Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8.970Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
CoolPlayer 2.17 - '.m3u' Local Stack Overflow
Multiple buffer overflows in Niek Albers CoolPlayer 216 and earlier allow remote attackers to execute arbitrary code via
23RISCO
abrir ↗Referência✓ VexDay Proof
torrentflux 2.2 - Arbitrary File Create/ Execute/Delete
index.php for TorrentFlux 2.2 allows remote registered users to execute arbitrary commands via shell metacharacters in t
23RISCO
abrir ↗Referência✓ VexDay Proof
F-Prot AntiVirus 4.6.6 - CHM Heap Overflow (PoC)
Heap-based buffer overflow in FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to exec
28RISCO
abrir ↗Referência✓ VexDay Proof
RiteCMS 2.2.1 - Authenticated Remote Code Execution
An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php
28RISCO
abrir ↗Referência✓ VexDay Proof
vBlog / C12 0.1 - 'cfgProgDir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Vortex Blog (vBlog, aka C12) a0.1_nonfunc allow remote attackers t
23RISCO
abrir ↗Referência✓ VexDay Proof
TorrentFlux 2.2 - 'downloaddetails.php' Local File Disclosure
Directory traversal vulnerability in downloaddetails.php in TorrentFlux 2.2 allows remote authenticated users to read ar
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPMyCMS 0.3 - 'basic.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in basic.inc.php in PhpMyCms 0.3 allows remote attackers to execute arbitrary PH
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPAlbum 0.4.1 Beta 6 - 'language.php' Local File Inclusion
Directory traversal vulnerability in language.php in phpAlbum 0.4.1 Beta 6 and earlier, when magic_quotes_gpc is disable
23RISCO
abrir ↗Referência✓ VexDay Proof
AstonSoft DeepBurner 1.8.0 - '.dbr' File Parsing Buffer Overflow
Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute
50RISCO
abrir ↗Referência✓ VexDay Proof
VerliAdmin 0.3 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in VerliAdmin 0.3 and earlier allows remote authenticated users to
23RISCO
abrir ↗Referência✓ VexDay Proof
TextSend 1.5 - '/config/sender.php' Remote File Inclusion
PHP remote file inclusion vulnerability in sender.php in Carsen Klock TextSend 1.5 allows remote attackers to execute ar
23RISCO
abrir ↗Referência✓ VexDay Proof
Webmin 1.962 - 'Package Updates' Escape Bypass RCE (Metasploit)
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can ex
28RISCO
abrir ↗Referência✓ VexDay Proof
Valdersoft Shopping Cart 3.0 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to
23RISCO
abrir ↗Referência✓ VexDay Proof
E-Uploader Pro 1.0 - Image Upload / Code Execution
Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to exe
23RISCO
abrir ↗Referência✓ VexDay Proof
Newxooper-PHP 0.9.1 - 'mapage.php' Remote File Inclusion
PHP remote file inclusion vulnerability in compteur/mapage.php in Newxooper 0.9.1 allows remote attackers to execute arb
23RISCO
abrir ↗Referência✓ VexDay Proof
PowerClan 1.14a - 'footer.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabl
23RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows - 'NetrWkstaUserEnum()' Remote Denial of Service
The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (m
35RISCO
abrir ↗Referência✓ VexDay Proof
BolinTech DreamFTP Server 1.0.2 - 'PORT' Remote Denial of Service
BolinTech Dream FTP Server 1.02 allows remote authenticated users, including anonymous users, to cause a denial of servi
23RISCO
abrir ↗Referência✓ VexDay Proof
cwmVote 1.0 - 'archive.php' Remote File Inclusion
PHP remote file inclusion vulnerability in archive.php in cwmVote 1.0 allows remote attackers to execute arbitrary PHP c
23RISCO
abrir ↗Referência✓ VexDay Proof
Paristemi 0.8.3b - 'buycd.php' Remote File Inclusion
PHP remote file inclusion vulnerability in buycd.php in Paristemi 0.8.3 allows remote attackers to execute arbitrary PHP
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to exec
23RISCO
abrir ↗Referência✓ VexDay Proof
Macromedia Shockwave 10 'SwDir.dll' Internet Explorer 7 - Denial of Service
An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Interne
23RISCO
abrir ↗Referência✓ VexDay Proof
Voodoo chat 1.0RC1b - 'users.dat' Password Disclosure
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remot
23RISCO
abrir ↗Referência✓ VexDay Proof
Vz (Adp) Forum 2.0.3 - Remote Password Disclosure
Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remo
23RISCO
abrir ↗Referência✓ VexDay Proof
Formbankserver 1.9 - 'Name' Remote Denial of Service
formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a
23RISCO
abrir ↗Referência✓ VexDay Proof
Quote&Ordering System 1.0 - 'ordernum' Multiple Vulnerabilities
SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users
23RISCO
abrir ↗Referência✓ VexDay Proof
CA BrightStor ARCserve - 'tapeeng.exe' Remote Buffer Overflow
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote a
28RISCO
abrir ↗Referência✓ VexDay Proof
uniForum 4 - 'wbsearch.aspx' SQL Injection
SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
WordPress Core 2.0.6 - 'wp-trackback.php' SQL Injection
wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric
28RISCO
abrir ↗Referência✓ VexDay Proof
Apple Mac OSX 10.4.8 - AppleTalk 'ATPsndrsp()' Heap Buffer Overflow (PoC)
Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remot
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.