Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8.970Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
iScripts Socialware - 'id' SQL Injection
iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sens
23RISCO
abrir ↗Referência✓ VexDay Proof
BtiTracker 1.4.7 / xbtit 2.0.542 - SQL Injection
SQL injection vulnerability in scrape.php in BtiTracker 1.4.7 and earlier and xBtiTracker 2.0.542 and earlier allows rem
23RISCO
abrir ↗Referência✓ VexDay Proof
Micro CMS 0.3.5 - Remote Add/Delete/Password Change
microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP Coupon Script 3.0 - 'bus' SQL Injection
SQL injection vulnerability in index.php in PHP Coupon Script 3.0 allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir ↗Referência✓ VexDay Proof
xml2owl 0.1.1 - 'showcode.php' Remote Command Execution
showCode.php in xml2owl 0.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPMyCart 1.3 - 'cat' SQL Injection
SQL injection vulnerability in shop.php in Conkurent PHPMyCart allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
wotw 5.0 - Local/Remote File Inclusion
PHP remote file inclusion vulnerability in visualizza.php in Way Of The Warrior (WOTW) 5.0 and earlier allows remote att
23RISCO
abrir ↗Referência✓ VexDay Proof
GRBoard 1.8 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in GRBoard 1.8, when register_globals is enabled and magic_quotes_gpc
23RISCO
abrir ↗Referência✓ VexDay Proof
acute control panel 1.0.0 - SQL Injection / Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Acute Control Panel 1.0.0 allow remote attackers to execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
microssys CMS 1.5 - Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Wajox Software microSSys CMS 1.5 and earlier, when register_glob
23RISCO
abrir ↗Referência✓ VexDay Proof
deeemm CMS (dmcms) 0.7.4 - Multiple Vulnerabilities
PHP remote file inclusion vulnerability in user_language.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to exec
23RISCO
abrir ↗Referência✓ VexDay Proof
ADN Forum 1.0b - Insecure Cookie Handling
index.php in ADN Forum 1.0b and earlier allows remote attackers to bypass authentication and gain sysop access via a fpu
23RISCO
abrir ↗Referência✓ VexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
Flat PHP Board 1.2 and earlier allows remote attackers to bypass authentication and obtain limited access to an arbitrar
23RISCO
abrir ↗Referência✓ VexDay Proof
Acc PHP eMail 1.1 - Insecure Cookie Handling
Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLET
23RISCO
abrir ↗Referência✓ VexDay Proof
minimal ablog 0.4 - SQL Injection / Arbitrary File Upload / Authentication Bypass
uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrativ
23RISCO
abrir ↗Referência✓ VexDay Proof
TurnkeyForms - Text Link Sales Authentication Bypass
admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privi
23RISCO
abrir ↗Referência✓ VexDay Proof
Exjune Officer Message System 1 - Multiple Vulnerabilities
exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which all
23RISCO
abrir ↗Referência✓ VexDay Proof
RantX 1.0 - Insecure Admin Authentication
The admin.php file in Rantx allows remote attackers to bypass authentication and gain privileges by setting the logininf
23RISCO
abrir ↗Referência✓ VexDay Proof
CodeAvalanche RateMySite - Database Disclosure
CodeAvalanche RateMySite stores sensitive information under the web root with insufficient access control, which allows
23RISCO
abrir ↗Referência✓ VexDay Proof
DreamAccount 3.1 - 'da_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in DreamAccount 3.1 and earlier, when register_globals is enabled, al
28RISCO
abrir ↗Referência✓ VexDay Proof
PHPMyphorum 1.5a - '/mep/frame.php' Remote File Inclusion
PHP remote file inclusion vulnerability in mep/frame.php in PHPMyphorum 1.5a allows remote attackers to execute arbitrar
23RISCO
abrir ↗Referência✓ VexDay Proof
Net-Side.net CMS - 'index.php?cms' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Net Side Content Management System (Net-Side.net CMS) allows rem
23RISCO
abrir ↗Referência✓ VexDay Proof
Free Image Hosting 2.0 - 'AD_BODY_TEMP' Remote File Inclusion
PHP remote file inclusion vulnerability in frontpage.php in Free Image Hosting 2.0 and earlier allows remote attackers t
23RISCO
abrir ↗Referência✓ VexDay Proof
EHCP 0.22.8 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Easy Hosting Control Panel for Ubuntu (EHCP) 0.22.8 and earlier al
23RISCO
abrir ↗Referência✓ VexDay Proof
Affiliate Market 0.1 Beta - 'Language' Local File Inclusion
Directory traversal vulnerability in user/header.php in Affiliate Market 0.1 BETA allows remote attackers to include and
23RISCO
abrir ↗Referência✓ VexDay Proof
Clever Copy 3.0 - 'results.php' SQL Injection
SQL injection vulnerability in results.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
Contenido 4.8.4 - Remote File Inclusion / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arb
23RISCO
abrir ↗Referência✓ VexDay Proof
LokiCMS 0.3.4 - 'admin.php' Create Local File Inclusion
Directory traversal vulnerability in admin.php in LokiCMS 0.3.4, when magic_quotes_gpc is disabled, allows remote attack
23RISCO
abrir ↗Referência✓ VexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-inse
23RISCO
abrir ↗Referência✓ VexDay Proof
Webace-Linkscript 1.3 SE - 'start.php' SQL Injection
SQL injection vulnerability in start.php in Webace-Linkscript (wls) 1.3 Special Edition (SE) allows remote attackers to
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.