup r11.5 - ActiveX Remote Buffer Overflow
Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including Br
50RISCO
abrir ↗Referência✓ VexDay Proof
Pluxml 0.3.1 - Remote Code Execution
Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute
23RISCO
abrir ↗Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.6 - Code Execution
Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 be
23RISCO
abrir ↗Referência✓ VexDay Proof
phpAuction - 'profile.php' SQL Injection (1)
SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attacker
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP Live Helper 2.0 - 'abs_path' Remote File Inclusion
PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote
23RISCO
abrir ↗Referência✓ VexDay Proof
XLPortal 2.2.4 - 'Search' SQL Injection
SQL injection vulnerability in index.php in XLPortal 2.2.4 and earlier allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
nweb2fax 0.2.7 - Multiple Vulnerabilities
viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in t
23RISCO
abrir ↗Referência✓ VexDay Proof
WebChat 0.77 - 'defines.php?WEBCHATPATH' Remote File Inclusion
PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP
23RISCO
abrir ↗Referência✓ VexDay Proof
Apartment Search Script - Arbitrary File Upload / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in listtest.php in Apartment Search Script allows remote attackers to inject ar
23RISCO
abrir ↗Referência✓ VexDay Proof
TeamSpeak 2.0 (Windows Release) - Remote Denial of Service
TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which al
23RISCO
abrir ↗Referência✓ VexDay Proof
Maian Weblog 4.0 - Insecure Cookie Handling
admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative
23RISCO
abrir ↗Referência✓ VexDay Proof
mcGalleryPRO 2006 - 'path_to_folder' Remote File Inclusion
PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
xeCMS 1.0.0 RC2 - Insecure Cookie Handling
admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by
28RISCO
abrir ↗Referência✓ VexDay Proof
Jasmine CMS 1.0 - SQL Injection / Remote Code Execution
Multiple SQL injection vulnerabilities in Jasmine CMS 1.0 allow remote attackers to execute arbitrary SQL commands via (
23RISCO
abrir ↗Referência✓ VexDay Proof
BitDefender Online Scanner 8 - ActiveX Heap Overflow
A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remo
23RISCO
abrir ↗Referência✓ VexDay Proof
Yahoo! JukeBox MediaGrid - 'AddBitmap()' ActiveX Buffer Overflow
Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attacker
23RISCO
abrir ↗Referência✓ VexDay Proof
Pre ADS Portal 2.0 - Authentication Bypass / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Pre ADS Portal 2.0 and earlier allow remote attackers to inject a
23RISCO
abrir ↗Referência✓ VexDay Proof
TOSMO/Mambo 1.4.13a - 'absolute_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and p
23RISCO
abrir ↗Referência✓ VexDay Proof
Pre ADS Portal 2.0 - Authentication Bypass / Cross-Site Scripting
homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows r
23RISCO
abrir ↗Referência✓ VexDay Proof
FirmWorX 0.1.2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP cod
23RISCO
abrir ↗Referência✓ VexDay Proof
NVR SP2 2.0 'nvUtility.dll 1.0.14.0' - 'DeleteXMLFile()' Insecure Method
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in
23RISCO
abrir ↗Referência✓ VexDay Proof
MiGCMS 2.0.5 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in MiGCMS 2.0.5, when register_globals is enabled, allow remote attac
23RISCO
abrir ↗Referência✓ VexDay Proof
U&M Software Signup 1.1 - Authentication Bypass
U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory,
23RISCO
abrir ↗Referência✓ VexDay Proof
U&M Software Event Lister 1.0 - Authentication Bypass
U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the adm
23RISCO
abrir ↗Referência✓ VexDay Proof
Durian Web Application Server 3.02 - Denial of Service
Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary c
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component rekry 1.0.0 - 'op_id' SQL Injection
SQL injection vulnerability in the Matti Kiviharju rekry (aka com_rekry or rekry!Joom) 1.0.0 component for Joomla! allow
23RISCO
abrir ↗Referência✓ VexDay Proof
DELTAScripts PHP Links 1.3 - Authentication Bypass
SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to
23RISCO
abrir ↗Referência✓ VexDay Proof
AJ Article 1.0 - Authentication Bypass
SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir ↗Referência✓ VexDay Proof
TurnkeyForms Entertainment Portal 2.0 - Insecure Cookie Handling
TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.