Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8.970Nuclei 4.394Metasploit 3.502✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
CRE Loaded 6.2 - 'products_id' SQL Injection
SQL injection vulnerability in product_info.php in CRE Loaded 6.2 allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir ↗Referência✓ VexDay Proof
Maran PHP Shop - 'prod.php' SQL Injection
SQL injection vulnerability in prod.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir ↗Referência✓ VexDay Proof
Seditio CMS Events Plugin - 'c' SQL Injection
SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 allows remote attacker
23RISCO
abrir ↗Referência✓ VexDay Proof
MyForum 1.3 - Insecure Cookie Handling
Graphiks MyForum 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the (1)
23RISCO
abrir ↗Referência✓ VexDay Proof
Flatchat 3.0 - 'pmscript.php' Local File Inclusion
Directory traversal vulnerability in pmscript.php in Flatchat 3.0 allows remote attackers to include and execute arbitra
23RISCO
abrir ↗Referência✓ VexDay Proof
fungamez rc1 - Authentication Bypass / Local File Inclusion
Directory traversal vulnerability in admin/load.php in FunGamez RC1 allows remote attackers to include and execute arbit
23RISCO
abrir ↗Referência✓ VexDay Proof
Invision Power Board 2.0.3 - 'login.php' SQL Injection
SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary
28RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Cmimarketplace - 'viewit' Directory Traversal
Directory traversal vulnerability in the Cmi Marketplace (com_cmimarketplace) component 0.1 for Joomla! allows remote at
38RISCO
abrir ↗Referência✓ VexDay Proof
GOM Player 2.1.16.6134 - Subtitle Local Buffer Overflow (PoC)
Stack-based buffer overflow in srt2smi.exe in Gretech Online Movie Player (GOM Player) 2.1.16.4635 allows remote attacke
23RISCO
abrir ↗Referência✓ VexDay Proof
Merlix Teamworx Server - File Disclosure/Bypass
SQL injection vulnerability in default.asp in Merlix Teamworx Server allows remote attackers to execute arbitrary SQL co
23RISCO
abrir ↗Referência✓ VexDay Proof
S-CMS 1.1 Stable - 'page' Local File Inclusion
Directory traversal vulnerability in plugin.php in S-Cms 1.1 Stable and 1.5.2 allows remote attackers to include and exe
23RISCO
abrir ↗Referência✓ VexDay Proof
Kusaba 1.0.4 - Remote Code Execution (1)
Multiple unrestricted file upload vulnerabilities in Kusaba 1.0.4 and earlier allow remote authenticated users to execut
23RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft GDI Plugin - '.png' Infinite Loop Denial of Service (PoC)
GDI+ in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (infinite loop) via a PNG file tha
28RISCO
abrir ↗Referência✓ VexDay Proof
TemaTres 1.0.3 - Blind SQL Injection
Multiple SQL injection vulnerabilities in TemaTres 1.0.3 and 1.031, when magic_quotes_gpc is disabled, allow remote atta
23RISCO
abrir ↗Referência✓ VexDay Proof
FCRing 1.31 - 'fcring.php?s_fuss' Remote File Inclusion
PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP cod
23RISCO
abrir ↗Referência✓ VexDay Proof
webSPELL 4.01.02 - 'topic' SQL Injection
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrar
23RISCO
abrir ↗Referência✓ VexDay Proof
NukeSentinel 2.5.05 - 'nukesentinel.php' File Disclosure
SQL injection vulnerability in nukesentinel.php in NukeSentinel 2.5.05, and possibly earlier, allows remote attackers to
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_lowcosthotels - Blind SQL Injection
SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joo
23RISCO
abrir ↗Referência✓ VexDay Proof
phpclanwebsite 1.23.3 fix pack #5 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc
23RISCO
abrir ↗Referência✓ VexDay Proof
32bit FTP (09.04.24) - 'CWD Response' Remote Buffer Overflow
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
23RISCO
abrir ↗Referência✓ VexDay Proof
32bit FTP (09.04.24) - 'CWD Response' Universal Overwrite (SEH)
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
23RISCO
abrir ↗Referência✓ VexDay Proof
Soritong MP3 Player 1.0 - Local Buffer Overflow (SEH)
Stack-based buffer overflow in Sorinara Soritong MP3 Player 1.0 allows remote attackers to execute arbitrary code via a
23RISCO
abrir ↗Referência✓ VexDay Proof
Avant Browser 11.0 build 26 - Remote Stack Overflow Crash
Stack-based buffer overflow in Avant Browser 11.0 build 26 allows remote attackers to cause a denial of service (crash)
23RISCO
abrir ↗Referência✓ VexDay Proof
Pluck CMS 4.6.2 - 'langpref' Local File Inclusion
Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to
28RISCO
abrir ↗Referência✓ VexDay Proof
StrawBerry 1.1.1 - Local File Inclusion / Remote Command Execution
Directory traversal vulnerability in plugins/ddb/foot.php in Strawberry 1.1.1 allows remote attackers to include and exe
28RISCO
abrir ↗Referência✓ VexDay Proof
Eggdrop/Windrop 1.6.19 - ctcpbuf Remote Crash
mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of
23RISCO
abrir ↗Referência✓ VexDay Proof
ST-Gallery 0.1a - Multiple SQL Injections
Multiple SQL injection vulnerabilities in the getGalleryImage function in st_admin/gallery_output.php in ST-Gallery 0.1
23RISCO
abrir ↗Referência✓ VexDay Proof
Adobe JRun 4 - 'logfile' (Authenticated) Directory Traversal
Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4
23RISCO
abrir ↗Referência✓ VexDay Proof
ICQ 6.5 - URL Search Hook (Windows Explorer) Remote Buffer Overflow (PoC)
Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial
23RISCO
abrir ↗Referência✓ VexDay Proof
Frontis 3.9.01.24 - 'source_class' SQL Injection
SQL injection vulnerability in bin/aps_browse_sources.php in Frontis 3.9.01.24 allows remote attackers to execute arbitr
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.