Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.056exploits catalogados
35.925CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.392VulnCheck XDB 8.755Nuclei 4.333Metasploit 3.478✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Attila PHP 3.0 - SQL Injection Unauthorized Privileged Access
SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to b
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Real Server 7/8/9 (Windows / Linux) - Remote Code Execution
Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetwor
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OptiSoft Blubster 2.5 - Remote Denial of Service
Blubster 2.5 allows remote attackers to cause a denial of service (crash) via a flood of connections to UDP port 701.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Avant Browser 8.0.2 - 'HTTP Request' Buffer Overflow (PoC)
Buffer overflow in Avant Browser 8.02 allows remote attackers to cause a denial of service (crash) and possibly execute
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Object Data Remote (MS03-032)
Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) all
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RealOne Player 1.0/2.0/6.0.10/6.0.11 - '.SMIL' File Script Execution
RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation wit
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DameWare Mini Remote Control Server - System
Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle XDB FTP Service - UNLOCK Buffer Overflow
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHPOutSourcing Zorum 3.x - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 earch Module - 'PDA_limit' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute ar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 pagemaster Module - 'PAGE_id' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute ar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 fatcat Module - 'fatcat_id' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute ar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHPOutsourcing Zorum 3.4 - Full Path Disclosure
index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names,
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.6.2 - Remote Command Execution
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to exe
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - DCOM RPC Interface Buffer Overrun
Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 Calendar Module - 'day' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute ar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Website 0.7.3/0.8.2/0.8.3/0.9.2 Calendar Module - SQL Injection
SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute ar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco IOS 12.x/11.x - HTTP Remote Integer Overflow
Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Informix Dynamic Server 9.40/Informix Extended Parallel Server 8.40 - Multiple Vulnerabilities (2)
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, wit
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PostNuke 0.6/0.7 Downloads Module - TTitle Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web sc
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Informix Dynamic Server 9.40/Informix Extended Parallel Server 8.40 - Multiple Vulnerabilities (1)
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, wit
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'RPC DCOM' Remote (Universal)
The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and loc
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
man-db 2.4.1 - 'open_cat_stream()' Local uid=man
man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when run
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin 3.0 - 'register.php' HTML Injection
Cross-site scripting (XSS) vulnerability in register.php for vBulletin 3.0 Beta 2 allows remote attackers to inject arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.6.0/2.6.1/2.6.2 - 'realpath()' Off-by-One Buffer Overflow
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to exe
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM DB2 - Shared Library Injection
IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM DB2 db2job - File Overwrite
IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and g
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Postfix 1.1.x - Denial of Service (2)
The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Postfix 1.1.x - Denial of Service (1)
The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.6.2 - Off-by-One Remote Command Execution
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to exe
45RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.