Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.797GitHub PoC 13.885VulnCheck XDB 8.484Nuclei 4.237Metasploit 3.467✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB✓ VexDay Proof
Joomla! Component JS Calendar 1.5.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the JoomlaSeller JS Calendar (com_jscalendar) component 1.5.1 and
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
hplip - 'hpssd.py' From Address Arbitrary Command Execution (Metasploit)
hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent a
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Community Builder Enhanced (CBE) 1.4.8/1.4.9/1.4.10 - Local File Inclusion / Remote Code Execution
Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 f
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX EvoCam Web Server - GET Buffer Overflow (Metasploit)
Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary cod
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
UFO: Alien Invasion IRC Client (OSX) - Remote Buffer Overflow (Metasploit)
Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary cod
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
xWeblog 2.2 - 'arsiv.asp?tarih' SQL Injection
SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Flex Timesheet - Authentication Bypass
Multiple SQL injection vulnerabilities in the log-in form in Truworth Flex Timesheet allow remote attackers to execute a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OPEN IT OverLook 5 - 'title.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in title.php in OPEN IT OverLook 5.0 allows remote attackers to inject arbitrar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
xWeblog 2.2 - 'oku.asp?makale_id' SQL Injection
SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir ↗Exploit-DB
libc/glob(3) - Resource Exhaustion / Remote ftpd-anonymous (Denial of Service)
Unspecified vulnerability in the FTP Server in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Club Manager - 'cm_id' SQL Injection
SQL injection vulnerability in the Club Manager (com_clubmanager) component for Joomla! allows remote attackers to execu
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat and Reader - Array Indexing Remote Code Execution
Array index error in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Mac OS X allows attackers to execut
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX LPD - Command Execution (Metasploit)
Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of ser
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft ASP.NET - Padding Oracle (MS10-070)
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Intern
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NetTerm NetFTPD - 'USER' Remote Buffer Overflow (Metasploit)
Buffer overflow in NetFtpd for NetTerm 5.1.1 and earlier allows remote attackers to execute arbitrary code via a long US
50RISCO
abrir ↗Exploit-DB
Cag CMS 0.2 - Cross-Site Scripting / Blind SQL Injection
SQL injection vulnerability in click.php in CAG CMS 0.2 Beta allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SlimFTPd - 'LIST' Concatenation Overflow (Metasploit)
Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directo
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ipswitch WS_FTP Server 5.03 - MKD Overflow (Metasploit)
Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Workstation Service - NetpManageIPCConnect Overflow (MS06-070) (Metasploit)
Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Wi
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 9i XDB (Windows x86) - FTP UNLOCK Overflow (Metasploit)
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Alcatel-Lucent OmniPCX Enterprise - masterCGI Arbitrary Command Execution (Metasploit)
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows rem
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft DirectX DirectShow - SAMI Buffer Overflow (MS07-064) (Metasploit)
Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GlobalScape Secure FTP Server - Input Overflow (Metasploit)
Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DNET Live-Stats 0.8 - Local File Inclusion
Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary fi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD - 'pseudofs' Null Pointer Dereference Privilege Escalation
The pfs_getextattr function in FreeBSD 7.x before 7.3-RELEASE and 8.x before 8.0-RC1 unlocks a mutex that was not previo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Savant Web Server 3.1 - Remote Overflow (Metasploit)
Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP G
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Surgemail SurgeWeb 4.3e - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in NetWin Surgemail before 4.3g allows remote attackers to inject arbitrary web
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SmarterMail < 7.2.3925 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in UserControls/Popups/frmHelp.aspx in SmarterStats 5.3, 5.3.3819, and possibly
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SmarterMail < 7.2.3925 - LDAP Injection
Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Chipmunk Board 1.3 - 'index.php?forumID' SQL Injection
SQL injection vulnerability in index.php in Chipmunk Board 1.3 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.