Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.620exploits catalogados
35.647CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.429GitHub PoC 14.270VulnCheck XDB 8.693Nuclei 4.299Metasploit 3.474✓ só verificadosrecentespopularesrisco
24.455 exploits
Exploit-DB✓ VexDay Proof
CMS Faethon 1.3.2 - 'mainpath' Remote File Inclusion
Multiple cross-site scripting (XSS) vulnerabilities in CMS Faethon 1.3.2 allow remote attackers to inject arbitrary web
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
mcGuestbook 1.3 - 'admin.php?lang' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in mcGuestbook 1.3 allow remote attackers to execute arbitrary PHP co
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bitweaver 1.3 - 'tmpImagePath' Attachment mod_mime
CRLF injection vulnerability in Bitweaver 1.3 allows remote attackers to conduct HTTP response splitting attacks by via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HotPlug CMS 1.0 - 'Login1.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in administration/tblcontent/login1.php in HotPlug CMS 1.0 allows remote attack
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bitweaver 1.3 - 'tmpImagePath' Attachment mod_mime
Cross-site scripting (XSS) vulnerability in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bitweaver 1.3 - 'tmpImagePath' Attachment mod_mime
users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parame
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pico Zip 4.01 - 'Filename' Local Buffer Overflow
Stack-based buffer overflow in the info tip shell extension (zipinfo.dll) in PicoZip 4.01 allows remote attackers to exe
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DeluxeBB 1.06 - 'templatefolder' Remote File Inclusion
PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote attackers to execute arbitrary code via a URL in
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VBZoom 1.11 - 'forum.php' SQL Injection
SQL injection vulnerability in forum.php in VBZooM 1.11 allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Secure ACS 2.3 - 'LoginProxy.cgi' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to i
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ISPConfig 2.2.3 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP co
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000 - 'Mrxsmb.sys' Local Privilege Escalation (MS06-030)
The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 an
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL Server 4/5 - Str_To_Date Remote Denial of Service
mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Works 8.0 Spreadsheet - Multiple Vulnerabilities
wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet 8.0 allows remote attackers to cause a denial of service (CPU consump
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Blue Dragon CMS 2.9.1 - 'template.php' File Inclusion
PHP remote file inclusion vulnerability in software_upload/public_includes/pub_templates/vphptree/template.php in PhpBlu
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000 - 'Mrxsmb.sys' Local Privilege Escalation (MS06-030)
The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 an
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - NtClose DeadLock (MS06-030)
The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 an
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RahnemaCo - 'page.php' Remote File Inclusion
PHP remote file inclusion vulnerability in page.php in an unspecified RahnemaCo.com product, possibly eShop, allows remo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MyBulletinBoard (MyBB) < 1.1.3 - Remote Code Execution
The domecode function in inc/functions_post.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows rem
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Andy Mack 35mm Slide Gallery 6.0 - 'index.php?imgdir' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in 35mmslidegallery 6.0 allow remote attackers to inject arbitrary w
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DoubleSpeak 0.1 - Multiple Remote File Inclusions
PHP remote file inclusion vulnerability in DoubleSpeak 0.1, when register_globals is enabled, allows remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Andy Mack 35mm Slide Gallery 6.0 - 'popup.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in 35mmslidegallery 6.0 allow remote attackers to inject arbitrary w
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft SMB Driver - Local Denial of Service
The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 an
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CEScripts (Multiple Scripts) - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Event Registration allows remote attackers to inject arbitrary web script or
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft DXImageTransform.Microsoft.Light - ActiveX Control Remote Code Execution
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execu
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Exchange Server 2000/2003 - Outlook Web Access Script Injection
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Acc
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Five Star Review Script - 'index2.php?sort' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in 5 Star Review allow remote attackers to inject arbitrary web scri
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SixCMS 6.0 - 'list.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in list.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iFoto 0.20 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly other versions before 0.50, allows remote attackers
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SixCMS 6.0 - 'detail.php' Directory Traversal
Directory traversal vulnerability in detail.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote atta
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.