Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.231exploits catalogados
35.420CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.266GitHub PoC 14.131VulnCheck XDB 8.635Nuclei 4.274Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.266 exploits
Referência✓ VexDay Proof
otscms 2.1.5 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in mod/PM/reply.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attack
23RISCO
abrir ↗Referência
CVE-2020-8657
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include
100RISCO
abrir ↗Referência✓ VexDay Proof
OPENi-CMS Site Protection Plugin - Remote File Inclusion
PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attackers to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
Axigen 2.0.0b1 - Remote Denial of Service (2)
axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial
28RISCO
abrir ↗Referência✓ VexDay Proof
OpenX 2.6.3 - 'MAX_type' Local File Inclusion
Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary file
23RISCO
abrir ↗Referência
CVE-2018-16509
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISCO
abrir ↗Referência
CVE-2018-3810
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RISCO
abrir ↗Referência
CVE-2009-3023
Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authen
60RISCO
abrir ↗Referência✓ VexDay Proof
philboard 1.14 - 'philboard_forum.asp' SQL Injection
SQL injection vulnerability in philboard_forum.asp in Philboard 1.14 and earlier allows remote attackers to execute arbi
23RISCO
abrir ↗Referência
CVE-2015-8556
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
28RISCO
abrir ↗Referência
CVE-2017-15222
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RISCO
abrir ↗Referência✓ VexDay Proof
Nortel SSL VPN Linux Client 6.0.3 - Local Privilege Escalation
The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 10
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke 8.0 Final - HTTP Referers SQL Injection
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" blo
35RISCO
abrir ↗Referência✓ VexDay Proof
News Bin Pro 5.33 - '.nbi' Local Buffer Overflow
Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
TurboFTP Server 5.30 Build 572 - 'newline/LIST' Multiple Remote Denial of Service Vulnerabilities
TurboFTP 5.30 Build 572 allows remote servers to cause a denial of service (CPU consumption) via a response with a large
23RISCO
abrir ↗Referência✓ VexDay Proof
TurboFTP Server 5.30 Build 572 - 'newline/LIST' Multiple Remote Denial of Service Vulnerabilities
Multiple heap-based buffer overflows in TurboFTP 5.30 Build 572 allow remote servers to cause a denial of service via (1
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP-MIP 0.1 - 'top.php?laypath' Remote File Inclusion
PHP remote file inclusion vulnerability in top.php in PHP Module Implementation (PHP-MIP) 0.1 allows remote attackers to
23RISCO
abrir ↗Referência
CVE-2024-13160
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RISCO
abrir ↗Referência
CVE-2019-7195
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi
100RISCO
abrir ↗Referência
CVE-2019-17621
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated rem
100RISCO
abrir ↗Referência
CVE-2018-4878
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir ↗Referência
CVE-2018-14417
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particul
45RISCO
abrir ↗Referência✓ VexDay Proof
Angel Lms 7.1 - 'default.asp?id' SQL Injection
SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers
23RISCO
abrir ↗Referência✓ VexDay Proof
Connectix Boards 0.7 - 'p_skin' Multiple Vulnerabilities
Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticat
23RISCO
abrir ↗Referência✓ VexDay Proof
WebMod 0.48 - Content-Length Remote Buffer Overflow
Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execut
23RISCO
abrir ↗Referência✓ VexDay Proof
AJ Dating 1.0 - 'view_profile.php' SQL Injection
SQL injection vulnerability in view_profile.php in AJDating 1.0 allows remote attackers to execute arbitrary SQL command
23RISCO
abrir ↗Referência✓ VexDay Proof
AJ Auction Pro - 'subcat.php' SQL Injection
SQL injection vulnerability in subcat.php in AJ Auction 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir ↗Referência✓ VexDay Proof
Mani Stats Reader 1.2 - 'ipath' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Mani Stats Reader 1.2 and earlier allows remote attackers to exe
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.