Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.449exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8.649Nuclei 4.283Metasploit 3.474✓ só verificadosrecentespopularesrisco
24.451 exploits
Exploit-DB✓ VexDay Proof
phpMyFAQ 1.6.7 - SQL Injection / Command Execution
SQL injection vulnerability in phpMyFAQ 1.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP < 4.5.0 - Unserialize Overflow (Metasploit)
Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Snort 2.6.1 - DCE/RPC Preprocessor Remote Buffer Overflow
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire I
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Comodo Firewall Pro 2.4.x - Local Protection Mechanism Bypass
Comodo Firewall Pro (CFP) (formerly Comodo Personal Firewall) 2.4.18.184 and earlier allows local users to bypass driver
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Madwifi 0.9.2.1 - WPA/RSN IE Remote Kernel Buffer Overflow
Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execut
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Built2go News Manager 1.0 Blog - 'rating.php?nid' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4 - Userland ZVAL Reference Counter Overflow (PoC)
Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitra
53RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Built2go News Manager 1.0 Blog - 'news.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
aWebNews 1.1 - 'listing.php?path_to_news' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in aWeb Labs aWebNews 1.5 allow remote attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat/Adobe Reader 7.0.9 - Information Disclosure
Adobe Reader and Acrobat Trial allow remote attackers to read arbitrary files via a file:// URI in a PDF document, as de
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HyperBook Guestbook 1.3 - GBConfiguration.DAT Hashed Password Information Disclosure
Thomas R. Pasawicz HyperBook Guestbook 1.30 stores sensitive information under the web root with insufficient access con
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.3.34/1.3.33 (Ubuntu / Debian) - CGI TTY Privilege Escalation
The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd fro
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
3Com TFTP Service (3CTftpSvc) 2.0.1 - Long Transporting Mode
Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a d
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
McAfee VirusScan for Mac (Virex) 7.7 - Local Privilege Escalation
VShieldCheck in McAfee VirusScan for Mac (Virex) before 7.7 patch 1 allow local users to change permissions of arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
EmbeddedWB Web Browser ActiveX Control - Remote Code Execution
Unspecified vulnerability in the EmbeddedWB Web Browser ActiveX control allows remote attackers to execute arbitrary cod
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Kiwi CatTools TFTP 3.2.8 - Directory Traversal
Directory traversal vulnerability in the TFTP server in Kiwi CatTools before 3.2.0 beta allows remote attackers to read
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Nullsoft SHOUTcast 1.9.7 - Logfile HTML Injection
Cross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitra
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - Audit Subsystems Local Denial of Service
The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SolarPay - 'index.php' Local File Inclusion
Directory traversal vulnerability in index.php in SolarPay allows remote attackers to read certain files via a .. (dot d
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 10g Database - 'SUBSCRIPTION_NAME' SQL Injection (2)
SQL injection vulnerability in the Oracle Database Server 10g allows remote authenticated users to execute arbitrary SQL
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Audins Audiens 3.3 - 'unistall.php' Authentication Bypass
Audins Audiens 3.3 allows remote attackers to bypass authentication and perform certain privileged actions, possibly an
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Audins Audiens 3.3 - 'setup.php?PATH_INFO' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in setup.php in Audins Audiens 3.3 allows remote attackers to inject arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Audins Audiens 3.3 - '/system/index.php?Cookie PHPSESSID' SQL Injection
SQL injection vulnerability in system/index.php in Audins Audiens 3.3 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SQLiteManager 1.2 - Local File Inclusion
Directory traversal vulnerability in SQLiteManager 1.2.0 allows remote attackers to read arbitrary files via a .. (dot d
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pagesetter 6.2/6.3.0 - 'index.php' Local File Inclusion
Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows r
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SQLiteManager 1.2 - 'main.php' Multiple HTML Injection Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.0 allow remote attackers to inject arbitrary we
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 10g KUPV$FT.ATTACH_JOB - SQL Injection (2)
Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arb
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 10g - KUPW$WORKER.MAIN SQL Injection (2)
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 9i/10g ACTIVATE_SUBSCRIPTION - SQL Injection (2)
SQL injection vulnerability in the Oracle Database Server 10g allows remote authenticated users to execute arbitrary SQL
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Core 2.1.1 - 'post.php' Cross-Site Scripting
Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.