Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.724exploits catalogados
35.724CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.492GitHub PoC 14.286VulnCheck XDB 8.703Nuclei 4.314Metasploit 3.474✓ só verificadosrecentespopularesrisco
24.455 exploits
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - HTML Tag Memory Corruption (MS06-013)
Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamicall
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Easy-Content Forums 1.0 - Multiple SQL Injection / Cross-Site Scripting Vulnerabilities
Multiple SQL injection vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to execute arbitrary SQL comman
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Easy-Content Forums 1.0 - Multiple SQL Injection / Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to inject arbitrary web scr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Plume CMS 1.0.3 - 'manager_path' Remote File Inclusion
PHP remote file inclusion vulnerability in manager/frontinc/prepend.php for Plume 1.0.3 allows remote attackers to execu
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
qjForum - 'member.asp' SQL Injection
SQL injection vulnerability in member.asp in qjForum allows remote attackers to execute arbitrary SQL commands via the u
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
tiffsplit (libtiff 3.8.2) - Local Stack Buffer Overflow
Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Plume CMS 1.0.3 - 'manager_path' Remote File Inclusion
PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Socketmail 2.2.6 - 'site_path' Remote File Inclusion
PHP remote file inclusion vulnerability in SocketMail Lite and Pro 2.2.6 and earlier, when register_globals and magic_qu
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Core 2.0.2 - 'cache' Remote Shell Injection
Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary c
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Invision Power Board 2.0/2.1 - 'index.php?CK' SQL Injection
SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 al
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Docebo 3.0.3 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Nucleus CMS 3.22 - 'DIR_LIBS' Remote File Inclusion
PHP remote file inclusion vulnerability in nucleus/libs/PLUGINADMIN.php in Nucleus 3.22 and earlier allows remote attack
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
netPanzer 0.8 rev 952 - 'frameNum' Server Terminiation
The setFrame function in Lib/2D/Surface.hpp for NetPanzer 0.8 and earlier allows remote attackers to cause a denial of s
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AZ Photo Album Script Pro - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in AZ Photo Album Script Pro allows remote attackers to inject arb
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PunkBuster < 1.229 - WebTool Service Remote Buffer Overflow (Denial of Service) (PoC)
Buffer overflow in the WebTool HTTP server component in (1) PunkBuster before 1.229, as used by multiple products includ
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Dia 0.8x/0.9x - Filename Remote Format String
Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Prodder 0.4 - Arbitrary Shell Command Execution
Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacter
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cyrus IMAPD 2.3.2 - 'pop3d' Remote Buffer Overflow (1)
Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allow
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CodeAvalanche News 1.2 - 'default.asp' SQL Injection
SQL injection vulnerability in default.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to execute arbitra
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpBazar 2.1.0 - Remote File Inclusion / Authentication Bypass
Admin/admin.php in phpBazar 2.1.0 and earlier allows remote attackers to bypass the authentication process and gain unau
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Artmedic NewsLetter 4.1 - 'Log.php' Remote Script Execution
artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpBazar 2.1.0 - Remote File Inclusion / Authentication Bypass
PHP remote file inclusion vulnerability in classified_right.php in phpBazar 2.1.0 and earlier allows remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
JemWeb DownloadControl 1.0 - 'DC.php' SQL Injection
Jemscripts DownloadControl 1.0 allows remote attackers to obtain sensitive information via an invalid dcid parameter to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cosmoshop 8.10.78/8.11.106 - 'Lshop.cgi' SQL Injection
SQL injection vulnerability in lshop.cgi in Cosmoshop 8.11.106 and earlier allows remote attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ASPBB 0.5.2 - 'default.asp?action' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in AspBB 0.5.2 allow remote attackers to inject arbitrary web script
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ASPBB 0.5.2 - 'profile.asp?get' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in AspBB 0.5.2 allow remote attackers to inject arbitrary web script
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
libextractor 0.5.13 - Multiple Heap Overflows (PoC)
Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
obotix IP Camera M1 1.9.4 .7/M10 2.0.5.2 - help Script Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
obotix IP Camera M1 1.9.4 .7/M10 2.0.5.2 - 'events.tar?source_ip' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Quezza BB 1.0 - 'quezza_root_path' File Inclusion
PHP remote file inclusion vulnerability in includes/class_template.php in Quezza 1.0 and earlier, and possibly 1.1.0 all
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.