Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.549GitHub PoC 14.290VulnCheck XDB 8.722Nuclei 4.320Metasploit 3.477✓ só verificadosrecentespopularesrisco
24.455 exploits
Exploit-DB✓ VexDay Proof
Cyphor 0.19 - 'lostpwd.php?nick' SQL Injection
Multiple SQL injection vulnerabilities in Cyphor 0.19 allow remote attackers to execute arbitrary SQL and obtain adminis
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cyphor 0.19 - Board Takeover (SQL Injection)
SQL injection vulnerability in show.php in Cyphor 0.19 and earlier allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cyphor 0.19 - 'newmsg.php?fid' SQL Injection
Multiple SQL injection vulnerabilities in Cyphor 0.19 allow remote attackers to execute arbitrary SQL and obtain adminis
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cyphor 0.19 - 'footer.php?t_login' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Cyphor 0.19 allows remote attackers to inject arbitrary web script or HTML v
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 9 - XML DB Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle HTML DB 1.5/1.6 - 'wwv_flow.accept?p_t02' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Aenovo - '/incs/searchdisplay.asp?strSQL' SQL Injection
Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execut
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Aenovo - '/Password/default.asp?Password' SQL Injection
Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execut
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Utopia News Pro 1.1.3 - 'footer.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to i
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Forms - Servlet TLS Listener Remote Denial of Service
The forms servlet (f90servlet) in Oracle Forms 4.5.10.22 allows remote attackers to cause a denial of service (TNS liste
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle HTML DB 1.5/1.6 - 'f?p=' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Utopia News Pro 1.1.3 - 'header.php?sitetitle' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to i
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 9.0 iSQL*Plus - TLS Listener Remote Denial of Service
iSQL*Plus (isqlplus) for Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to cause a denial of service
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Utopia News Pro 1.1.3 - 'news.php' SQL Injection
SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TellMe 1.2 - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in TellMe 1.2 and earlier allows remote attackers to inject arbitrary web scrip
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 1.0.6/1.0.7 - iFrame Handling Denial of Service
Mozilla Firefox 1.0.7 and earlier on Linux allows remote attackers to cause a denial of service (client crash) via an IF
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP - Wireless Zero Configuration Service Information Disclosure
The Microsoft Wireless Zero Configuration system (WZCS) stores WEP keys and pair-wise Master Keys (PMK) of the WPA pre-s
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Gnome-PTY-Helper UTMP - Hostname Spoofing
gnome-pty-helper in GNOME libzvt2 and libvte4 allows local users to spoof the logon hostname via a modified DISPLAY envi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Prozilla 1.3.7.4 - 'ftpsearch' Results Handling Buffer Overflow
Buffer overflow in the get_string_ahref function for ProZilla 1.3.7.4 and possibly earlier, with the -ftpsearch option e
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Virtools Web Player 3.0.0.100 - Buffer Overflow (Denial of Service) (PoC)
Buffer overflow in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to execute arbitrary code via a lon
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Merak Mail Server 8.2.4 r - Arbitrary File Deletion
Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earli
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IceWarp Web Mail 5.5.1 - 'blank.html?id' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibl
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IceWarp Web Mail 5.5.1 - 'calendar_d.html?createdataCX' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibl
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IceWarp Web Mail 5.5.1 - 'calendar_m.html?createdataCX' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibl
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IceWarp Web Mail 5.5.1 - 'calendar_w.html?createdataCX' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibl
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
LucidCMS 2.0 - Login SQL Injection
SQL injection vulnerability in lucidCMS 1.0.11 allows remote attackers to execute arbitrary SQL commands via the login f
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SquirrelMail 1.4.2 Address Add Plugin - 'add.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in add.php in Address Add Plugin 1.9 and 2.0 for Squirrelmail allows remote att
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TWiki TWikiUsers - INCLUDE Function Arbitrary Command Execution
The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary co
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Fusion 6.00.109 - 'msg_send' SQL Injection
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CubeCart 3.0.3 - 'cart.php?redir' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web scr
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.