Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.233GitHub PoC 14.119VulnCheck XDB 8.617Nuclei 4.257Metasploit 3.474✓ só verificadosrecentespopularesrisco
24.451 exploits
Exploit-DB✓ VexDay Proof
Mozilla Firefox 2.0.x - Nested 'window.print()' Denial of Service
Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sopcast SopCore Control - 'sopocx.ocx' Command Execution
Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
EZ-Blog beta1 - Delete All Posts / SQL Injection
Multiple SQL injection vulnerabilities in EZ-Blog Beta 1, when magic_quotes_gpc is disabled, allow remote attackers to e
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell eDirectory iMonitor - 'Accept-Language' Request Buffer Overflow (PoC)
Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allow
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - 'seccomp' System Call Security Bypass
The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
EZ-Blog beta1 - Delete All Posts / SQL Injection
EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via re
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Graugon PHP Article Publisher 1.0 - SQL Injection / Cookie Handling
Multiple SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 allow remote attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Graugon PHP Article Publisher 1.0 - SQL Injection / Cookie Handling
admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrativ
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Merak Media Player 3.2 - '.m3u' File Local Buffer Overflow (SEH)
Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long strin
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Media Commands - '.m3u' Local Overwrite (SEH)
Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a d
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NovaStor NovaNET 12 - 'DtbClsLogin()' Remote Stack Buffer Overflow
Stack-based buffer overflow in the DtbClsLogin function in NovaStor NovaNET 12 allows remote attackers to (1) execute ar
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Blogsa 1.0 - 'Widgets.aspx' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Widgets.aspx in Blogsa 1.0 Beta 3 and earlier allows remote attackers to inj
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HTC Touch - vCard over IP Denial of Service
HTC Touch Pro and HTC Touch Cruise vCard allows remote attackers to cause denial of service (CPU consumption, SMS consum
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Document Library 1.0.1 - Arbitrary Change Admin
admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Orbit Downloader 2.8.4 - 'Hostname' Remote Buffer Overflow
Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Irokez Blog 0.7.3.2 - Multiple Input Validation Vulnerabilities
Multiple PHP remote file inclusion vulnerabilities in Irokez CMS 0.7.1 and earlier, when register_globals is enabled, al
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
djbdns 1.05 - Long Response Packet Remote Cache Poisoning
The response_addname function in response.c in Daniel J. Bernstein djbdns 1.05 and earlier does not constrain offsets in
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Websphere Application Server 6.1/7.0 - Administrative Console Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 bef
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSC 0.11.x - PKCS#11 Implementation Unauthorized Access
OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data obj
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative au
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Wesnoth 1.x - PythonAI Remote Code Execution
The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute ar
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
Directory traversal vulnerability in notes.php in Phlatline's Personal Information Manager (pPIM) 1.01 allows remote att
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - Cloned Process 'CLONE_PARENT' Local Origin Validation
The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent pr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
Unrestricted file upload vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in events.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows rem
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote att
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Safari 4 - 'feeds:' URI Null Pointer Dereference Remote Denial of Service
Apple Safari 4 Beta build 528.16 allows remote attackers to cause a denial of service (NULL pointer dereference and appl
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player 9/10 - Invalid Object Reference Remote Code Execution
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed obje
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Magento 1.2 - '/app/code/core/Mage/Admin/Model/Session.php?login['Username']' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Magento 1.2 - '/app/code/core/Mage/Adminhtml/controllers/IndexController.php?email' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitr
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.