Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.549GitHub PoC 14.290VulnCheck XDB 8.722Nuclei 4.320Metasploit 3.477✓ só verificadosrecentespopularesrisco
24.455 exploits
Exploit-DB✓ VexDay Proof
EasyPHPCalendar 6.1.5/6.2.x - 'setupSQL.php?serverPath' Remote File Inclusion
PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
EasyPHPCalendar 6.1.5/6.2.x - 'popup.php?serverPath' Remote File Inclusion
PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
XML-RPC Library 1.3.0 - 'xmlrpc.php' Remote Command Execution (2)
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PH
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Nokia Affix < 3.2.0 - btftp Remote Client
Buffer overflow in Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitr
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RaXnet Cacti 0.5/0.6.x/0.8.x - 'Graph_Image.php' Remote Command Execution Variant
PHP file inclusion vulnerability in top_graph_header.php in Cacti 0.8.6d and possibly earlier versions allows remote att
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
XML-RPC Library 1.3.0 - 'xmlrpc.php' Remote Code Injection
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PH
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
osTicket 1.2/1.3 - 'view.php?inc' Arbitrary Local File Inclusion
PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CyberStrong eShop 4.2 - '10expand.asp' SQL Injection
SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication informa
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
fsboard 2.0 - Directory Traversal
Directory traversal vulnerability in default.asp for FSboard 2.0 allows remote attackers to read arbitrary files via "..
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Core 1.5.1.2 - 'xmlrpc' Interface SQL Injection
SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitra
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CyberStrong EShop 4.2 - '20review.asp' SQL Injection
SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication informa
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Message Queuing - Remote Buffer Overflow Universal (MS05-017) (v.0.3)
Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Hosting Controller 6.1 - 'error.asp' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BisonFTP 4R1 - Remote Denial of Service
BisonFTP Server V4R1 allows remote authenticated users to cause a denial of service via an invalid command with a long a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 9/10 - 'ld.so' Local Privilege Escalation (2)
The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 9/10 - 'ld.so' Local Privilege Escalation (1)
The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ASPNuke 0.80 - 'forgot_password.asp?email' Cross-Site Scripting
Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Inframail Advantage Server Edition 6.0 < 6.37 - 'SMTP' Buffer Overflow
Buffer overflow in Inframail Advantage Server Edition 6.0 through 6.7 allows remote attackers to cause a denial of servi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ASPNuke 0.80 - 'article.asp' SQL Injection
SQL injection vulnerability in article.asp in unknown versions of aspnuke allows remote attackers to execute arbitrary S
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ASPNuke 0.80 - 'Language_Select.asp' HTTP Response Splitting
HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web conte
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Inframail Advantage Server Edition 6.0 < 6.37 - 'FTP' Buffer Overflow
Buffer overflow in Inframail Advantage Server Edition 6.0 through 6.7 allows remote attackers to cause a denial of servi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ASPNuke 0.80 - 'comment_post.asp' SQL Injection
SQL injection vulnerability in comment_post.asp in ASP Nuke 0.80 allows remote attackers to execute arbitrary SQL statem
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ASPNuke 0.80 - 'register.asp' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IA eMailServer Corporate Edition 5.2.2 - Denial of Service
Format string vulnerability in IMAP4 in IA eMailServer Corporate Edition 5.2.2 build 1051 allows remote attackers to cau
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
UBBCentral UBB.Threads < 6.5.2 Beta - 'mailthread.php' SQL Injection
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Fusion 6.00.105 - Accessible Database Backups Download
PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficien
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
UBBCentral UBB.Threads 5.5.1/6.x - 'grabnext.php?posted' SQL Injection
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Solaris 10 Traceroute - Multiple Local Buffer Overflow Vulnerabilities
traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privile
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
UBBCentral UBB.Threads 5.5.1/6.x - 'download.php?Number' SQL Injection
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitr
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.