Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8.970Nuclei 4.394Metasploit 3.502✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
Simple Customer 1.3 - Arbitrary Change Admin Password
profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to chan
23RISCO
abrir ↗Referência✓ VexDay Proof
jetAudio 7.x - '.m3u' Local Overwrite (SEH)
Stack-based buffer overflow in COWON America jetAudio Basic 7.0.3 allows user-assisted remote attackers to execute arbit
23RISCO
abrir ↗Referência✓ VexDay Proof
MyBloggie 2.1.6 - Multiple SQL Injections
Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to per
23RISCO
abrir ↗Referência✓ VexDay Proof
cf shopkart 5.2.2 - SQL Injection / File Disclosure
CF Shopkart 5.2.2 stores cfshopkart52.mdb under the web root with insufficient access control, which allows remote attac
23RISCO
abrir ↗Referência✓ VexDay Proof
U&M Software JustBookIt 1.0 - Authentication Bypass
U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, whic
23RISCO
abrir ↗Referência✓ VexDay Proof
Advanced Guestbook 2.4.0 - 'phpBB' File Inclusion
PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when regist
23RISCO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Lykos Reviews 1.00 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in the Lykos Reviews (lykos_reviews) 1.00 module for Xoops allows remote attack
23RISCO
abrir ↗Referência✓ VexDay Proof
Zomplog 3.8 - 'mp3playlist.php' SQL Injection
SQL injection vulnerability in plugins/mp3playlist/mp3playlist.php in Zomplog 3.8 and earlier allows remote attackers to
23RISCO
abrir ↗Referência✓ VexDay Proof
LimeSurvey 1.52 - 'language.php' Remote File Inclusion
PHP remote file inclusion vulnerability in classes/core/language.php in LimeSurvey 1.5.2 and earlier allows remote attac
23RISCO
abrir ↗Referência✓ VexDay Proof
4Images 1.7.7 - Filter Bypass HTML Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
TOWeLS 0.1 - 'scripture.php' Remote File Inclusion
PHP remote file inclusion vulnerability in src/scripture.php in The Online Web Library Site (TOWels) 0.1 allows remote a
28RISCO
abrir ↗Referência✓ VexDay Proof
CcMail 1.0.1 - Insecure Cookie Handling
Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session
23RISCO
abrir ↗Referência✓ VexDay Proof
Download Accelerator Plus DAP 8.x - '.m3u' File Buffer Overflow
Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allow
23RISCO
abrir ↗Referência✓ VexDay Proof
CCLeague Pro 1.2 - Insecure Cookie Authentication
admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin
23RISCO
abrir ↗Referência✓ VexDay Proof
P2P Foxy - Out of Memory Denial of Service
Foxy P2P software allows remote attackers to cause a denial of service (memory consumption) via a foxy URI with a downlo
23RISCO
abrir ↗Referência✓ VexDay Proof
Dokeos 1.6.5 - 'courseLog.php?scormcontopen' SQL Injection
SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arb
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Pony Gallery 1.5 - SQL Injection
SQL injection vulnerability in index.php in the Pony Gallery (com_ponygallery) 1.5 and earlier component for Joomla! all
23RISCO
abrir ↗Referência✓ VexDay Proof
xGB 2.0 - 'xGB.php' Remote Security Bypass
xGB.php in xGB 2.0 does not require authentication for an admin edit action, which allows remote attackers to make unspe
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPizabi 0.848b C1 HFP3 - Database Information Disclosure
The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings del
23RISCO
abrir ↗Referência✓ VexDay Proof
DreamNews Manager - 'id' SQL Injection
SQL injection vulnerability in dreamnews-rss.php in DreamNews Manager allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Referência✓ VexDay Proof
sma-db 0.3.12 - Remote File Inclusion / Cross-Site Scripting
PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP
23RISCO
abrir ↗Referência✓ VexDay Proof
MFORUM 0.1a - Arbitrary Add Admin
Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote att
23RISCO
abrir ↗Referência✓ VexDay Proof
AyeView 2.20 - '.GIF' Image Local Crash
AyeView 2.20 allows user-assisted attackers to cause a denial of service (application crash) via a GIF file with a malfo
23RISCO
abrir ↗Referência✓ VexDay Proof
MyBlog: PHP and MySQL Blog/CMS software - SQL Injection / Cross-Site Scripting
Sam Crew MyBlog stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain se
23RISCO
abrir ↗Referência✓ VexDay Proof
Bitweaver 2.6 - 'saveFeed()' Remote Code Execution
Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 an
23RISCO
abrir ↗Referência✓ VexDay Proof
MKPortal 1.1.1 reviews / Gallery modules - SQL Injection
Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1
23RISCO
abrir ↗Referência✓ VexDay Proof
Online Grades & Attendance 3.2.6 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in Online Grades & Attendance 3.2.5 and earlier, and possibly 3.2.6, when r
23RISCO
abrir ↗Referência✓ VexDay Proof
Vanilla 1.1.3 - Blind SQL Injection
Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortrol
23RISCO
abrir ↗Referência✓ VexDay Proof
Scribe 0.2 - 'index.php' Local File Inclusion
Directory traversal vulnerability in index.php in Scribe 0.2 allows remote attackers to read arbitrary local files via a
23RISCO
abrir ↗Referência✓ VexDay Proof
Alstrasoft AskMe Pro 2.1 - Multiple SQL Injections
AlstraSoft AskMe Pro 2.1 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent a
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.