Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
HP-UX 11i - 'swask' Format String Privilege Escalation
Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to exec
23RISCO
abrir ↗Referência✓ VexDay Proof
SourceForge 1.0.4 - 'database.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/database.php in SourceForge (aka alexandria) 1.0.4 allows remote atta
23RISCO
abrir ↗Referência✓ VexDay Proof
FreeWebShop.org script 2.2.2 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 and earlier allow remote attackers to execute a
23RISCO
abrir ↗Referência✓ VexDay Proof
FreeWebShop.org script 2.2.2 - Multiple Vulnerabilities
Directory traversal vulnerability in index.php in FreeWebshop 2.2.1 and earlier allows remote attackers to read arbitrar
23RISCO
abrir ↗Referência✓ VexDay Proof
Creasito E-Commerce Content Manager - 'admin' Authentication Bypass
Creasito E-Commerce Content Manager 1.3.08 allows remote attackers to bypass authentication and perform privileged funct
23RISCO
abrir ↗Referência✓ VexDay Proof
Omni-NFS Server 5.2 - 'nfsd.exe' Remote Stack Overflow (Metasploit)
Stack-based buffer overflow in nfsd.exe in XLink Omni-NFS Server 5.2 allows remote attackers to execute arbitrary code v
50RISCO
abrir ↗Referência✓ VexDay Proof
SAP Web Application Server 6.40 - Arbitrary File Disclosure
Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 a
23RISCO
abrir ↗Referência✓ VexDay Proof
iPrimal Forums - '/admin/index.php' Change User Password
admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to bypass authentication and modify user passwo
23RISCO
abrir ↗Referência✓ VexDay Proof
Quick.CMS.Lite 0.3 - Cookie sLanguage Local File Inclusion
Directory traversal vulnerability in general.php in OpenSolution Quick.Cms.Lite 0.3 allows remote attackers to include a
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPAdventure 1.1 - 'ad_main.php' Remote File Inclusion
PHP remote file inclusion vulnerability in ad_main.php in PHPAdventure 1.1-Alpha and earlier allows remote attackers to
23RISCO
abrir ↗Referência✓ VexDay Proof
IrayoBlog 0.2.4 - '/inc/irayofuncs.php' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/irayofuncs.php in IrayoBlog alpha-0.2.4 allows remote attackers to execut
23RISCO
abrir ↗Referência✓ VexDay Proof
Xcode OpenBase 10.0.0 (OSX) - Symlink Privilege Escalation
openexec in OpenBase SQL before 10.0.1 allows local users to create arbitrary files via a symlink attack on the /tmp/out
23RISCO
abrir ↗Referência✓ VexDay Proof
Xcode OpenBase 10.0.0 (OSX) - Unsafe System Call Privilege Escalation
Untrusted search path vulnerability in openexec in OpenBase SQL before 10.0.1 allows local users to gain privileges via
23RISCO
abrir ↗Referência✓ VexDay Proof
USupport 1.0 - 'detail.asp' SQL Injection
SQL injection vulnerability in detail.asp in Superfreaker Studios USupport 1.0 allows remote attackers to execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
AspPired2Poll 1.0 - 'MoreInfo.asp' SQL Injection
SQL injection vulnerability in MoreInfo.asp in The Net Guys ASPired2Poll 1.0 and earlier allows remote attackers to exec
23RISCO
abrir ↗Referência✓ VexDay Proof
StoryStream 4.0 - 'baseDir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in iWonder Designs Storystream 0.4.0.0 allow remote attackers to exec
23RISCO
abrir ↗Referência✓ VexDay Proof
Rama CMS 0.68 - Cookie: lang Local File Inclusion
Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows rem
23RISCO
abrir ↗Referência✓ VexDay Proof
EncapsCMS 0.3.6 - '/core/core.php' Remote File Inclusion
PHP remote file inclusion vulnerability in core/core.php in EncapsCMS 0.3.6 allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
PgmReloaded 0.8.5 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in PgmReloaded 0.8.5 and earlier allow remote attackers to execute ar
23RISCO
abrir ↗Referência✓ VexDay Proof
phpProfiles 3.1.2b - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute a
23RISCO
abrir ↗Referência✓ VexDay Proof
Ixprim CMS 1.2 - Blind SQL Injection
The code function in install.fct.php in Ixprim 1.2 produces a guessable value of the confidential IXP_CODE in mainfile.p
23RISCO
abrir ↗Referência✓ VexDay Proof
cwmExplorer 1.0 - 'show_file' Source Code Disclosure
Directory traversal vulnerability in index.php in cwmExplorer 1.0 allows remote attackers to read arbitrary files and so
23RISCO
abrir ↗Referência✓ VexDay Proof
Http explorer Web Server 1.02 - Directory Traversal
Directory traversal vulnerability in Http explorer 1.02 allows remote attackers to read arbitrary files via a .. (dot do
23RISCO
abrir ↗Referência✓ VexDay Proof
RealPlayer 10.5 - ActiveX Control Denial of Service
A certain ActiveX control in rpau3260.dll in RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of s
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPMyManga 0.8.1 - 'template.php' Multiple File Inclusions
Multiple PHP remote file inclusion vulnerabilities in template.php in Phpmymanga 0.8.1 and earlier allow remote attacker
23RISCO
abrir ↗Referência✓ VexDay Proof
Pagetool CMS 1.07 - 'pt_upload.php' Remote File Inclusion
Multiple PHP file inclusion vulnerabilities in src/admin/pt_upload.php in Pagetool 1.07 allow remote attackers to execut
23RISCO
abrir ↗Referência✓ VexDay Proof
Jinzora 2.7 - 'INCLUDE_PATH' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Jinzora Media Jukebox 2.7 and earlier, when register_globals is en
23RISCO
abrir ↗Referência✓ VexDay Proof
Irokez Blog 0.7.1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Irokez CMS 0.7.1 and earlier, when register_globals is enabled, al
23RISCO
abrir ↗Referência✓ VexDay Proof
Ciberia Content Federator 1.0.1 - 'path' Remote File Inclusion
PHP remote file inclusion vulnerability in socios/maquetacion_socio.php (members/maquetacion_member.php) in Ciberia Cont
23RISCO
abrir ↗Referência✓ VexDay Proof
acFTP FTP Server 1.5 - 'REST/PBSZ' Remote Denial of Service
acFTP 1.5 allows remote authenticated users to cause a denial of service via a crafted argument to the (1) REST or (2) P
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.