Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8.970Nuclei 4.394Metasploit 3.502✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
Pre Real Estate Listings - Arbitrary File Upload
Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticat
23RISCO
abrir ↗Referência✓ VexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to execute arbitra
23RISCO
abrir ↗Referência✓ VexDay Proof
Kjtechforce mailman b1 - Delete Row 'code' SQL Injection
Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote att
23RISCO
abrir ↗Referência✓ VexDay Proof
EgyPlus 7ml 1.0.1 - Authentication Bypass
cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit whe
53RISCO
abrir ↗Referência✓ VexDay Proof
Carom3D 5.06 - Unicode Buffer Overrun/Denial of Service
The LAN game feature in Carom3D 5.06 allows remote authenticated users to cause a denial of service (application hang) v
23RISCO
abrir ↗Referência✓ VexDay Proof
Barracuda Web Application Firewall - Authentication Bypass
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a perm
28RISCO
abrir ↗Referência✓ VexDay Proof
Nero ShowTime 5.0.15.0 - '.m3u' Playlist File Remote Buffer Overflow (PoC)
Buffer overflow in Nero ShowTime 5.0.15.0 allows remote attackers to cause a denial of service (crash) and possibly exec
23RISCO
abrir ↗Referência✓ VexDay Proof
ReVou Twitter Clone - Authentication Bypass
Multiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
HockeySTATS Online 2.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in TheHockeyStop HockeySTATS Online 2.0 Basic and Advanced allow remote attackers
23RISCO
abrir ↗Referência✓ VexDay Proof
Mozilla Firefox 3.0.5 - Status Bar Obfuscation / Clickjacking
Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that
23RISCO
abrir ↗Referência✓ VexDay Proof
Multiple Vendor - PF Null Pointer Dereference
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirO
23RISCO
abrir ↗Referência✓ VexDay Proof
iPhotoAlbum 1.1 - 'header.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in iPhotoAlbum 1.1 allow remote attackers to execute arbitrary code v
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPWebThings 1.5.2 - 'help.php?module' Local File Inclusion
Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allo
23RISCO
abrir ↗Referência✓ VexDay Proof
Mundi Mail 0.8.2 - 'top' Remote File Inclusion
PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when regi
23RISCO
abrir ↗Referência✓ VexDay Proof
LushiNews 1.01 - 'comments.php' SQL Injection
SQL injection vulnerability in comments.php in LushiNews 1.01 and earlier allows remote authenticated users to inject ar
23RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft DNS Server - Dynamic DNS Update/Change
The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients i
35RISCO
abrir ↗Referência✓ VexDay Proof
0irc-client 1345 build20060823 - Denial of Service
0irc 1345 build 20060823 allows remote attackers to cause a denial of service (application crash) by operating an IRC se
23RISCO
abrir ↗Referência✓ VexDay Proof
IPSwitch IMail Server 8.0x - Remote Heap Overflow
Heap-based buffer overflow in iaspam.dll in the SMTP Server in Ipswitch IMail Server 8.01 through 8.11 allows remote att
23RISCO
abrir ↗Referência✓ VexDay Proof
Wordsmith 1.1b - 'config.inc.php?_path' Remote File Inclusion
PHP remote file inclusion vulnerability in config.inc.php in Wordsmith 1.0 RC1, when register_globals is enabled, allows
35RISCO
abrir ↗Referência✓ VexDay Proof
Ask.com/AskJeeves Toolbar Toolbar 4.0.2.53 - ActiveX Remote Buffer Overflow
Stack-based buffer overflow in the AskJeevesToolBar.SettingsPlugin.1 ActiveX control in askBar.dll in IAC Search & Media
50RISCO
abrir ↗Referência✓ VexDay Proof
NagiosQL 2005 2.00 - 'prepend_adm.php' Remote File Inclusion
PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to ex
23RISCO
abrir ↗Referência✓ VexDay Proof
Chupix CMS 0.2.3 - 'repertoire' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/include/header.php in chupix 0.2.3, when register_globals is enabled, a
23RISCO
abrir ↗Referência✓ VexDay Proof
SyntaxCMS 1.3 - 'FCKeditor' Arbitrary File Upload
Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.
23RISCO
abrir ↗Referência✓ VexDay Proof
actSite 1.56 - 'news.php' Local File Inclusion
Directory traversal vulnerability in phpinc/news.php in actSite 1.56 allows remote attackers to include and execute arbi
23RISCO
abrir ↗Referência✓ VexDay Proof
Phpjobscheduler 3.0 - 'installed_config_file' File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Phpjobscheduler 3.0 allow remote attackers to execute arbitrary PH
23RISCO
abrir ↗Referência✓ VexDay Proof
RsGallery2 < 1.11.2 - 'rsgallery.html.php' File Inclusion
PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for
23RISCO
abrir ↗Referência✓ VexDay Proof
CMS Faethon 2.2 Ultimate - Remote File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php in CMS Faethon 2.2 Ultimate allows remote attackers to inject arb
23RISCO
abrir ↗Referência✓ VexDay Proof
My PHP Indexer 1.0 - 'index.php' Local File Download
Multiple directory traversal vulnerabilities in index.php in My PHP Indexer 1.0 allow remote attackers to read arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
Belkin Wireless G Router / ADSL2 Modem - Authentication Bypass
The web interface to the Belkin Wireless G router and ADSL2 modem F5D7632-4V6 with firmware 6.01.08 allows remote attack
23RISCO
abrir ↗Referência✓ VexDay Proof
RunCMS 1.6 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary we
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.