Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.620exploits catalogados
35.647CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.429GitHub PoC 14.270VulnCheck XDB 8.693Nuclei 4.299Metasploit 3.474✓ só verificadosrecentespopularesrisco
24.455 exploits
Exploit-DB✓ VexDay Proof
DreamAccount 3.1 - 'auth.api.php' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/index.php in DreamAccount 3.1 allows remote attackers to execute arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Winged Gallery 1.0 - 'Thumb.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in gallery/thumb.php in Winged Gallery 1.0 allows remote attackers to inject ar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MailEnable 1.x - SMTP 'HELO' Remote Denial of Service
The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier b
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
XM Easy Personal FTP Server 5.0.1 - 'Port' Remote Overflow (PoC)
Format string vulnerability in XM Easy Personal FTP Server 5.0.1 allows remote attackers to cause a denial of service (a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jaws 0.6.2 - Search gadget SQL Injection
SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Yahoo! Messenger 7.0/7.5 - 'jscript.dll' Non-ASCII Character Denial of Service
Yahoo! Messenger 7.5.0.814 and 7.0.438 allows remote attackers to cause a denial of service (crash) via messages that co
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Usenet 0.5 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Usenet Script 0.5 allows remote attackers to inject arbitrary w
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BlueDragon Server 6.2.1 - '.cfm' Denial of Service
BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to cause a denial of service (hang) via a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mambo 4.6rc1 - Weblinks Blind SQL Injection (2)
SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SoftBizScripts Dating Script 1.0 - 'featured_photos.php' SQL Injection
Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1)
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ralf image Gallery 0.7.4 - Multiple Vulnerabilities
PHP remote file inclusion vulnerability in check_entry.php in Ralf Image Gallery (RIG), aka Raphael Moll RIG Image Galle
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SoftBizScripts Dating Script 1.0 - 'news_desc.php' SQL Injection
Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1)
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SoftBizScripts Dating Script 1.0 - 'index.php' SQL Injection
Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1)
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2003 - Embedded Shockwave Flash Object Security Bypass
Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows RRAS - Remote Stack Overflow (MS06-025) (Metasploit)
Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Serve
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SoftBizScripts Dating Script 1.0 - 'products.php' SQL Injection
Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1)
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Woltlab Burning Board 1.2/2.0/2.3 - 'report.php?postid' SQL Injection
SQL injection vulnerability in report.php in Woltlab Burning Board (WBB) 2.3.1 allows remote attackers to execute arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Woltlab Burning Board 1.2/2.0/2.3 - 'newthread.php?boardid' SQL Injection
SQL injection vulnerability in newthread.php in Woltlab Burning Board (WBB) 2.0 RC2 allows remote attackers to execute a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ralf image Gallery 0.7.4 - Multiple Vulnerabilities
Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Event Calendar 4.2 - SQL Injection
SQL injection vulnerability in calendar.php in Codewalkers ltwCalendar (aka PHP Event Calendar) 4.2, 4.1.3, and earlier
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Excel - Code Execution
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrar
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Blue Dragon CMS 2.9.1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in phpBlueDragon 2.9.1 allow remote attackers to execute arbitrary PH
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Woltlab Burning Board 1.2/2.0/2.3 - 'showmods.php?boardid' SQL Injection
SQL injection vulnerability in showmods.php in Woltlab Burning Board (WBB) 1.2 allows remote attackers to execute arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
e107 0.7.5 - 'Subject' HTML Injection
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 9 - long href Remote Denial of Service
Opera 9 allows remote attackers to cause a denial of service (crash) via an A tag with an href attribute with a URL cont
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Maximus SchoolMAX 4.0.1 - 'Error_msg' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in icue_login.asp in Maximus SchoolMAX 4.0.1 and earlier iCue and iParent appli
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin 3.0.9/3.5.x - 'member.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary we
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
V3 Chat Instant Messenger - 'search.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
V3 Chat Instant Messenger - 'expire.php?cust_name' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
V3 Chat Instant Messenger - 'mycontacts.php' membername Arbitrary User Buddy List Manipulation
mycontacts.php in V3 Chat allows remote authenticated users to gain privileges as other users via a modified membername
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.