Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.324exploits catalogados
37.130CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.614GitHub PoC 15.330VulnCheck XDB 9.001Nuclei 4.401Metasploit 3.502✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
DomPHP 0.82 - 'index.php' Local File Inclusion
Directory traversal vulnerability in aides/index.php in DomPHP 0.82 allows remote attackers to include and execute arbit
23RISCO
abrir ↗Referência✓ VexDay Proof
ImageStation - 'SonyISUpload.cab 1.0.0.38' ActiveX Buffer Overflow (PoC)
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyIS
28RISCO
abrir ↗Referência✓ VexDay Proof
Mambo Component Ricette 1.0 - SQL Injection
SQL injection vulnerability in index.php in the Giorgio Nordo Ricette (com_ricette) 1.0 component for Joomla! and Mambo
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_clasifier - 'cat_id' SQL Injection
SQL injection vulnerability in index.php in the Classifier (com_clasifier) component for Joomla! allows remote attackers
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_pccookbook - 'user_id' SQL Injection
SQL injection vulnerability in index.php in the PccookBook (com_pccookbook) component for Joomla! allows remote attacker
23RISCO
abrir ↗Referência✓ VexDay Proof
XOOPS Module myTopics - 'articleId' SQL Injection
SQL injection vulnerability in print.php in the myTopics module for XOOPS allows remote attackers to execute arbitrary S
23RISCO
abrir ↗Referência✓ VexDay Proof
Now SMS/Mms Gateway 5.5 - Remote Buffer Overflow
Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute ar
50RISCO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Classifieds - 'cid' SQL Injection
SQL injection vulnerability in index.php in the jlmZone Classifieds module for XOOPS allows remote attackers to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
RunCMS Module MyAnnonces - 'cid' SQL Injection
SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to
23RISCO
abrir ↗Referência✓ VexDay Proof
Creative Software AutoUpdate Engine - ActiveX Stack Overflow
Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote atta
50RISCO
abrir ↗Referência✓ VexDay Proof
SNMPv3 - HMAC Validation error Remote Authentication Bypass
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-S
35RISCO
abrir ↗Referência✓ VexDay Proof
Sun Solaris 10 - snoop(1M) Utility Remote Command Execution
Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o op
28RISCO
abrir ↗Referência✓ VexDay Proof
PORAR WebBoard - 'question.asp' SQL Injection
SQL injection vulnerability in question.asp in PORAR WEBBOARD allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP Download Manager 1.1 - Local File Inclusion
Directory traversal vulnerability in include/body.inc.php in Linux Web Shop (LWS) php Download Manager 1.0 and 1.1 allow
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPUserBase 1.3b - 'unverified.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in templates/default/header.inc.php in Linux Web Shop (LWS) php User Base 1.3 BE
35RISCO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke Module Kose_Yazilari - 'artid' SQL Injection
Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
Motorola Timbuktu Pro 8.6.5 - File Deletion/Creation
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu P
50RISCO
abrir ↗Referência✓ VexDay Proof
Motorola Timbuktu Pro 8.6.5/8.7 - Directory Traversal / Log Injection
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu P
50RISCO
abrir ↗Referência✓ VexDay Proof
Podcast Generator 1.0 Beta 2 - Remote File Inclusion / File Disclosure
Multiple PHP remote file inclusion vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to
28RISCO
abrir ↗Referência✓ VexDay Proof
Podcast Generator 1.0 Beta 2 - Remote File Inclusion / File Disclosure
Multiple directory traversal vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to read
23RISCO
abrir ↗Referência✓ VexDay Proof
Home FTP Server 1.4.5 - Remote Denial of Service
Home FTP Server 1.4.5.89 allows remote attackers to cause a denial of service (crash) by opening a FTP passive mode conn
23RISCO
abrir ↗Referência✓ VexDay Proof
SunOS 5.10 Sun Cluster - 'rpc.metad' Denial of Service (PoC)
rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC requ
23RISCO
abrir ↗Referência✓ VexDay Proof
PunBB 1.2.16 - Blind Password Recovery
The password reset feature in PunBB 1.2.16 and earlier uses predictable random numbers based on the system time, which a
23RISCO
abrir ↗Referência✓ VexDay Proof
NetWin Surgemail 3.8k4-4 - IMAP (Authenticated) Remote LIST Universal
Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated user
23RISCO
abrir ↗Referência✓ VexDay Proof
ASUS DPC Proxy 2.0.0.16/19 - Remote Buffer Overflow
Stack-based buffer overflow in the DPC Proxy server (DpcProxy.exe) in ASUS Remote Console (aka ARC or ASMB3) 2.0.0.19 an
60RISCO
abrir ↗Referência✓ VexDay Proof
PEEL CMS 3.x - Admin Hash Extraction / Arbitrary File Upload
Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote auth
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component custompages 1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joo
35RISCO
abrir ↗Referência✓ VexDay Proof
Danneo CMS 0.5.1 - Blind SQL Injection
SQL injection vulnerability in index.php in Danneo CMS 0.5.1 and earlier, when the Referers statistics option is enabled
23RISCO
abrir ↗Referência✓ VexDay Proof
RunCMS Module Photo 3.02 - 'cid' SQL Injection
SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
BolinOS 4.6.1 - Local File Inclusion / Cross-Site Scripting
BolinOS 4.6.1 allows remote attackers to obtain sensitive information via a direct request to system/actionspages/_b/con
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.