Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.930exploits catalogados
37.572CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 23.973GitHub PoC 15.478VulnCheck XDB 9.069Nuclei 4.426Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.482 exploits
Exploit-DB
PHP Link Directory 4.1.0 - Cross-Site Request Forgery (Add Admin)
Cross-site request forgery (CSRF) vulnerability in admin/conf_users_edit.php in PHP Link Directory (phpLD) 4.1.0 allows
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Java Web Start BasicServiceImpl - Remote Code Execution (Metasploit)
Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server - Service Relative Path Stack Corruption (MS08-067) (Metasploit)
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISCO
abrir ↗Exploit-DB
Look n stop - Local Denial of Service
lnsfw1.sys 6.0.2900.5512 in Look 'n' Stop Firewall 2.06p4 and 2.07 allows local users to cause a denial of service (cras
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Lowbids - 'viewfaqs.php' Blind SQL Injection
SQL injection vulnerability in viewfaqs.php in PHP LOW BIDS allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpCMS 2008 - SQL Injection
SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - CSS SetUserClip Memory Corruption (MS10-090) (Metasploit)
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary cod
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpCMS 2008 - SQL Injection
SQL injection vulnerability in include/admin/model_field.class.php in PHPCMS 2008 V2 allows remote attackers to execute
23RISCO
abrir ↗Exploit-DB
Simploo CMS 1.7.1 - PHP Code Execution
Static code injection vulnerability in Simploo CMS 1.7.1 and earlier allows remote authenticated users to inject arbitra
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell iPrint 5.52 - ActiveX 'GetDriverSettings()' Command Execution
Stack-based buffer overflow in an ActiveX control in ienipp.ocx in Novell iPrint Client 5.52 allows remote attackers to
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
acpid 1.0.x - Multiple Local Denial of Service Vulnerabilities
acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pango Font Parsing - 'pangoft2-render.c' Heap Corruption
Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pan
28RISCO
abrir ↗Exploit-DB
CakePHP 1.3.5/1.2.8 - 'Unserialize()' File Inclusion
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows re
50RISCO
abrir ↗Exploit-DB
N-13 News 3.4 - Cross-Site Request Forgery (Admin Add)
Cross-site request forgery (CSRF) vulnerability in news/admin.php in N-13 News 3.4, 3.7, and 4.0 allows remote attackers
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component allCineVid 1.0.0 - Blind SQL Injection
SQL injection vulnerability in the allCineVid component (com_allcinevid) 1.0.0 for Joomla! allows remote attackers to ex
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Fusion Teams Structure Infusion Addon - SQL Injection
SQL injection vulnerability in team.php in the Teams Structure module 3.0 for PHP-Fusion allows remote attackers to exec
23RISCO
abrir ↗Exploit-DB
Linux Kernel 2.6.32 (Ubuntu 10.04) - '/proc' Handling SUID Privilege Escalation
The proc filesystem implementation in the Linux kernel 2.6.37 and earlier does not restrict access to the /proc director
23RISCO
abrir ↗Exploit-DB
SmoothWall Express 3.0 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Expre
23RISCO
abrir ↗Exploit-DB
SmoothWall Express 3.0 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothw
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpCMS 2008 V2 - 'data.php' SQL Injection
SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AWBS 2.9.2 - 'cart.php' Blind SQL Injection
SQL injection vulnerability in cart.php in Advanced Webhost Billing System (AWBS) 2.9.2 and possibly earlier allows remo
23RISCO
abrir ↗Exploit-DB
BetMore Site Suite 4 - 'bid' Blind SQL Injection
SQL injection vulnerability in mainx_a.php in E-PROMPT C BetMore Site Suite 4.0 through 4.2.0 allows remote attackers to
23RISCO
abrir ↗Exploit-DB
Kingsoft AntiVirus 2011 SP5.2 'KisKrnl.sys' 2011.1.13.89 - Local Kernel Mode Denial of Service
KisKrnl.sys 2011.1.13.89 and earlier in Kingsoft AntiVirus 2011 SP5.2 allows local users to cause a denial of service (c
23RISCO
abrir ↗Exploit-DB
Seo Panel 2.2.0 - Cookie-Rendered Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Seo Panel 2.2.0 allow remote attackers to inject arbitrary web sc
23RISCO
abrir ↗Exploit-DB
Real Networks RealPlayer SP - 'RecordClip' Method Remote Code Execution
The browser-plugin implementation in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1 allows
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CakePHP 1.3.5/1.2.8 - Cache Corruption (Metasploit)
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows re
50RISCO
abrir ↗Exploit-DB
Sielco Sistemi Winlog 2.07.00 - Stack Overflow
Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft WMI Administration Tools - ActiveX Buffer Overflow (Metasploit)
The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Objectivity/DB - Lack of Authentication
The server components in Objectivity/DB 10.0 do not require authentication for administrative commands, which allows rem
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SiteScape Enterprise Forum 7 - TCL Injection
support/dispatch.cgi in SiteScape Forum allows remote attackers to execute arbitrary TCL code via code separator charact
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.