Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.842exploits catalogados
37.493CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 23.901GitHub PoC 15.465VulnCheck XDB 9.066Nuclei 4.426Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.482 exploits
Exploit-DB✓ VexDay Proof
Support Incident Tracker 3.65 - Remote Command Execution (Metasploit)
Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote
43RISCO
abrir ↗Exploit-DB
Mambo 4.x - 'Zorder' SQL Injection
SQL injection vulnerability in administrator/index2.php in Mambo CMS 4.6.5 and earlier allows remote attackers to execut
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Support Incident Tracker 3.65 - Remote Command Execution (Metasploit)
ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive in
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
glibc - 'LD_AUDIT' Arbitrary DSO Load Privilege Escalation
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
osCSS2 - '_ID' Local file Inclusion
Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arb
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AbsoluteFTP 1.9.6 < 2.2.10 - 'LIST' Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute ar
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenPAM - 'pam_start()' Local Privilege Escalation
Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to loa
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
labwiki 1.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in LabWiki 1.1 and earlier allow remote attackers to inject arbitrar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
labwiki 1.1 - Multiple Vulnerabilities
edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated user
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - TCP/IP Stack Reference Counter Integer Overflow (MS11-083)
Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, a
60RISCO
abrir ↗Exploit-DB
KnFTP 1.0 - Remote Buffer Overflow (DEP Bypass) (Metasploit)
Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Hyperion Strategic Finance 12.x - Tidestone Formula One WorkBook OLE Control TTF16.ocx Remote Heap Overflow
Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Buil
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OrderSys 1.6.4 - SQL Injection
Multiple SQL injection vulnerabilities in OrderSys 1.6.4 and earlier allow remote attackers to execute arbitrary SQL com
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WHMCompleteSolution 3.x/4.x - Multiple Vulnerabilities
Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read a
23RISCO
abrir ↗Exploit-DB
Oracle - xdb.xdb_pitrig_pkg.PITRIG_DROPMETADATA procedure
Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remote authenticated use
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
aidiCMS 3.55 - 'ajax_create_folder.php' Remote Code Execution
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHPMyFAQ 2.7.0 - 'ajax_create_folder.php' Remote Code Execution
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Excel 2007 - '.xlb' Local Buffer Overflow (MS11-021) (Metasploit)
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain leng
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ZenPhoto 1.4.1.4 - 'ajax_create_folder.php' Remote Code Execution
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Centreon 2.3.1 - 'command_name' Remote Command Execution
Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to exe
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ajax File and Image Manager 1.0 Final - Remote Code Execution
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Libc - 'regcomp()' Stack Exhaustion Denial of Service
regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.
23RISCO
abrir ↗Exploit-DB
WHMCompleteSolution (WHMCS) 3.x - 'clientarea.php' Local File Disclosure
Directory traversal vulnerability in clientarea.php in WHMCompleteSolution (WHMCS) 3.x.x allows remote attackers to read
23RISCO
abrir ↗Exploit-DB
DreamBox DM800 1.5rc1 - File Disclosure
Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DreamBox DM800 - 'file' Local File Disclosure
Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mini-stream Ripper 3.0.1.1 - Local Buffer Overflow (Metasploit) (3)
Stack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long e
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google Android 2.3.5 - PowerVR SGX Driver Information Disclosure
The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive information from kernel
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
S9Y Serendipity 1.5.5 - 'serendipity[filter][bp.ALT]' Cross-Site Scripting
Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Web File Browser 0.4b14 - File Download
Directory traversal vulnerability in webFileBrowser.php in Web File Browser 0.4b14 allows remote authenticated users to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jara 1.6 - Multiple Vulnerabilities
Jara 1.6 has an XSS vulnerability
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.