Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8.970Nuclei 4.394Metasploit 3.502✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
CSPartner 1.0 - Delete All Users / SQL Injection
SQL injection vulnerability in gestion.php in CSPartner 0.1, when magic_quotes_gpc is disabled, allows remote attackers
23RISCO
abrir ↗Referência✓ VexDay Proof
JASmine 0.0.2 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Nayco JASmine (aka Jasmine-Web) allows remote attackers to execu
23RISCO
abrir ↗Referência✓ VexDay Proof
Ultrastats 0.2.144/0.3.11 - 'serverid' SQL Injection
SQL injection vulnerability in index.php in Ultrastats 0.2.144 and 0.3.11 allows remote attackers to execute arbitrary S
23RISCO
abrir ↗Referência✓ VexDay Proof
Apoll 0.7b - Authentication Bypass
SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execu
23RISCO
abrir ↗Referência✓ VexDay Proof
YaBBSM 3.0.0 - 'Offline.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in SuperMod 3.0.0 for YABB (YaBBSM) allow remote attackers to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
Apoll 0.7b - Authentication Bypass
SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execu
23RISCO
abrir ↗Referência✓ VexDay Proof
e107 - 'include()' Remote File Upload
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to
28RISCO
abrir ↗Referência✓ VexDay Proof
Brim 1.2.1 - 'renderer' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Barry Nauta BRIM 1.2.1 and earlier allow remote attackers to execu
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPPowerCards 2.10 - 'txt.inc.php' Remote Code Execution
Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is
23RISCO
abrir ↗Referência✓ VexDay Proof
Winamp 5.12 - '.pls' Remote Buffer Overflow (Perl) (2)
Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with
60RISCO
abrir ↗Referência✓ VexDay Proof
flinx 1.3 - 'id' SQL Injection
SQL injection vulnerability in category.php in Flinx 1.3 and earlier allows remote attackers to execute arbitrary SQL co
23RISCO
abrir ↗Referência✓ VexDay Proof
Move Networks Upgrade Manager Control - Remote Buffer Overflow
Stack-based buffer overflow in the QMPUpgrade.Upgrade.1 ActiveX control in QMPUpgrade.dll 1.0.0.1 in Move Networks Upgra
28RISCO
abrir ↗Referência✓ VexDay Proof
Web Wiz Forums 9.07 - 'sub' Directory Traversal
Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows Server 2000 - UPNP 'getdevicelist' Memory Leak Denial of Service
PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 a
35RISCO
abrir ↗Referência✓ VexDay Proof
Top Auction 1.0 - 'viewcat.php' SQL Injection
SQL injection vulnerability in PHP Labs Top Auction allows remote attackers to execute arbitrary SQL commands via the (1
23RISCO
abrir ↗Referência✓ VexDay Proof
MyBulletinBoard (MyBB) 1.03 - 'misc.php' SQL Injection
SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote
23RISCO
abrir ↗Referência✓ VexDay Proof
Mambo Component 'com_newsletter' 4.5 - 'listid' SQL Injection
SQL injection vulnerability in index.php in the Newsletter (com_newsletter) component for Mambo 4.5 and Joomla! allows r
23RISCO
abrir ↗Referência✓ VexDay Proof
Mambo Component 'com_mamml' - 'listid' SQL Injection
SQL injection vulnerability in index.php in the MaMML (com_mamml) component for Mambo and Joomla! allows remote attacker
23RISCO
abrir ↗Referência✓ VexDay Proof
Cisco IP Phone 7940 - Reboot (Denial of Service)
The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN pack
28RISCO
abrir ↗Referência✓ VexDay Proof
Photo Cart 3.9 - 'adminprint.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in adminprint.php in PicturesPro Photo Cart 3.9 allow remote attacker
23RISCO
abrir ↗Referência✓ VexDay Proof
BXCP 0.2.9.9 - 'tid' SQL Injection
SQL injection vulnerability in index.php in BXCP 0.299 allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir ↗Referência✓ VexDay Proof
Wikepage Opus 10 < 2006.2a (lng) - Remote Command Execution
Directory traversal vulnerability in index.php for Wikepage 2006.2a Opus 10 allows remote attackers to include arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
JiRos FAQ Manager 1.0 - 'index.asp' SQL Injection
SQL injection vulnerability in index.asp in JiRos FAQ Manager 1.0 allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir ↗Referência✓ VexDay Proof
Sejoong Namo ActiveSquare 6 - 'NamoInstaller.dll' install Method
The NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1 and earlier in Namo Web Editor in Sejoong N
28RISCO
abrir ↗Referência✓ VexDay Proof
Mambo Component 'com_akogallery' 2.5b - SQL Injection
SQL injection vulnerability in index.php in the Arthur Konze AkoGallery (com_akogallery) 2.5 beta component for Mambo an
23RISCO
abrir ↗Referência✓ VexDay Proof
Mambo Component Restaurant 1.0 - SQL Injection
SQL injection vulnerability in index.php in the Restaurant (com_restaurant) 1.0 component for Mambo and Joomla! allows r
23RISCO
abrir ↗Referência✓ VexDay Proof
TIBCO Rendezvous 7.4.11 - Password Extractor
TIBCO RendezVous 7.4.11 and earlier logs base64-encoded usernames and passwords in rvrd.db, which allows local users to
23RISCO
abrir ↗Referência✓ VexDay Proof
CilemNews System 1.1 - 'yazdir.asp' haber_id SQL Injection
SQL injection vulnerability in yazdir.asp in Cilem Hiber 1.1 allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir ↗Referência✓ VexDay Proof
The Classified Ad System 1.0 - 'main' SQL Injection
Multiple SQL injection vulnerabilities in PWP Technologies The Classified Ad System allow remote attackers to execute ar
23RISCO
abrir ↗Referência✓ VexDay Proof
Aztek Forum 4.00 - Cross-Site Scripting / SQL Injection
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a "*/*" in the msg parameter to index.php, w
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.