Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
81.177exploits catalogados
37.765CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 24.138GitHub PoC 15.538VulnCheck XDB 9.080Nuclei 4.434Metasploit 3.505✓ só verificadosrecentespopularesrisco
24.482 exploits
Exploit-DB✓ VexDay Proof
IBM DB2 - 'REPEAT()' Local Heap Buffer Overflow
Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated use
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Geo++ GNCASTER 1.4.0.7 - GET Denial of Service
Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to cause a denial of service (application crash) and possibly
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iOS Serversman 3.1.5 - HTTP Remote Denial of Service
FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch, allows remote attackers to cause a deni
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PostgreSQL - 'bitsubstr' Buffer Overflow
The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Secure Desktop 3.x - 'translation' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions bef
23RISCO
abrir ↗Exploit-DB
South River Technologies WebDrive Service 9.02 build 2232 - Bad Security Descriptor Privilege Escalation
South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which all
23RISCO
abrir ↗Exploit-DB
Joomla! Component com_mochigames - SQL Injection
SQL injection vulnerability in the Mochigames (com_mochigames) component 0.51 and possibly other versions for Joomla! al
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
magic-portal 2.1 - SQL Injection
SQL injection vulnerability in home.php in magic-portal 2.1 allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir ↗Exploit-DB
Joomla! Component com_casino - SQL Injection
SQL injection vulnerability in the casino (com_casino) component 1.0 for Joomla! allows remote attackers to execute arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component com_gameserver - SQL Injection
SQL injection vulnerability in the indianpulse Game Server (com_gameserver) component 1.2 for Joomla! allows remote atta
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome 3.0 - Style Sheet redirection Information Disclosure
WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's targe
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Java System Web Server 6.1/7.0 - WebDAV Format String
Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows r
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Java System Web Server 6.1/7.0 - Digest Authentication Remote Buffer Overflow
Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 8 - URI Validation Remote Code Execution
The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API functi
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Blog System 1.x - 'note' SQL Injection
Multiple SQL injection vulnerabilities in NetArt Media Blog System 1.5 allow remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
kloNews 2.0 - 'cat.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in cat.php in KloNews 2.0 allows remote attackers to inject arbitrary web scrip
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DataLife Engine 8.3 - '/engine/inc/help.php?config[langs]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DataLife Engine 8.3 - '/engine/inc/include/init.php?selected_language' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DataLife Engine 8.3 - '/engine/ajax/pm.php?config[lang]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DataLife Engine 8.3 - '/engine/ajax/addcomments.php?_REQUEST[skin]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pidgin MSN 2.6.4 - File Download
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allow
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT/2000/2003/2008/XP/Vista/7 - 'KiTrap0D' User Mode to Ring Escalation (MS10-015)
The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Se
91RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AdvertisementManager 3.1 - 'req' Local/Remote File Inclusion
PHP remote file inclusion vulnerability in cgi/index.php in AdvertisementManager 3.1.0 allows remote attackers to execut
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zenoss 2.3.3 - Multiple Cross-Site Request Forgery Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6/7/8 - Shockwave Flash Object Denial of Service
Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow remote attackers to cause a denial of service
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bits Video Script 2.04/2.05 - 'search.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allows re
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Hitmaaan Gallery 1.3 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Hitmaaan Gallery 1.3 allow remote attackers to injec
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bits Video Script 2.04/2.05 - '/register.php' Arbitrary File Upload / Arbitrary PHP Code Execution
Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Scri
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Easysitenetwork Jokes Complete Website - 'id' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Jokes Complete Website allow remote attackers to inject arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bits Video Script 2.05 Gold Beta - 'showcasesearch.php?rowptem[template]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in BitScripts Bits Video Script 2.05 Gold Beta, and possibly 2.04, al
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.