Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.542exploits catalogados
34.971CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.899GitHub PoC 13.947VulnCheck XDB 8.542Nuclei 4.243Metasploit 3.468✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB
Yamamah - 'news' SQL Injection / Source Code Disclosure
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbit
23RISCO
abrir ↗Exploit-DB
Yamamah - 'news' SQL Injection / Source Code Disclosure
SQL injection vulnerability in index.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote at
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SolarWinds TFTP Server 10.4.0.13 - Denial of Service
SolarWinds TFTP Server 10.4.0.13 allows remote attackers to cause a denial of service (crash) via a long write request.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sygate Personal Firewall 5.6 build 2808 - ActiveX with DEP Bypass
Buffer overflow in an ActiveX control in SSHelper.dll for Symantec Sygate Personal Firewall 5.6 build 2808 allows remote
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Streamcast 0.9.75 - HTTP User-Agent Buffer Overflow (Metasploit)
Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or
50RISCO
abrir ↗Exploit-DB
ardeacore 2.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in ardeaCore/lib/core/ardeaInit.php in ardeaCore PHP Framework 2.2 allows remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AneCMS 1.x - '/modules/blog/index.php' HTML Injection
Cross-site scripting (XSS) vulnerability in class/tools.class.php in AneCMS Blog 1.3 and possibly earlier allows remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe InDesign CS3 - '.INDD' Handling Buffer Overflow
Buffer overflow in Adobe InDesign CS3 10.0 allows user-assisted remote attackers to execute arbitrary code via a crafted
28RISCO
abrir ↗Exploit-DB
DaLogin - Multiple Vulnerabilities
SQL injection vulnerability in new.php in DaLogin 2.2 and 2.2.5 allows remote attackers to execute arbitrary SQL command
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Nginx 0.7.65/0.8.39 (dev) - Source Disclosure / Download
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Nginx 0.8.36 - Source Disclosure / Denial of Service
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AneCMS 1.x - '/modules/blog/index.php' SQL Injection
SQL injection vulnerability in modules/blog/index.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Power Tab Editor 1.7 (Build 80) - Local Buffer Overflow
Stack-based buffer overflow in Power Tab Editor 1.7 build 80 allows user-assisted remote attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Nginx 0.8.36 - Source Disclosure / Denial of Service
nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequen
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SchoolMation 2.3 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to execute arb
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SchoolMation 2.3 - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers t
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Help and Support Center - '/sysinfo/sysinfomain.htm' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Hel
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Arab Portal 2.2 - 'members.php' SQL Injection
SQL injection vulnerability in members.php in Arab Portal 2.2, when magic_quotes_gpc is disabled, allows remote attacker
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Help Centre Handles - Malformed Escape Sequences Incorrectly (MS03-044)
The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server
60RISCO
abrir ↗Exploit-DB
Netvolution CMS 2.x - SQL Injection Script
SQL injection vulnerability in default.asp in ATCOM Netvolution 2.5.6 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Science Fair In A Box - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to e
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Science Fair In A Box - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
eLms Pro - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in error.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arb
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
eLms Pro - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to execute arbitrary S
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
eLms Pro - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Virtual Real Estate Manager 3.5 - SQL Injection
SQL injection vulnerability in listing_detail.asp in Mckenzie Creations Virtual Real Estate Manager (VRM) 3.5 allows rem
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Online Notebook Manager - SQL Injection
SQL injection vulnerability in onlinenotebookmanager.asp in DMXReady Online Notebook Manager 1.0 allows remote attackers
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HauntmAx CMS Haunted House - Directory Listing / SQL Injection
SQL injection vulnerability in index.php in HauntmAx Haunted House Directory Listing CMS allows remote attackers to exec
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Real Estate Script - SQL Injection
SQL injection vulnerability in index.php in Eicra Realestate Script 1.0 and 1.6.0 allows remote attackers to execute arb
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash / Reader - Live Malware
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrob
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.