Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.902exploits catalogados
34.597CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.624GitHub PoC 13.727VulnCheck XDB 8.410Nuclei 4.231Metasploit 3.467✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB✓ VexDay Proof
Elite Bulletin Board 2.1.21 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in the (1) update_whosonline_reg and (2) update_whosonline_guest functions in Eli
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
banana dance b.2.6 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Banana Dance B.2.6 and earlier allow remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
banana dance b.2.6 - Multiple Vulnerabilities
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
banana dance b.2.6 - Multiple Vulnerabilities
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information v
23RISCO
abrir ↗Exploit-DB
FireFly Mediaserver 1.0.0.1359 - Null Pointer Dereference
Firefly Media Server 1.0.0.1359 allows remote attackers to cause a denial of service (NULL pointer dereference) via a (1
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
InduSoft Web Studio - 'ISSymbol.ocx InternationalSeparator()' Heap Overflow (Metasploit)
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol v
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Crystal Reports CrystalPrintControl - ActiveX ServerResourceVersion Property Overflow (Metasploit)
Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHPWCMS 1.5.4.6 - 'preg_replace' Multiple Vulnerabilities
IRIS citations management tool through 1.3 allows remote attackers to execute arbitrary commands.
23RISCO
abrir ↗Exploit-DB
Cisco Wireless Lan Controller 7.2.110.0 - Multiple Vulnerabilities
screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Portable phpMyAdmin - Authentication Bypass
The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain ph
28RISCO
abrir ↗Exploit-DB
Centreon Enterprise Server 2.3.3 < 2.3.9-4 - Blind SQL Injection
SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote
23RISCO
abrir ↗Exploit-DB
Cisco Wireless Lan Controller 7.2.110.0 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software
23RISCO
abrir ↗Exploit-DB
Cisco Wireless Lan Controller 7.2.110.0 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) dev
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 3.3.5 - Btrfs CRC32C feature Infinite Loop Local Denial of Service
The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc1 allows local users to cause a denial o
23RISCO
abrir ↗Exploit-DB
Axway Secure Transport 5.1 SP2 - Directory Traversal
Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated use
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell File Reporter (NFR) Agent - XML Parsing Remote Code Execution
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and ex
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell File Reporter (NFR) Agent - XML Parsing Remote Code Execution
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrar
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell File Reporter (NFR) Agent - XML Parsing Remote Code Execution
Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbi
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector - DtbClsLogin Buffer Overflow (Metasploit)
Unspecified vulnerability in HP Data Protector Express, and Data Protector Express Single Server Edition (SSE), 3.x befo
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Smartphone Pentest Framework - Multiple Remote Command Execution Vulnerabilities
Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary comman
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SimpleInvoices invoices Module - Customer Field Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in SimpleInvoices before stable-2012-1-CIS3000 allow remote attacker
23RISCO
abrir ↗Exploit-DB
TVMOBiLi 2.1.0.3557 - Denial of Service
Multiple stack-based buffer overflows in HttpUtils.dll in TVMOBiLi before 2.1.0.3974 allow remote attackers to cause a d
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google Android Kernel 2.6 - Local Denial of Service Crash (PoC)
Buffer overflow in the VFAT filesystem implementation in the Linux kernel before 3.3 allows local users to gain privileg
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Achievo 1.4.5 - Multiple Vulnerabilities (2)
SQL injection vulnerability in dispatch.php in Achievo 1.4.5 allows remote authenticated users to execute arbitrary SQL
23RISCO
abrir ↗Exploit-DB
Clipbucket 2.6 Revision 738 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in ClipBucket 2.6 Revision 738 and earlier allow remote attackers to execute arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SumatraPDF 2.1.1/MuPDF 1.0 - Integer Overflow
SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corru
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM System Director Agent - DLL Injection (Metasploit)
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows rem
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 2.0.4 - '.swf' Crash (PoC)
Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow remote attackers to cause a denial of ser
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Simple Gmail Login - Stack Trace Information Disclosure
simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sen
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle MySQL / MariaDB - Insecure Salt Generation Security Bypass
Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt duri
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.