Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.233GitHub PoC 14.119VulnCheck XDB 8.617Nuclei 4.257Metasploit 3.474✓ só verificadosrecentespopularesrisco
24.451 exploits
Exploit-DB✓ VexDay Proof
Adobe Flash Player 9/10 - Invalid Object Reference Remote Code Execution
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed obje
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! / Mambo Component gigCalendar 1.0 - 'banddetails.php' SQL Injection
Multiple SQL injection vulnerabilities in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla!, when magic_q
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 7 (Windows 2003 SP2) - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 7 (Windows XP SP2) - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - 'sock.c' SO_BSDCOMPAT Option Information Disclosure
The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain struct
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Enomaly ECP / Enomalism < 2.2.1 - Multiple Local Vulnerabilities
Argument injection vulnerability in Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows lo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - 'make_indexed_dir()' Local Denial of Service
The make_indexed_dir function in fs/ext4/namei.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TPTEST 3.1.7 - Stack Buffer Overflow (PoC)
Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 allows remote attackers to have an unknown
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 6.0.9 - XPath Expression Remote Denial of Service
sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CmsFaethon 2.2.0 - 'item' SQL Injection
SQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ea-gBook 0.1 - Remote Command Execution / Remote File Inclusion
PHP remote file inclusion vulnerability in index_inc.php in ea gBook 0.1 and 0.1.4 allows remote attackers to execute ar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ideacart 0.02 - Local File Inclusion / SQL Injection
SQL injection vulnerability in secure/index.php in IdeaCart 0.02 allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Vlinks 1.1.6 - 'id' SQL Injection
SQL injection vulnerability in page.php in Vlinks 1.0.3 and 1.1.6 allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ideacart 0.02 - Local File Inclusion / SQL Injection
Directory traversal vulnerability in index.php in IdeaCart 0.02 and 0.02a allows remote attackers to read arbitrary file
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Poppler 0.10.3 - Denial of Service
The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of servic
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Poppler 0.10.3 - Denial of Service
The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of servic
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GeoVision Digital Video Surveillance System 8.2 - Arbitrary File Disclosure
Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote atta
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bloggeruniverse 2.0 Beta - 'id' SQL Injection
SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows rem
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ProFTPd - 'mod_mysql' Authentication Bypass
ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms vi
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TYPO3 < 4.0.12/4.1.10/4.2.6 - 'jumpUrl' Remote File Disclosure
The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 befo
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Swann DVR4 SecuraNet - Directory Traversal
Directory traversal vulnerability in the administrative web server in Swann DVR4-SecuraNet allows remote attackers to re
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ProFTPd 1.3 - 'mod_sql' 'Username' SQL Injection
SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL co
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Banking@Home 2.1 - 'login.asp' Multiple SQL Injections
SQL injection vulnerability in Login.asp in Craft Silicon Banking@Home 2.1 and earlier allows remote attackers to execut
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WB News 2.1.1 - config[installdir] Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in WB News 2.0.1, when register_globals is enabled, allow remote atta
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FlexCMS 2.5 - 'catId' SQL Injection
SQL injection vulnerability in FlexCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the ItemId para
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Gaeste 1.6 - 'gastbuch.php' Remote File Disclosure
Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell QuickFinder Server - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterp
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FotoWeb 6.0 - 'Login.fwx?s' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in FotoWeb 6.0 (Build 273) allow remote attackers to inject arbitrar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FotoWeb 6.0 - 'Grid.fwx?search' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in FotoWeb 6.0 (Build 273) allow remote attackers to inject arbitrar
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.