Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.797GitHub PoC 13.885VulnCheck XDB 8.484Nuclei 4.237Metasploit 3.467✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB✓ VexDay Proof
Ruby on Rails 3.0.5 - 'WEBrick::HTTPRequest' Module HTTP Header Injection
The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Lingxia I.C.E CMS - Blind SQL Injection
SQL injection vulnerability in api/ice_media.cfc in Lingxia I.C.E CMS 1.0 allows remote attackers to execute arbitrary S
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2003 - AD BROWSER ELECTION Remote Heap Overflow
Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TaskFreak! 0.6.4 - 'rss.php' HTTP Referer Header Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in include/html/header.php in TaskFreak! 0.6.4 allow remote attacker
23RISCO
abrir ↗Exploit-DB
TaskFreak! 0.6.4 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in include/html/header.php in TaskFreak! 0.6.4 allow remote attacker
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TaskFreak! 0.6.4 - 'print_list.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in include/html/header.php in TaskFreak! 0.6.4 allow remote attacker
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TaskFreak! 0.6.4 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in include/html/header.php in TaskFreak! 0.6.4 allow remote attacker
23RISCO
abrir ↗Exploit-DB
PixelPost 1.7.3 - Multiple POST SQL Injections
Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Horde - Horde_Image::factory driver Argument Local File Inclusion
Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware befor
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ManageEngine ADSelfService Plus 4.4 - POST Manipulation Security Question
accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Bui
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ManageEngine ADSelfService Plus 4.4 - 'EmployeeSearch.cc' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in the Employee Search Engine in ZOHO ManageEng
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MihanTools Script 1.3.3 - SQL Injection
SQL injection vulnerability in product.php in MihanTools 1.33 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Exploit-DB
Multiple Vendor Calendar Manager - Remote Code Execution
Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, a
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 1.1.6 - 'MKV' Memory Corruption (Metasploit)
demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - CreateSizedDIBSECTION Stack Buffer Overflow (MS11-006) (Metasploit)
Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - CSS Recursive Import Use-After-Free (MS11-003) (Metasploit)
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in msh
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server - sp_replwritetovarbin Memory Corruption (MS09-004) (via SQL Injection) (Metasploit)
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server - Payload Execution (via SQL Injection) (Metasploit)
The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in pla
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server - Payload Execution (via SQL Injection) (Metasploit)
The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3)
60RISCO
abrir ↗Exploit-DB
ProFTPd - 'mod_sftp' Integer Overflow Denial of Service (PoC)
Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a deni
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Comcast DOCSIS 3.0 Business Gateways - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the SMC SMCD3G-CCR (aka Comcast Busin
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Comcast DOCSIS 3.0 Business Gateways - Multiple Vulnerabilities
The web management portal on the SMC SMCD3G-CCR (aka Comcast Business Gateway) with firmware before 1.4.0.49.2 uses pred
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Comcast DOCSIS 3.0 Business Gateways - Multiple Vulnerabilities
A certain Comcast Business Gateway configuration of the SMC SMCD3G-CCR with firmware before 1.4.0.49.2 has a default pas
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Majordomo2 - 'SMTP/HTTP' Directory Traversal
The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct d
60RISCO
abrir ↗Exploit-DB
VideoLAN VLC Media Player 1.1 - Subtitle 'StripTags()' Memory Corruption
The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text decoder (modules/code
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark 1.4.3 - '.pcap' Memory Corruption
Wireshark 1.2.0 through 1.2.14, 1.4.0 through 1.4.3, and 1.5.0 frees an uninitialized pointer during processing of a .pc
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Majordomo2 - 'SMTP/HTTP' Directory Traversal
Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allo
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 0.9.4 - TiVo Buffer Overflow (Metasploit)
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Tandberg E & EX & C Series Endpoints - Default Root Account Credentials
The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with softwar
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RedaxScript 0.3.2 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in includes/password.php in Redaxscript 0.3.2 allow remote attackers to execute a
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.