Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.662GitHub PoC 13.743VulnCheck XDB 8.460Nuclei 4.233Metasploit 3.467✓ só verificadosrecentespopularesrisco
21.662 exploits
Referência✓ VexDay Proof
Bux.to Clone Script - Insecure Cookie Handling
Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the logge
23RISCO
abrir ↗Referência✓ VexDay Proof
MyPicGallery 1.0 - Arbitrary Add Admin
MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting
23RISCO
abrir ↗Referência✓ VexDay Proof
Atomic Photo Album 1.1.0pre4 - Insecure Cookie Handling
Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which proba
23RISCO
abrir ↗Referência✓ VexDay Proof
A+ PHP Scripts - Nms Insecure Cookie Handling
A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator priv
23RISCO
abrir ↗Referência✓ VexDay Proof
SG Real Estate Portal 2.0 - Insecure Cookie Handling
SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the
23RISCO
abrir ↗Referência✓ VexDay Proof
OpenInvoice 0.9 - Arbitrary Change User Password
auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by se
23RISCO
abrir ↗Referência✓ VexDay Proof
Esqlanelapse Software Project 2.6.2 - Insecure Cookie Handling
Esqlanelapse 2.6.1 and 2.6.2 allows remote attackers to bypass authentication and gain privileges via modified (1) enomb
23RISCO
abrir ↗Referência✓ VexDay Proof
MyShoutPro 1.2 - Final Insecure Cookie Handling
MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_acce
23RISCO
abrir ↗Referência✓ VexDay Proof
FretsWeb 1.2 - 'name' Blind SQL Injection
Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir ↗Referência✓ VexDay Proof
Tribiq CMS 5.0.9a (Beta) - Insecure Cookie Handling
Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the CO
23RISCO
abrir ↗Referência✓ VexDay Proof
RPG.Board 0.0.8Beta2 - Insecure Cookie Handling
RPG.Board 0.8 Beta2 and earlier allows remote attackers to bypass authentication and gain privileges by setting the keep
23RISCO
abrir ↗Referência
CVE-2014-5520
SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir ↗Referência
CVE-2022-40797
Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.
48RISCO
abrir ↗Referência
CVE-2014-3871
Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds
23RISCO
abrir ↗Referência
CVE-2020-5147
SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to
23RISCO
abrir ↗Referência
CVE-2012-4998
Cross-site scripting (XSS) vulnerability in index.php in starCMS allows remote attackers to inject arbitrary web script
23RISCO
abrir ↗Referência
CVE-2008-0843
StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a dir
23RISCO
abrir ↗Referência
CVE-2008-0843
StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a dir
23RISCO
abrir ↗Referência
CVE-2010-2512
SQL injection vulnerability in customprofile.php in 2daybiz Matrimonial Script allows remote attackers to execute arbitr
23RISCO
abrir ↗Referência
CVE-2016-3652
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM)
23RISCO
abrir ↗Referência
CVE-2009-4447
Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct requ
23RISCO
abrir ↗Referência
CVE-2016-1000124
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
23RISCO
abrir ↗Referência
CVE-2015-6512
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows
23RISCO
abrir ↗Referência
CVE-2015-6512
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows
23RISCO
abrir ↗Referência
CVE-2011-4674
SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions before 1.8.9, allows rem
23RISCO
abrir ↗Referência
CVE-2019-16531
LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
23RISCO
abrir ↗Referência
CVE-2023-34723
An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information
23RISCO
abrir ↗Referência✓ VexDay Proof
Light Weight Calendar 1.x - 'date' Remote Code Execution
Eval injection vulnerability in cal.php in Light Weight Calendar (LWC) 1.0 allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
Yahoo! Messenger 8.1.0.421 - CYFT Object Arbitrary File Download
Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.
23RISCO
abrir ↗Referência✓ VexDay Proof
ezcms 1.2 - Blind SQL Injection / Authentication Bypass
admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which all
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.