Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.781exploits catalogados
36.771CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.305GitHub PoC 15.197VulnCheck XDB 8.932Nuclei 4.379Metasploit 3.493✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
MetaForum 0.513 Beta - Arbitrary File Upload
Unrestricted file upload vulnerability in usercp.php in MetaForum 0.513 Beta restricts file types based on the MIME type
23RISCO
abrir ↗Referência✓ VexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (PoC)
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RISCO
abrir ↗Referência✓ VexDay Proof
Free Bible Search PHP Script - SQL Injection
SQL injection vulnerability in readbible.php in Free Bible Search PHP Script 1.0 allows remote attackers to execute arbi
23RISCO
abrir ↗Referência✓ VexDay Proof
verlihub 0.9.8d-RC2 - Remote Command Execution
The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlie
23RISCO
abrir ↗Referência✓ VexDay Proof
JBC Explorer 7.20 RC 1 - Remote Code Execution
Direct static code injection vulnerability in dirsys/modules/config/post.php in JBC Explorer 7.20 RC1 and earlier allows
23RISCO
abrir ↗Referência✓ VexDay Proof
ESPG (Enhanced Simple PHP Gallery) 1.72 - File Disclosure
Directory traversal vulnerability in gallery/comment.php in Enhanced Simple PHP Gallery (ESPG) 1.72 allows remote attack
23RISCO
abrir ↗Referência✓ VexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir ↗Referência✓ VexDay Proof
Quate CMS 0.3.4 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Quate CMS 0.3.4 allow remote attackers to inject arbitrary web sc
23RISCO
abrir ↗Referência✓ VexDay Proof
CoreHTTP 0.5.3alpha - HTTPd Remote Buffer Overflow
Multiple buffer overflows in the HttpSprockMake function in http.c in Frank Yaul corehttp 0.5.3alpha allow remote attack
23RISCO
abrir ↗Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.6 - Local File Inclusion / Code Execution
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 all
23RISCO
abrir ↗Referência✓ VexDay Proof
ZeusCMS 0.3 - Blind SQL Injection
Absolute path traversal vulnerability in ZeusCMS 0.3 and earlier might allow remote attackers to list arbitrary director
23RISCO
abrir ↗Referência✓ VexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remo
23RISCO
abrir ↗Referência✓ VexDay Proof
Advanced Links Management (ALM) 1.52 - SQL Injection
SQL injection vulnerability in read.php in Advanced Links Management (ALM) 1.5.2 allows remote attackers to execute arbi
23RISCO
abrir ↗Referência✓ VexDay Proof
FTPShell Server 4.3 - Licence Key Remote Buffer Overflow (PoC)
Stack-based buffer overflow in FTPShell Server 4.3 allows user-assisted remote attackers to cause a denial of service (p
23RISCO
abrir ↗Referência✓ VexDay Proof
CDex 1.70b2 (Windows XP SP3) - '.ogg' Local Buffer Overflow
Buffer overflow in CDex 1.70b2 allows remote attackers to execute arbitrary code via a crafted Info header in an Ogg Vor
23RISCO
abrir ↗Referência✓ VexDay Proof
PsNews 1.1 - 'show.php?newspath' Local File Inclusion
Directory traversal vulnerability in news/show.php in PsNews 1.1 allows remote attackers to include and execute arbitrar
23RISCO
abrir ↗Referência✓ VexDay Proof
CityWriter 0.9.7 - 'head.php' Remote File Inclusion
PHP remote file inclusion vulnerability in head.php in CityWriter 0.9.7 allows remote attackers to execute arbitrary PHP
23RISCO
abrir ↗Referência✓ VexDay Proof
Snircd 1.3.4 - 'send_user_mode' Denial of Service
The send_user_mode function in s_user.c in (1) Undernet ircu 2.10.12.12 and earlier, (2) snircd 1.3.4 and earlier, and u
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component EasyBook 1.1 - 'gbid' SQL Injection
SQL injection vulnerability in the EasyBook (com_easybook) component 1.1 for Joomla! allows remote attackers to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 7 - Clickjacking
Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick acti
28RISCO
abrir ↗Referência✓ VexDay Proof
SiteXS CMS 0.1.1 - Local File Inclusion
Directory traversal vulnerability in post.php in SiteXS CMS 0.1.1 and earlier allows remote attackers to include and exe
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component ElearningForce Flash Magazine Deluxe - SQL Injection
SQL injection vulnerability in the ElearningForce Flash Magazine Deluxe (com_flashmagazinedeluxe) component for Joomla!
23RISCO
abrir ↗Referência✓ VexDay Proof
PLog 1.0.6 - 'albumID' SQL Injection
SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitra
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component beamospetition 1.0.12 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attack
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component beamospetition 1.0.12 - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Jo
23RISCO
abrir ↗Referência✓ VexDay Proof
mebiblio 0.4.7 - SQL Injection / Arbitrary File Upload / Cross-Site Scripting
Unrestricted file upload vulnerability in upload/uploader.html in meBiblio 0.4.7 allows remote attackers to execute arbi
23RISCO
abrir ↗Referência✓ VexDay Proof
ezusermanager 1.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in ezUserManager 1.6 and earlier, when register_globals is enabled, allows remot
23RISCO
abrir ↗Referência✓ VexDay Proof
TightVNC - Authentication Failure Integer Overflow (PoC)
Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to ca
28RISCO
abrir ↗Referência✓ VexDay Proof
UltraVNC/TightVNC (Multiple VNC Clients) - Multiple Integer Overflows (PoC)
Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to ca
28RISCO
abrir ↗Referência✓ VexDay Proof
WOW Web On Windows ActiveX Control 2 - Remote Code Execution
Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attac
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.