Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8.843Nuclei 4.358Metasploit 3.489✓ só verificadosrecentespopularesrisco
22.910 exploits
Referência
Joomla! Component Jimtawl 2.1.6 - Arbitrary File Upload
Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true
35RISCO
abrir ↗Referência
Joomla! Component JMS Music 1.1.1 - SQL Injection
SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username par
23RISCO
abrir ↗Referência
CVE-2018-6583
SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request.
28RISCO
abrir ↗Referência
CVE-2018-6584
SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request.
23RISCO
abrir ↗Referência
CVE-2018-6604
SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetail
23RISCO
abrir ↗Referência
CVE-2018-6606
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows
23RISCO
abrir ↗Referência
Joomla! Component JSP Tickets 1.1 - SQL Injection
SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit acti
23RISCO
abrir ↗Referência
CVE-2018-6756
True Key (TK) Windows Client - Authentication Abuse vulnerability
41RISCO
abrir ↗Referência
CVE-2018-6849
In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client informati
43RISCO
abrir ↗Referência
CVE-2018-7602
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISCO
abrir ↗Referência
CVE-2018-7739
antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and
35RISCO
abrir ↗Referência
CVE-2018-7777
The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Ele
35RISCO
abrir ↗Referência
CVE-2018-7841
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code
100RISCO
abrir ↗Referência
CVE-2018-7921
Huawei B315s-22 products with software of 21.318.01.00.26 have an information leak vulnerability. Unauthenticated adjace
28RISCO
abrir ↗Referência
CVE-2018-8021
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to pos
35RISCO
abrir ↗Referência
CVE-2018-8065
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access v
60RISCO
abrir ↗Referência
CVE-2018-8174
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir ↗Referência✓ VexDay Proof
CascadianFAQ 4.1 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to exe
23RISCO
abrir ↗Referência✓ VexDay Proof
Galeria Zdjec 3.0 - 'zd_numer.php' Local File Inclusion
Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include an
23RISCO
abrir ↗Referência✓ VexDay Proof
GuppY 4.5.16 - Remote Command Execution
Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject
23RISCO
abrir ↗Referência✓ VexDay Proof
Dev-C++ 4.9.9.2 - '.CPP' File Parsing Local Stack Overflow (PoC)
Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of serv
23RISCO
abrir ↗Referência✓ VexDay Proof
Hailboards 1.2.0 - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers t
23RISCO
abrir ↗Referência✓ VexDay Proof
ExoPHPDesk 1.2.1 - 'faq.php' SQL Injection
SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 and earlier allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
Cadre PHP Framework - Remote File Inclusion
PHP remote file inclusion vulnerability in fw/class.Quick_Config_Browser.php in Cadre PHP Framework 20020724 allows remo
23RISCO
abrir ↗Referência✓ VexDay Proof
Fullaspsite Asp Hosting Sitesi - 'tr' SQL Injection
SQL injection vulnerability in windows.asp in Fullaspsite Asp Hosting Sitesi allows remote attackers to execute arbitrar
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPMyRing 4.1.3b - 'fichier' Remote File Inclusion
PHP remote file inclusion vulnerability in lang/leslangues.php in Nicolas Grandjean PHPMyRing 4.1.3b and earlier allows
23RISCO
abrir ↗Referência✓ VexDay Proof
Chicken of the VNC 2.0 - 'NULL-pointer' Remote Denial of Service
Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large compu
23RISCO
abrir ↗Referência✓ VexDay Proof
CoD2: DreamStats 4.2 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and ear
23RISCO
abrir ↗Referência✓ VexDay Proof
Flip 2.01 final - 'previewtheme.php?inc_path' Remote File Inclusion
PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote
35RISCO
abrir ↗Referência✓ VexDay Proof
Photo Galerie Standard 1.1 - 'view.php' SQL Injection
SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.