Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
81.270exploits catalogados
37.818CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 24.178GitHub PoC 15.557VulnCheck XDB 9.108Nuclei 4.440Metasploit 3.505✓ só verificadosrecentespopularesrisco
24.482 exploits
Exploit-DB✓ VexDay Proof
Joomla! Component com_lyftenbloggie 1.04 - SQL Injection
SQL injection vulnerability in Lyften Designs LyftenBloggie (com_lyftenbloggie) component 1.0.4 for Joomla! allows remot
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Micronet SP1910 Data Access Controller UI - Cross-Site Scripting / HTML Code Injection
Cross-site scripting (XSS) vulnerability in loginpages/error_user.shtml on the Micronet Network Access Controller SP1910
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP < 5.3.1 - 'MultiPart/form-data' Denial of Service
PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipa
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Eureka Email Client - Remote Buffer Overflow
Stack-based buffer overflow in Eureka Email 2.2q allows remote POP3 servers to execute arbitrary code via a long error m
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cacti 0.8.7e - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web scrip
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cacti 0.8.7e - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in include/top_graph_header.php in Cacti before 0.8.7g allows remote attackers
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Serenity Audio Player Playlist - '.m3u' Local Buffer Overflow
Stack-based buffer overflow in the MplayInputFile function in Serenity Audio Player 3.2.3 and earlier allows remote atta
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin WP-Cumulus 1.20 - Full Path Disclosure / Cross-Site Scripting
WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive informat
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component com_gcalendar 1.1.2 - 'gcid' SQL Injection
SQL injection vulnerability in the Google Calendar GCalendar (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlie
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpBazar-2.1.1fix - Remote Administration-Panel
phpBazar 2.1.1fix and earlier does not require administrative authentication for admin/admin.php, which allows remote at
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Radio istek scripti 2.5 - Remote Configuration Disclosure
RADIO istek scripti 2.5 stores sensitive information under the web root with insufficient access control, which allows r
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
kr-web 1.1b2 - Remote File Inclusion
PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execut
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
XM Easy Personal FTP Server 5.8.0 - Remote Denial of Service
Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (daemon outage)
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phptraverse 0.8.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in assets/plugins/mp3_id/mp3_id.php in PHP Traverser 0.8.0 allows remote attacke
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
outreach project tool 1.2.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in forums/Forum_Include/index.php in Outreach Project Tool (OPT) 1.2.7 and earli
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
klinza Professional CMS 5.0.1 - 'menulast.php' Local File Inclusion
Directory traversal vulnerability in funzioni/lib/menulast.php in klinza professional cms 5.0.1 and earlier allows remot
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
XM Easy Personal FTP Server 5.8.0 - Remote Denial of Service
XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (crash) by uploading or
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Python < 2.5.2 Imageop Module - 'imageop.crop()' Buffer Overflow
Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent atta
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Quick.Cart 3.4 / Quick.CMS 2.4 - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authen
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TYPSoft FTP Server 1.10 - APPE DELE Denial of Service
TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (crash) by sending an APPE (appen
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NukeHall 0.3 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in NukeHall 0.3 and earlier allow remote attackers to execute arbitra
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
pointcomma 3.8b2 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/classes/pctemplate.php in PointComma 3.8b2 and earlier allows remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Quick.Cart 3.4 / Quick.CMS 2.4 - Delete Function Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authen
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 6.0.9 - SELECT Statement WHERE Clause Sub-query Denial of Service
mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of cert
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Autodesk SoftImage Scene TOC - Arbitrary Command Execution
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene pac
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 6.0.9 - 'GeomFromWKB()' Function First Argument Geometry Value Handling Denial of Service
mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of cert
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Autodesk SoftImage 7.0 Scene - '.TOC' File Remote Code Execution
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene pac
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Autodesk Maya Script - Nodes Arbitrary Command Execution
Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TEKUVA - Password Reminder Authentication Bypass
TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover c
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco VPN Client - Integer Overflow Denial of Service
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.