Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.324exploits catalogados
37.130CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.614GitHub PoC 15.330VulnCheck XDB 9.001Nuclei 4.401Metasploit 3.502✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
QuickUpCMS - Multiple SQL Injections Vulnerabilities
Multiple SQL injection vulnerabilities in Concepts & Solutions QuickUpCMS allow remote attackers to execute arbitrary SQ
23RISCO
abrir ↗Referência✓ VexDay Proof
Power Phlogger 2.2.5 - 'css_str' SQL Injection
SQL injection vulnerability in edCss.php in PowerPhlogger 2.2.5 and earlier allows remote authenticated users to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP-Address Book 3.1.5 - SQL Injection / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inje
23RISCO
abrir ↗Referência✓ VexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Stack Overflow (PoC)
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RISCO
abrir ↗Referência✓ VexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Overflow (SEH)
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component SimpleShop 3.4 - SQL Injection
SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component 3.4 and earlier for Joomla! allows remo
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component JooBlog 0.1.1 - Blind SQL Injection
SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbi
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Bible Study 1.5.0 - 'id' SQL Injection
SQL injection vulnerability in the Bible Study (com_biblestudy) component before 6.0.7c for Joomla! allows remote attack
23RISCO
abrir ↗Referência✓ VexDay Proof
mebiblio 0.4.7 - SQL Injection / Arbitrary File Upload / Cross-Site Scripting
SQL injection vulnerability in admin/journal_change_mask.inc.php in meBiblio 0.4.7 allows remote attackers to execute ar
23RISCO
abrir ↗Referência✓ VexDay Proof
CMSimple 3.1 - Local File Inclusion / Arbitrary File Upload
Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote a
43RISCO
abrir ↗Referência✓ VexDay Proof
Roundcube Webmail 0.2b - Remote Code Execution
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail)
35RISCO
abrir ↗Referência✓ VexDay Proof
phpMyAdmin 3.1.0 - Cross-Site Request Forgery / SQL Injection
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remot
23RISCO
abrir ↗Referência✓ VexDay Proof
CzarNews 1.14 - 'tpath' Remote File Inclusion
PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the
28RISCO
abrir ↗Referência✓ VexDay Proof
Achievo 1.3.2 - 'FCKeditor' Arbitrary File Upload
Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/co
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP-Fusion Mod TI - 'id' SQL Injection
SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to
23RISCO
abrir ↗Referência✓ VexDay Proof
JiRo's FAQ Manager eXperience 1.0 - 'fID' SQL Injection
SQL injection vulnerability in read.asp in JiRo's FAQ Manager eXperience 1.0 allows remote attackers to execute arbitrar
23RISCO
abrir ↗Referência✓ VexDay Proof
Black Ice Software Annotation Plugin - 'BiAnno.ocx' Remote Buffer Overflow (2)
Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows
28RISCO
abrir ↗Referência✓ VexDay Proof
Black Ice Software Inc Barcode SDK - 'BITiff.ocx' Remote Buffer Overflow (1)
Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5
28RISCO
abrir ↗Referência✓ VexDay Proof
Black Ice Software Inc Barcode SDK - 'BITiff.ocx' Remote Buffer Overflow (2)
Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5
28RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Rapid Recipe 1.6.6/1.6.7 - SQL Injection
SQL injection vulnerability in the Rapid Recipe (com_rapidrecipe) component 1.6.6 and 1.6.7 for Joomla! allows remote at
23RISCO
abrir ↗Referência✓ VexDay Proof
CoolPlayer 2.19 - '.Skin' Local Buffer Overflow
Stack-based buffer overflow in skin.c in CoolPlayer 2.17 through 2.19 allows remote attackers to execute arbitrary code
23RISCO
abrir ↗Referência✓ VexDay Proof
CoolPlayer 2.19 - '.Skin' Local Buffer Overflow
Stack-based buffer overflow in skin.c in CoolPlayer 2.17 through 2.19 allows remote attackers to execute arbitrary code
23RISCO
abrir ↗Referência✓ VexDay Proof
Nitro Web Gallery 1.4.3 - 'section' SQL Injection
SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbi
23RISCO
abrir ↗Referência✓ VexDay Proof
Mybizz-Classifieds - 'cat' SQL Injection
SQL injection vulnerability in index.php in MyBizz-Classifieds allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
CaupoShop Classic 1.3 - 'saArticle[ID]' SQL Injection
SQL injection vulnerability in csc_article_details.php in Caupo.net CaupoShop Classic 1.3 allows remote attackers to exe
23RISCO
abrir ↗Referência✓ VexDay Proof
E-topbiz ViralDX 2.07 - 'bannerid' SQL Injection
SQL injection vulnerability in adclick.php in E-topbiz Viral DX 1 2.07 allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
DUcalendar 1.0 - 'iEve' SQL Injection
SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execu
23RISCO
abrir ↗Referência✓ VexDay Proof
Link ADS 1 - 'linkid' SQL Injection
SQL injection vulnerability in out.php in E-topbiz Link ADS 1 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
Efestech Shop 2.0 - 'cat_id' SQL Injection
SQL injection vulnerability in default.asp in EfesTECH Shop 2.0 allows remote attackers to execute arbitrary SQL command
23RISCO
abrir ↗Referência✓ VexDay Proof
XchangeBoard 1.70 - 'boardID' SQL Injection
SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.