Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.600GitHub PoC 14.323VulnCheck XDB 8.722Nuclei 4.320Metasploit 3.477✓ só verificadosrecentespopularesrisco
22.600 exploits
Referência✓ VexDay Proof
APC ActionApps CMS 2.8.1 - Remote File Inclusion
PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a
28RISCO
abrir ↗Referência✓ VexDay Proof
Socketwiz BookMarks 2.0 - 'root_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in smarty_config.php in Socketwiz Bookmarks 2.0 and earlier allows remote attack
23RISCO
abrir ↗Referência✓ VexDay Proof
NetProxy 4.03 - Web Filter Evasion / Bypass Logging
Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from
23RISCO
abrir ↗Referência✓ VexDay Proof
CNStats 2.9 - 'who_r.php?bj' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in CNStats 2.9 allow remote attackers to execute arbitrary PHP code v
23RISCO
abrir ↗Referência✓ VexDay Proof
Chipmunk Blog - (Authentication Bypass) Add Admin
Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.p
23RISCO
abrir ↗Referência
CVE-2015-4414
Directory traversal vulnerability in download_audio.php in the SE HTML5 Album Audio Player (se-html5-album-audio-player)
43RISCO
abrir ↗Referência
CVE-2009-4796
Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in
23RISCO
abrir ↗Referência✓ VexDay Proof
Syntax Desktop 2.7 - 'synTarget' Local File Inclusion
Directory traversal vulnerability in admin/modules/aa/preview.php in Syntax Desktop 2.7 allows remote attackers to inclu
23RISCO
abrir ↗Referência✓ VexDay Proof
Flip 3.0 - Remote Admin Creation
account.php in Adam Scheinberg Flip 3.0 and earlier allows remote attackers to create administrative accounts via the un
23RISCO
abrir ↗Referência✓ VexDay Proof
Catviz 0.4.0 beta1 - Local File Inclusion / Cross-Site Scripting
Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrar
23RISCO
abrir ↗Referência
CVE-2010-4865
SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to e
23RISCO
abrir ↗Referência✓ VexDay Proof
UploadImage/UploadScript 1.0 - Remote Change Admin Password
admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which al
23RISCO
abrir ↗Referência
CVE-2013-1892
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMo
50RISCO
abrir ↗Referência
CVE-2013-1892
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMo
50RISCO
abrir ↗Referência✓ VexDay Proof
Verlihub Control Panel 1.7.x - Local File Inclusion
Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers
23RISCO
abrir ↗Referência
CVE-2018-13134
TP-Link Archer C1200 1.13 Build 2018/01/24 rel.52299 EU devices have XSS via the PATH_INFO to the /webpages/data URI.
23RISCO
abrir ↗Referência✓ VexDay Proof
yourplace 1.0.2 - Multiple Vulnerabilities / Remote Code Execution
login/register_form.php in YourPlace 1.0.2 and earlier does not check that a username already exists when a new account
23RISCO
abrir ↗Referência
CVE-2017-10033
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Support Tools). Support
23RISCO
abrir ↗Referência
CVE-2014-3216
GOM Media Player 2.2.57.5189 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg
23RISCO
abrir ↗Referência
CVE-2014-4699
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved
23RISCO
abrir ↗Referência
CVE-2014-4699
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved
23RISCO
abrir ↗Referência
Printix Client 1.3.1106.0 - Remote Code Execution (RCE)
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL
28RISCO
abrir ↗Referência
CVE-2018-17310
On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of add
23RISCO
abrir ↗Referência
CVE-2015-4591
eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remo
23RISCO
abrir ↗Referência
CVE-2017-2509
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" com
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.