Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.697exploits catalogados
36.715CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.264GitHub PoC 15.172VulnCheck XDB 8.920Nuclei 4.373Metasploit 3.493✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
ASX to MP3 Converter - '.m3u' Local Stack Overflow (PoC)
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RISCO
abrir ↗Referência✓ VexDay Proof
ASX to MP3 Converter 3.0.0.7 - '.m3u' Universal Stack Overflow
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RISCO
abrir ↗Referência✓ VexDay Proof
Mini-stream Ripper - '.m3u' Local Stack Overflow (PoC)
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RISCO
abrir ↗Referência✓ VexDay Proof
eLineStudio Site Composer (ESC) 2.6 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote atta
23RISCO
abrir ↗Referência✓ VexDay Proof
MODx CMS 0.9.2.1 - 'FCKeditor' Remote File Inclusion
PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS
23RISCO
abrir ↗Referência✓ VexDay Proof
pPIM 1.0 - Arbitrary File Delete / Cross-Site Scripting
Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote att
23RISCO
abrir ↗Referência✓ VexDay Proof
ClaSS 0.8.60 - 'export.php' Local File Inclusion
Directory traversal vulnerability in scripts/export.php in ClaSS before 0.8.61 allows remote attackers to read arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
Durian Web Application Server 3.02 - Remote Buffer Overflow
Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary c
23RISCO
abrir ↗Referência✓ VexDay Proof
Lanius CMS 1.2.16 - 'FCKeditor' Arbitrary File Upload
Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.
23RISCO
abrir ↗Referência✓ VexDay Proof
Ax Developer CMS 0.1.1 - 'index.php?module' Local File Inclusion
Directory traversal vulnerability in index.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers to include and
23RISCO
abrir ↗Referência✓ VexDay Proof
Acidcat CMS 3.4.1 - Multiple Vulnerabilities
Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3)
23RISCO
abrir ↗Referência✓ VexDay Proof
Aardvark Topsites PHP 4.2.2 - 'path' Remote File Inclusion
PHP remote file inclusion vulnerability in sources/join.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_gl
23RISCO
abrir ↗Referência✓ VexDay Proof
QuickTalk forum 1.3 - 'lang' Local File Inclusion
Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
RPG.Board 0.0.8Beta2 - 'showtopic' SQL Injection
SQL injection vulnerability in index.php in RPG.Board 0.8 Beta2 and earlier allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
EZ Publish < 3.9.5/3.10.1/4.0.1 - Privilege Escalation
The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1
23RISCO
abrir ↗Referência✓ VexDay Proof
Mini-stream Ripper 3.0.1.1 - '.m3u' Universal Stack Overflow
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RISCO
abrir ↗Referência✓ VexDay Proof
Mambo Component MMP 1.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in help.mmp.php in the MMP Component (com_mmp) 1.2 and earlier for Mambo allows
23RISCO
abrir ↗Referência✓ VexDay Proof
Pluck CMS 4.5.2 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute
23RISCO
abrir ↗Referência✓ VexDay Proof
AEP SmartGate 4.3b - 'GET' Arbitrary File Download
Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
Keller Web Admin CMS 0.94 Pro - Local File Inclusion (1)
Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to includ
23RISCO
abrir ↗Referência✓ VexDay Proof
Max.Blog 1.0.6 - Arbitrary Delete Post
delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog p
23RISCO
abrir ↗Referência✓ VexDay Proof
EasyNews PRO News Publishing 4.0 - Password Disclosure
STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows re
23RISCO
abrir ↗Referência✓ VexDay Proof
RM Downloader - '.m3u' Local Stack Overflow (PoC)
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RISCO
abrir ↗Referência✓ VexDay Proof
RM Downloader 3.0.0.9 - '.m3u' Universal Stack Overflow
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RISCO
abrir ↗Referência✓ VexDay Proof
eNdonesia 8.4 - '/mod.php/friend.php/admin.php' Multiple Vulnerabilities
Directory traversal vulnerability in mod.php in eNdonesia 8.4 allows remote attackers to read arbitrary files via a .. (
23RISCO
abrir ↗Referência✓ VexDay Proof
Open Azimyt CMS 0.22 - 'lang' Local File Inclusion
Directory traversal vulnerability in lang/lang-system.php in Open Azimyt CMS 0.22 minimal and 0.21 stable allows remote
23RISCO
abrir ↗Referência✓ VexDay Proof
RoseOnlineCMS 3 beta2 - 'op' Local File Inclusion
Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files
23RISCO
abrir ↗Referência✓ VexDay Proof
Sepcity Classified - 'ID' SQL Injection
SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent at
23RISCO
abrir ↗Referência✓ VexDay Proof
WM Downloader 3.0.0.9 - '.m3u' Universal Stack Overflow
Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RISCO
abrir ↗Referência✓ VexDay Proof
Motorola Timbuktu Pro 8.6.5/8.7 - Directory Traversal / Log Injection
Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging informat
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.