Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.449exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8.649Nuclei 4.283Metasploit 3.474✓ só verificadosrecentespopularesrisco
24.451 exploits
Exploit-DB✓ VexDay Proof
PHP 5.2.0/5.2.1 - Rejected Session ID Double-Free
Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MiniGZip - Controls File_Compress Buffer Overflow
Stack-based buffer overflow in the file_compress function in minigzip (Modules/zlib) in Python 2.5 allows context-depend
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000 - 'WinMM.dll' / '.WAV' Remote Denial of Service
winmm.dll in Microsoft Windows XP allows user-assisted remote attackers to cause a denial of service (infinite loop) via
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
JGBBS 3.0beta1 - 'search.asp?author' SQL Injection
SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 and earlier allows remote attackers to execute arbitrary S
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CARE2X 1.1 - 'ROOT_PATH' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in CARE2X 1.1 allow remote attackers to execute arbitrary PHP code vi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ClipShare 1.5.3 - 'ADODB-Connection.Inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/adodb-connection.inc.php in ClipShare 1.5.3 allows remote attackers t
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.2 - EXT/Filter Function Remote Buffer Overflow
Buffer underflow in the PHP_FILTER_TRIM_DEFAULT macro in the filtering extension (ext/filter) in PHP 5.2.0 allows contex
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
D-Link TFTP 1.0 - Transporting Mode Remote Buffer Overflow
Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GE
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OES (Open Educational System) 0.1beta - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1beta allow remote attackers to exec
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.2.0 (OSX) - EXT/Filter Space Trimming Buffer Underflow
Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by pas
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PostNuke Module phgstats 0.5 - 'phgdir' Remote File Inclusion
phgstats.inc.php in phgstats before 0.5.1, if register_globals is enabled, allows remote attackers to include arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
cPanel 10.9.x - 'Fantastico' Local File Inclusion
Multiple absolute path traversal vulnerabilities in Fantastico, as used with cPanel 10.x, allow remote authenticated use
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.2.0 - EXT/Filter FDF Post Filter Bypass
The FDF support (ext/fdf) in PHP 5.2.0 and earlier does not implement the input filtering hooks for ext/filter, which al
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SoftNews 4.1/5.5 - '/engine/init.php?root_dir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Softnews Media Group DataLife Engine allow remote attackers to exe
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SoftNews 4.1/5.5 - '/engine/Ajax/editnews.php?root_dir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Softnews Media Group DataLife Engine allow remote attackers to exe
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Premod SubDog 2 - '/includes/functions_kb.php?phpbb_root_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remote attackers to execute arbitrary PHP co
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Premod SubDog 2 - '/includes/logger_engine.php?phpbb_root_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remote attackers to execute arbitrary PHP co
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NukeSentinel 2.5.06 - SQL Injection
nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, whic
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Premod SubDog 2 - '/includes/themen_portal_mitte.php?phpbb_root_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remote attackers to execute arbitrary PHP co
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 5.0.x - Single Row SubSelect Remote Denial of Service
MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schem
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Duyuru Scripti - 'Goster.asp' SQL Injection
SQL injection vulnerability in goster.asp in fystyq Duyuru Scripti allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - FTP Server Response Denial of Service (MS07-016)
The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitr
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD 3.x/4.x - ICMPv6 Packet Handling Remote Buffer Overflow
Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragme
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
JCCorp URLShrink Free 1.3.1 - 'CreateURL.php' Remote File Inclusion
PHP remote file inclusion vulnerability in createurl.php in JCcorp (aka James Coyle) URLshrink allows remote attackers t
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.2.0 / PHP with PECL ZIP 1.8.3 - 'zip://' URL Wrapper Buffer Overflow
Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Omnikey Cardman 4040 Driver - Local Buffer Overflow (PoC)
Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Grayscale Blog 0.8.0 - Security Bypass / SQL Injection / Cross-Site Scripting
SQL injection vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, might allow remote attackers to exec
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Grayscale Blog 0.8.0 - Security Bypass / SQL Injection / Cross-Site Scripting
Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to gain privileges via direct requests with
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Grayscale Blog 0.8.0 - Security Bypass / SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.