Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.056exploits catalogados
35.925CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.392VulnCheck XDB 8.755Nuclei 4.333Metasploit 3.478✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
PhpGedView 2.61 - PHPInfo Information Disclosure
admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Edimax AR-6004 ADSL Router - Management Interface Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the web management interface in Edimax AR-6004 ADSL Routers allows remote at
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHPGedView 2.61 - Multiple Remote File Inclusions
PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php fo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.23/2.6.0 - 'do_mremap()' Bound Checking Validator (1)
The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SnapStream PVS Lite 2.0 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script o
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ZYXEL ZyWALL 10 Management Interface - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to in
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PhpGedView 2.61 - Search Script Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HT
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HotNews 0.x - 'config[incdir]' Remote File Inclusion
PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP co
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HotNews 0.x - 'hotnews-engine.inc.php3?config[header]' Remote File Inclusion
PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP co
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpBB 1.x/2.0.x - 'search.php?search_results' SQL Injection
SQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FreznoShop 1.2.3/1.3 - Search Script Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to i
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Webcam Corp Webcam Watchdog 1.0/1.1/3.63 Web Server - Remote Buffer Overflow
Buffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long H
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ASP-Nuke 1.0/1.2/1.3 - Remote User Database Access
ASP-Nuke 1.3 and earlier places user credentials under the web document root with insufficient access control, which all
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ASPApp PortalApp - Remote User Database Access
PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
EasyDynamicPages 1.0 - 'config_page.php' PHP Remote File Inclusion
PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Athena Web Registration - Remote Command Execution
athenareg.php in Athena Web Registration allows remote attackers to execute arbitrary commands via shell metacharacters
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Surfnet 1.31 - CMD_CREDITCARD_CHARGE Denial of Service
Info Touch Surfnet kiosk allows local users to crash Surfnet and access the underlying operating system via the CMD_CRED
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
YaSoft Switch Off 2.3 - 'swnet.dll' Remote Buffer Overflow
Stack-based buffer overflow in swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote authenticated users to execu
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
YaSoft Switch Off 2.3 - Large Packet Remote Denial of Service
swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
XSOK 1.02 - '-xsokdir' Local Buffer Overflow Game
Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, o
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
XSOK 1.0 2 - 'LANG Environment' Local Buffer Overrun
Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, o
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000 - showHelp '.CHM' File Execution (MS03-004)
Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal a
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Alt-N MDaemon 6.x/WorldClient - Form2Raw Raw Message Handler Buffer Overflow (2)
Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbi
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Alt-N MDaemon 6.x/WorldClient - Form2Raw Raw Message Handler Buffer Overflow (1)
Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbi
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - Failure To Log Undocumented TRACK Requests
Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote a
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 2.0.4x mod_php - File Descriptor Leakage (2)
The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 2.0.4x mod_php - File Descriptor Leakage (1)
The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
KnowledgeBuilder 2.0/2.1/3.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote at
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Opera Browser 6.0 6 - URI Display Obfuscation
Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before a
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 6.x - 'Category' SQL Injection
SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary S
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.