Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.930exploits catalogados
37.572CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 23.973GitHub PoC 15.478VulnCheck XDB 9.069Nuclei 4.426Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.482 exploits
Exploit-DB✓ VexDay Proof
4Site CMS 2.6 - 'cat' SQL Injection
SQL injection vulnerability in catalog/index.shtml in 4site CMS 2.6, and possibly earlier, allows remote attackers to ex
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox SeaMonkey 3.6.10 / Thunderbird 3.1.4 - 'document.write' Memory Corruption
Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
JBoss JMX - Console Deployer Upload and Execute (Metasploit)
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GNU C library dynamic linker - '$ORIGIN' Expansion
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Brooky CubeCart 2.0.1 - SQL Injection
SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GNU C library dynamic linker - '$ORIGIN' Expansion
Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain modified versions of the GNU C Library (aka
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Fat Player 0.6b - '.wav' Local Buffer Overflow (SEH)
Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Piranha Virtual Server Package - 'passwd.php3' Arbitrary Command Execution (Metasploit)
The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password tha
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Piranha Virtual Server Package - 'passwd.php3' Arbitrary Command Execution (Metasploit)
The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execute arbitrary command
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Kisisel Radyo Script - Multiple Vulnerabilities
SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Kisisel Radyo Script - Multiple Vulnerabilities
Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - NTLM Weak Nonce (MS10-012)
The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft ASP.NET - Padding Oracle File Download (MS10-070)
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Intern
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office - 'HtmlDlgHelper' Class Memory Corruption (MS10-071)
mshtmled.dll in Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code via a crafted Micr
28RISCO
abrir ↗Exploit-DB
IBM solidDB 6.5.0.3 - Denial of Service
solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon recei
23RISCO
abrir ↗Exploit-DB
IBM solidDB 6.5.0.3 - Denial of Service
solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon recei
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DATAC RealWin SCADA Server 2.0 (Build 6.1.8.10) - Buffer Overflow
Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a
50RISCO
abrir ↗Exploit-DB
IBM solidDB 6.5.0.3 - Denial of Service
Stack consumption vulnerability in solid.exe in IBM solidDB 6.5.0.3 and earlier allows remote attackers to cause a denia
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TWiki 5.0 - '/bin/view?rev' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inje
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TWiki 5.0 - bin/login Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inje
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Jstore - 'Controller' Local File Inclusion
Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Winamp 5.5.8.2985 - Multiple Buffer Overflows
Buffer overflow in the in_mod plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vect
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Java 6 - OBJECT tag 'launchjnlp'/'docbase' Remote Buffer Overflow
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows r
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.5.10/3.6.6 - 'WMP' Memory Corruption Using Popups
Microsoft Windows Media Player (WMP) 9 through 12 does not properly deallocate objects during a browser reload action, w
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Solaris - 'su' Crash
Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect confidentiality and integrit
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Collabtive 0.65 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Collabtive 0.6.5 allow remote attackers to inject arbitrary web s
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AdaptCMS 2.0.1 Beta - Remote File Inclusion (Metasploit)
PHP remote file inclusion vulnerability in inc/smarty/libs/init.php in AdaptCMS 2.0.0 Beta, when register_globals is ena
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Collabtive 0.65 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Fusion Middleware 10.1.2/10.1.3 - BPEL Console Cross-Site Scripting
Unspecified vulnerability in the BPEL Console component in Oracle Fusion Middleware 11.1.1.1.0 and 11.1.1.2.0 allows rem
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager (OV NNM) 7.53/7.51 - 'OVAS.exe' Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51, and earlier allows
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.