Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.866exploits catalogados
35.812CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.573GitHub PoC 14.316VulnCheck XDB 8.722Nuclei 4.320Metasploit 3.477✓ só verificadosrecentespopularesrisco
24.455 exploits
Exploit-DB✓ VexDay Proof
Azerbaijan Development Group AzDGDatingPlatinum 1.1.0 - 'view.php?id' SQL Injection
Multiple SQL injection vulnerabilities in AzDGDatingPlatinum 1.1.0 allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RadScripts RadBids Gold 2.0 - 'index.php?mode' SQL Injection
SQL injection vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.x/2.6.x - BlueTooth Signed Buffer Index Privilege Escalation (1)
The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
The Includer CGI 1.0 - Remote Command Execution (3)
includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the U
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
The Includer CGI 1.0 - Remote Command Execution (2)
includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the U
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AN HTTPD - 'CMDIS.dll' Remote Buffer Overflow (PoC)
Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PostNuke Phoenix 0.760 RC3 - 'OP' Cross-Site Scripting
Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote attackers to inject arbitrary web scrip
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PostNuke Phoenix 0.760 RC3 - 'Module' Cross-Site Scripting
Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote attackers to inject arbitrary web scrip
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AN HTTPD 1.42 - Arbitrary Log Content Injection
CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
P2P Share Spy 2.2 - Local Password Disclosure
Rebrand P2P Share Spy 2.2 stores the user password in plaintext in the txtPassword value in the registry, which allows l
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 6.x < 7.6 Top module - SQL Injection
SQL injection vulnerability in the Top module for PHP-Nuke 6.x through 7.6 allows remote attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linksys WET11 - Password Update Remote Authentication Bypass
Linksys WET11 1.5.4 allows remote attackers to change the password without providing the original password via the data
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SGI IRIX 6.5.22 - GR_OSView Information Disclosure
gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files w
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SGI IRIX 6.5.22 - GR_OSView Local Arbitrary File Overwrite
gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary fil
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 7.6 Web_Links Module - Multiple SQL Injections
Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 7.6 allow remote attackers to execute arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Active Auction House - 'start.asp?ReturnURL' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary w
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CubeCart 2.0.x - 'view_cart.php?add' Full Path Disclosure
CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.ph
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Lotus Domino Server 6.5.1 Web Service - Remote Denial of Service
NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attac
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Active Auction House - 'WatchThisItem.asp' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary w
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Active Auction House - 'account.asp?ReturnURL' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary w
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpBB 2.0.13 Linkz Pro Module - SQL Injection
Multiple SQL injection vulnerabilities in SnailSource phpBB 2.0.x mods allow remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpBB 2.0.13 DLMan Pro Module - SQL Injection
Multiple SQL injection vulnerabilities in SnailSource phpBB 2.0.x mods allow remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Active Auction House - 'ItemInfo.asp' SQL Injection
Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CubeCart 2.0.x - 'view_product.php?product' Full Path Disclosure
CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.ph
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FTP Now 2.6.14 - Local Password Disclosure
FTP Now 2.6.14 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local use
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ocean12 Membership Manager Pro - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to i
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CubeCart 2.0.x - 'tellafriend.php?product' Full Path Disclosure
CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.ph
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 7.6 Web_Links Module - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web scrip
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Active Auction House - 'default.asp' Multiple SQL Injections
Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CubeCart 2.0.x - 'index.php' Multiple Full Path Disclosures
CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.ph
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.