Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.233GitHub PoC 14.119VulnCheck XDB 8.617Nuclei 4.257Metasploit 3.474✓ só verificadosrecentespopularesrisco
24.451 exploits
Exploit-DB✓ VexDay Proof
Microsoft XML Core Services DTD - Cross-Domain Scripting (MS08-069)
Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office,
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pilot Group PG Roommate Finder Solution - SQL Injection
SQL injection vulnerability in admin/index.php in PG Roommate Finder Solution allows remote attackers to execute arbitra
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft XML Core Services DTD - Cross-Domain Scripting (MS08-069)
Cross-domain vulnerability in Microsoft XML Core Services 3.0 and 4.0, as used in Internet Explorer, allows remote attac
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Softbiz Classifieds Script - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in signinform.php in Softbiz Classifieds Script allows remote attackers to inje
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (2)
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.2.6 - 'error_log' Safe_mode Bypass
The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe m
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GeSHi 1.0.x - XML Parsing Remote Denial of Service
The highlighting functionality in geshi.php in GeSHi before 1.0.8 allows remote attackers to cause a denial of service (
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Vista - 'iphlpapi.dll' Local Kernel Buffer Overflow
Stack-based buffer overflow in Microsoft Device IO Control in iphlpapi.dll in Microsoft Windows Vista Gold and SP1 allow
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AskPert - Authentication Bypass
SQL injection vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RevSense 1.0 - Authentication Bypass
SQL injection vulnerability in index.php in W3matter AskPert allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MusicBox 2.3.8 - 'viewalbums.php' SQL Injection
SQL injection vulnerability in viewalbums.php in Musicbox 2.3.6 and 2.3.7 allows remote attackers to execute arbitrary S
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SaturnCMS - Blind SQL Injection
SQL injection vulnerability in lib/url/meta_url.php in SaturnCMS allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BoutikOne CMS - 'search_query' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php in BoutikOne CMS allows remote attackers to inject arbitrary web
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 9.62 - 'file://' Local Heap Overflow
Multiple buffer overflows in Opera before 9.63 might allow (1) remote attackers to execute arbitrary code via a crafted
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (1)
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Simple Customer 1.2 - Authentication Bypass
SQL injection vulnerability in login.php in Simple Customer as downloaded on 20081118 allows remote attackers to execute
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (1)
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VeryPDF PDFView - ActiveX Component Heap Buffer Overflow
Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Active Directory LDAP Server - 'Username' Enumeration
The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Alstrasoft Web Host Directory 1.2 - Multiple Vulnerabilities
SQL injection vulnerability in the login directory in AlstraSoft Web Host Directory allows remote attackers to execute a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Alstrasoft Web Host Directory 1.2 - Multiple Vulnerabilities
AlstraSoft Web Host Directory stores sensitive information under the web root with insufficient access control, which al
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ScriptsFeed (SF) Auto Classifieds Software - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execut
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ScriptsFeed (SF) Auto Classifieds Software - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows re
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ScriptsFeed (SF) Recipes Listing Portal - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows re
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ScriptsFeed (SF) Real Estate Classifieds Software - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execut
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ScriptsFeed (SF) Real Estate Classifieds Software - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ScriptsFeed (SF) Recipes Listing Portal - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Netgear WGR614 - Administration Interface Remote Denial of Service
The web management interface in Netgear WGR614v9 allows remote attackers to cause a denial of service (crash) via a requ
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Net-SNMP 5.1.4/5.2.4/5.4.1 Perl Module - Buffer Overflow (PoC)
Buffer overflow in the __snprint_value function in snmp_get in Net-SNMP 5.1.4, 5.2.4, and 5.4.1, as used in SNMP.xs for
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Castle Rock Computing SNMPc < 7.1.1 - 'Community' Remote Buffer Overflow (PoC)
Stack-based buffer overflow in the Network Manager in Castle Rock Computing SNMPc 7.1 and earlier allows remote attacker
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.