Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.449exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8.649Nuclei 4.283Metasploit 3.474✓ só verificadosrecentespopularesrisco
24.451 exploits
Exploit-DB✓ VexDay Proof
Outpost Firewall PRO 4.0 - Local Privilege Escalation
Agnitum Outpost Firewall PRO 4.0 allows local users to bypass access restrictions and insert Trojan horse drivers into t
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
InstantASP 4.1 - 'Logon.aspx?sessionid' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web s
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jax Petition Book 3.06 - 'jax_petitionbook.php?languagepack' Local File Inclusion
Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin SpamBam - Key Calculation Security Bypass
The SpamBam plugin for WordPress allows remote attackers to bypass restrictions and add blog comments by using server-su
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Kaspersky AntiVirus 6.0 - Local Privilege Escalation
Unspecified vulnerability in KLIF (klif.sys) in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for Fi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
InstantASP 4.1 - 'Members1.aspx' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web s
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jax Petition 3.06 Book - 'smileys.php?languagepack' Local File Inclusion
Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Libgtop2 Library - Local Buffer Overflow
Stack-based buffer overflow in the glibtop_get_proc_map_s function in libgtop before 2.14.6 (libgtop2) allows local user
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple WebKit build 18794 - WebCore Remote Denial of Service
WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and applicati
41RISCO
abrir ↗Exploit-DB✓ VexDay Proof
KarjaSoft Sami FTP Server 2.0.2 - USER/PASS Remote Buffer Overflow (PoC)
Stack-based buffer overflow in Sami FTP Server 2.0.1 allows remote attackers to execute arbitrary code via a long USER c
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.8 - DMG UFS UFS_LookUp Denial of Service
The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 7.x - 'Block-Old_Articles.php' SQL Injection
SQL injection vulnerability in blocks/block-Old_Articles.php in Francisco Burzi PHP-Nuke 7.9 and earlier, when register_
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 0.8.6a - Denial of Service (1)
VideoLAN VLC 0.8.6a allows remote attackers to cause a denial of service (application crash) via a crafted .wmv file.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WinZip 9.0 - Command Line Remote Buffer Overflow
Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and po
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
All In One Control Panel 1.3.x - 'cp_downloads.php?did' SQL Injection
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.010 and earlier, when magic_quotes_gpc is
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpBB 2.0.21 - 'privmsg.php' HTML Injection
Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows r
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 0.8.6a - Denial of Service (2)
VideoLAN VLC 0.8.6a allows remote attackers to cause a denial of service (application crash) via a crafted .wmv file.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CA BrightStor ARCserve Backup - Message Engine/Tape Engine Remote Buffer Overflow
The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.8 - DMG UFS FFS_MountFS Integer Overflow
Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
eIQnetworks Network Security Analyzer - Null Pointer Dereference
The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Magic Photo Storage Website - '/user/couple_profile.php?_config[site_path]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.8 - Apple Finder DMG Volume Name Memory Corruption (PoC)
Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly e
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Edit-X - 'Edit_Address.php' Remote File Inclusion
PHP remote file inclusion vulnerability in edit_address.php in edit-x ecommerce allows remote attackers to execute arbit
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Magic Photo Storage Website - '/user/user_membership_password.php?_config[site_path]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Magic Photo Storage Website - '/user/user_extend.php?_config[site_path]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Magic Photo Storage Website - '/user/user_email.php?_config[site_path]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Magic Photo Storage Website - '/user/user_catelog_password.php?_config[site_path]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Magic Photo Storage Website - '/user/login.php?_config[site_path]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Magic Photo Storage Website - '/user/index.php?_config[site_path]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Magic Photo Storage Website - '/user/delete_category.php?_config[site_path]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.