Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.549GitHub PoC 14.290VulnCheck XDB 8.722Nuclei 4.320Metasploit 3.477✓ só verificadosrecentespopularesrisco
24.455 exploits
Exploit-DB✓ VexDay Proof
MySource 2.14 - 'header.php?bgcolor' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'edit_table_props.php?bgcolor' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NetFlow Analyzer 4 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'edit_table_row_props.php?bgcolor' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Snort 2.4.0 < 2.4.3 - Back Orifice Pre-Preprocessor Remote (Metasploit)
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to exec
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'edit_table_cell_props.php?bgcolor' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'edit_table_cell_type_wysiwyg.php?Stylesheet' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Lynx 2.8.6dev.13 - Remote Buffer Overflow (PoC)
Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbit
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6 - Console Keymap Local Command Injection
The VT implementation (vt_ioctl.c) in Linux kernel 2.6.12, and possibly other versions including 2.6.14.4, allows local
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Comersus Backoffice Plus - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus allows re
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 8.02 - Remote Denial of Service (2)
Opera 8.02 and earlier allows remote attackers to cause a denial of service (client crash) via (1) a crafted HTML file w
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 8.02 - Remote Denial of Service (1)
Opera 8.02 and earlier allows remote attackers to cause a denial of service (client crash) via (1) a crafted HTML file w
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PunBB 1.2.x - 'search.php' SQL Injection
SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Complete PHP Counter - SQL Injection
Multiple SQL injection vulnerabilities in list.php in Complete PHP Counter allow remote attackers to execute arbitrary S
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 4.0.3 - Requests Containing MS-DOS Device Names Information Disclosure
Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TYPSoft FTP Server 1.11 - 'RETR' Denial of Service
TYPSoft FTP 0.95 allows remote attackers to cause a denial of service (CPU consumption) via a "../../*" argument to (1)
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Complete PHP - Counter Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in list.php in Complete PHP Counter allows remote attackers to inject arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TYPSoft FTP Server 1.11 - 'RETR' Denial of Service
Typsoft FTP Server 1.11, with "Sub Directory Include" enabled, allows remote attackers to cause a denial of service (cra
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
YaPiG 0.95b - 'view.php?img_size' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow rem
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Accelerated Mortgage Manager - 'Password' SQL Injection
SQL injection vulnerability in Accelerated Mortgage Manager allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebGUI 6.x - Arbitrary Command Execution
Unspecified vulnerability in the www_add method in Asset.pm in Plain Black WebGUI 6.3.0 and other versions before 6.7.6
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000/2003 - MSDTC TIP Denial of Service (MS05-051)
Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC servic
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RARLAB WinRar 2.90/3.x - UUE/XXE Invalid Filename Error Message Format String
Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via for
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Accelerated E Solutions - SQL Injection
SQL injection vulnerability in an unspecified Accelerated Enterprise Solutions product, possibly Accelerated E Solutions
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 2.6.4-pl1 - Directory Traversal
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to in
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SGI IRIX 6.5.28 - 'runpriv' Design Error
runpriv in SGI IRIX allows local users to bypass intended restrictions and execute arbitrary commands via shell metachar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Up-IMAPProxy 1.2.3/1.2.4 - Multiple Unspecified Remote Format String Vulnerabilities
Format string vulnerability in the ParseBannerAndCapability function in main.c for up-imapproxy 1.2.3 and 1.2.4 allows r
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CA iTechnology iGateway - 'Debug Mode' Remote Buffer Overflow
Buffer overflow in Computer Associates (CA) iGateway 3.0 and 4.0 before 4.0.050623, when running in debug mode, allows r
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
versatileBulletinBoard 1.00 RC2 - Board Takeover (SQL Injection)
Multiple SQL injection vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to execute arbit
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Xine-Lib 1.1 - 'Media Player Library' Remote Format String
Format string vulnerability in input_cdda.c in xine-lib 1-beta through 1-beta 3, 1-rc, 1.0 through 1.0.2, and 1.1.1 allo
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.