Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
μTorrent (uTorrent) 1.6 build 474 - 'announce' Key Remote Heap Overflow
Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a c
35RISCO
abrir ↗Referência✓ VexDay Proof
Total Video Player 1.20 - '.m3u' File Local Stack Buffer Overflow
Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers t
28RISCO
abrir ↗Referência✓ VexDay Proof
Jupiter CMS 1.1.5 - Arbitrary File Upload
Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload a
23RISCO
abrir ↗Referência✓ VexDay Proof
ActSoft DVD-Tools - 'dvdtools.ocx' Remote Buffer Overflow
Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary cod
23RISCO
abrir ↗Referência✓ VexDay Proof
k-links directory - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links allows remote attackers to inject arbitrary web s
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component EZ Store Remote - Blind SQL Injection
SQL injection vulnerability in the EZ Store (com_ezstore) component for Joomla! allows remote attackers to execute arbit
23RISCO
abrir ↗Referência✓ VexDay Proof
phsBlog 0.1.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in phsBlog 0.1.1 allow remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir ↗Referência✓ VexDay Proof
Symphony 1.7.01 (non-patched) - Remote Code Execution
Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and e
23RISCO
abrir ↗Referência✓ VexDay Proof
OpenImpro 1.1 - 'image.php' SQL Injection
SQL injection vulnerability in image.php in OpenImpro 1.1 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir ↗Referência✓ VexDay Proof
Quicksilver Forums 1.4.1 - SQL Injection
SQL injection vulnerability in index.php in Quicksilver Forums 1.4.1 allows remote attackers to execute arbitrary SQL co
23RISCO
abrir ↗Referência✓ VexDay Proof
Vacation Rental Script 3.0 - 'id' SQL Injection
SQL injection vulnerability in index.php in Vacation Rental Script 3.0 allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
TubeGuru Video Sharing Script - 'UID' SQL Injection
SQL injection vulnerability in ugroups.php in PozScripts TubeGuru Video Sharing Script allows remote attackers to execut
23RISCO
abrir ↗Referência✓ VexDay Proof
Ventrilo 3.0.2 - Null Pointer Remote Denial of Service
The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of s
23RISCO
abrir ↗Referência✓ VexDay Proof
Enrollment System Project v1.0 - SQL Injection Authentication Bypass (SQLI)
Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to
53RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft Visual Studio - 'Msmask32.ocx' ActiveX Remote Buffer Overflow (PoC)
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft Visual Studio - 'Msmask32.ocx' ActiveX Remote Buffer Overflow
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RISCO
abrir ↗Referência✓ VexDay Proof
phpArcadeScript 4 - 'cat' SQL Injection
SQL injection vulnerability in index.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute a
23RISCO
abrir ↗Referência✓ VexDay Proof
cyberBB 0.6 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in cyberBB 0.6 allow remote authenticated users to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
Ad Board - 'id' SQL Injection
SQL injection vulnerability in trr.php in YourFreeWorld Ad Board Script allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
Extreme phpBB 3.0.1 - 'functions.php' Remote File Inclusion
PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka phpBB Extreme) 3.0.1 allows remote attack
23RISCO
abrir ↗Referência✓ VexDay Proof
SCO UnixWare Reliant HA 1.1.4 - Local Privilege Escalation
Untrusted search path vulnerability in (1) hvdisp and (2) rcvm in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local use
23RISCO
abrir ↗Referência✓ VexDay Proof
SCO UnixWare Merge - 'mcd' Local Privilege Escalation
Merge mcd in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges via a crafted -d argument
23RISCO
abrir ↗Referência✓ VexDay Proof
minimal ablog 0.4 - SQL Injection / Arbitrary File Upload / Authentication Bypass
Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arb
23RISCO
abrir ↗Referência✓ VexDay Proof
Banner Management Script - 'id' SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Banner Management Script allows remote attackers to execute arbit
23RISCO
abrir ↗Referência✓ VexDay Proof
YourFreeWorld Classifieds - 'category' SQL Injection
SQL injection vulnerability in view.php in YourFreeWorld Classifieds Script allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
YourFreeWorld Viral Marketing - SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Viral Marketing Script allows remote attackers to execute arbitra
23RISCO
abrir ↗Referência✓ VexDay Proof
VMware Workstation 6.5.1 - 'hcmon.sys 6.0.0.45731' Local Denial of Service
hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VM
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP Live Helper 2.0.1 - Multiple Vulnerabilities
SQL injection vulnerability in onlinestatus_html.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attacker
23RISCO
abrir ↗Referência✓ VexDay Proof
Quick Poll Script - 'id' SQL Injection
SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir ↗Referência✓ VexDay Proof
SunShop Shopping Cart 4.1.4 - 'id' SQL Injection
Multiple SQL injection vulnerabilities in class.ajax.php in Turnkey Web Tools SunShop Shopping Cart before 4.1.5 allow r
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.