Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8.970Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
Absolute Content Rotator 6.0 - Insecure Cookie Handling
Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RISCO
abrir ↗Referência✓ VexDay Proof
PPStream - 'PowerPlayer.dll 2.0.1.3829' ActiveX Remote Overflow
Buffer overflow in the PowerPlayer.dll ActiveX control in PPStream 2.0.1.3829 allows remote attackers to execute arbitra
23RISCO
abrir ↗Referência✓ VexDay Proof
Dragoon 0.1 - 'lng' Local File Inclusion
Directory traversal vulnerability in forum/kietu/libs/calendrier.php in Dragoon 0.1 allows remote attackers to include a
23RISCO
abrir ↗Referência✓ VexDay Proof
SasCam WebCam Server 2.6.5 - ActiveX Remote Buffer Overflow
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote
50RISCO
abrir ↗Referência✓ VexDay Proof
WordPress Core 2.1.2 - 'xmlrpc' SQL Injection
SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated
23RISCO
abrir ↗Referência✓ VexDay Proof
WengoPhone 2.x - SIP Phone Remote Denial of Service
WengoPhone 2.1 allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Co
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPStore Car Dealers - Arbitrary File Upload
Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitra
23RISCO
abrir ↗Referência✓ VexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (1)
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RISCO
abrir ↗Referência✓ VexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (2)
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RISCO
abrir ↗Referência✓ VexDay Proof
ASPPortal 3.1.1 - 'downloadid' SQL Injection
Multiple SQL injection vulnerabilities in ASPPortal 3.1.1 and earlier allow remote attackers to execute arbitrary SQL co
23RISCO
abrir ↗Referência✓ VexDay Proof
ViArt CMS/Shop/Helpdesk 3.3.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Sho
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component JoomlaXplorer 1.6.2 - Remote s
Directory traversal vulnerability in index.php in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 an
23RISCO
abrir ↗Referência✓ VexDay Proof
ScriptsFeed (SF) Real Estate Classifieds Software - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows re
23RISCO
abrir ↗Referência✓ VexDay Proof
ScriptsFeed (SF) Auto Classifieds Software - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbi
23RISCO
abrir ↗Referência✓ VexDay Proof
UeberProject 1.0 - '/login/secure.php' Remote File Inclusion
PHP remote file inclusion vulnerability in login/secure.php in UeberProject Management System 1.0 and earlier allows rem
23RISCO
abrir ↗Referência✓ VexDay Proof
Frequency Clock 0.1b - 'securelib' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Frequency Clock 0.1b (Beta 0.1) allow remote attackers to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
AuraCMS 2.1 - Remote File Attachment / Local File Inclusion
Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute ar
23RISCO
abrir ↗Referência✓ VexDay Proof
XZero Community Classifieds 4.95.11 - Local File Inclusion / SQL Injection
Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attacker
23RISCO
abrir ↗Referência✓ VexDay Proof
ChilkatHttp ActiveX 2.3 - Arbitrary Files Overwrite
The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0,
23RISCO
abrir ↗Referência✓ VexDay Proof
Bankoi Webhost Panel 1.20 - Authentication Bypass
Multiple SQL injection vulnerabilities in login.asp in Bankoi WebHosting Control Panel 1.20 allow remote attackers to ex
23RISCO
abrir ↗Referência✓ VexDay Proof
Active PHP Bookmark Notes 0.2.5 - Remote File Inclusion
PHP remote file inclusion vulnerability in templates/head.php in Active PHP Bookmark Notes (APB) 0.2.5 and earlier allow
23RISCO
abrir ↗Referência✓ VexDay Proof
Clever Internet ActiveX Suite 6.2 - Arbitrary File Download/Overwrite
Absolute path traversal vulnerability in the clInetSuiteX6.clWebDav ActiveX control in CLINETSUITEX6.OCX in Clever Inter
23RISCO
abrir ↗Referência✓ VexDay Proof
ExBB 0.22 - Local/Remote File Inclusion
Directory traversal vulnerability in modules/threadstop/threadstop.php in ExBB Italia 0.22 and earlier, when register_gl
23RISCO
abrir ↗Referência✓ VexDay Proof
Sun xVM VirtualBox < 1.6.4 - Privilege Escalation (PoC)
The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communicat
71RISCO
abrir ↗Referência✓ VexDay Proof
DFLabs PTK 1.0 - Local Command Execution
The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute ar
23RISCO
abrir ↗Referência✓ VexDay Proof
Discuz! - Remote Reset User Password
member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostp
23RISCO
abrir ↗Referência✓ VexDay Proof
aspwebalbum 3.2 - Multiple Vulnerabilities
Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary c
23RISCO
abrir ↗Referência✓ VexDay Proof
Links Directory 1.1 - 'cat_id' SQL Injection
SQL injection vulnerability in links.php in Scriptsagent.com Links Directory 1.1 allows remote authenticated users to ex
23RISCO
abrir ↗Referência✓ VexDay Proof
The Rat CMS Alpha 2 - Authentication Bypass
Multiple SQL injection vulnerabilities in login.php in The Rat CMS Alpha 2 allow remote attackers to execute arbitrary S
23RISCO
abrir ↗Referência✓ VexDay Proof
falcon CMS 1.4.3 - Remote File Inclusion / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to inject arbi
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.