Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8.846Nuclei 4.361Metasploit 3.490✓ só verificadosrecentespopularesrisco
19.066 exploits
Exploit-DB✓ VexDay Proof
Command School Student Management System - '/sw/admin_generations.php?id' SQL Injection
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Command School Student Management System - '/sw/admin_grades.php?id' SQL Injection
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Libcloud Digital Ocean API - Local Information Disclosure
Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows loca
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Advanced Dewplayer - 'download-file.php' Script Directory Traversal
Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CMS Afroditi - 'id' SQL Injection
SQL injection vulnerability in Naxtech CMS Afroditi 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
JForum 'adminUsers' Module - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote attack
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RealNetworks RealPlayer 16.0.3.51/16.0.2.32 - '.rmp' Version Attribute Buffer Overflow
Heap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RealNetworks RealPlayer 16.0.3.51/16.0.2.32 - '.rmp' Version Attribute Buffer Overflow
Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP SiteScope issueSiebelCmd - Remote Code Execution (Metasploit)
The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authenti
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zimbra Collaboration Server 7.2.2/8.0.2 - Local File Inclusion (Metasploit)
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSIS 'modname' - PHP Code Execution (Metasploit)
Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP cod
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat CloudForms Management Engine 5.1 - agent/linuxpkgs Directory Traversal (Metasploit)
Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow re
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Synology DiskStation Manager - SLICEUPLOAD Remote Command Execution (Metasploit)
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Hancom Office - '.hml' File Processing Heap Buffer Overflow
Buffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DenyHosts - 'regex.py' Remote Denial of Service
denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Leed - 'id' SQL Injection
SQL injection vulnerability in action.php in Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to e
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ability Mail Server 2013 3.1.1 - Web UI Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Code-Crafters Ability Mail Server 3.1.1 allows remote attackers to inject ar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Nvidia (nvsvc) Display Driver Service - Local Privilege Escalation (Metasploit)
The NVIDIA driver before 307.78, and Release 310 before 311.00, in the NVIDIA Display Driver service on Windows does not
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'ndproxy.sys' Local Privilege Escalation (Metasploit)
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges
98RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Reader ToolButton - Use-After-Free (Metasploit)
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitr
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'win32k.sys' Integer Overflow (MS13-101)
Integer overflow in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Core 2.0.11 - '/wp-admin/options-discussion.php' Script Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPre
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
C2C Forward Auction Creator - '/auction/casp/Admin.asp' SQL Injection (Admin Authentication Bypass)
Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQ
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Gitlab 6.0 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versions before 6.5.0 allows remote attackers to inject
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Icinga - cgi/config.c process_cgivars Function Off-by-One Read Remote Denial of Service
Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
C2C Forward Auction Creator 2.0 - '/auction/asp/list.asp?pa' SQL Injection
Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQ
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iScripts AutoHoster - 'additionalsettings.php' SQL Injection
Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iScripts AutoHoster - 'tmpid' Local File Inclusion
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iScripts AutoHoster - 'main_smtp.php' Traversal
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iScripts AutoHoster - 'id' Local File Inclusion
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitr
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.