Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8.946Nuclei 4.390Metasploit 3.501✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
Liberum Help Desk 0.97.3 - SQL Injection / File Disclosure
Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, whic
23RISCO
abrir ↗Referência✓ VexDay Proof
ColdFusion Scripts Red_Reservations - Database Disclosure
The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access cont
23RISCO
abrir ↗Referência✓ VexDay Proof
Ocean12 FAQ Manager Pro - Database Disclosure
Ocean12 FAQ Manager Pro stores sensitive data under the web root with insufficient access control, which allows remote a
23RISCO
abrir ↗Referência✓ VexDay Proof
cf shopkart 5.2.2 - SQL Injection / File Disclosure
CF Shopkart 5.2.2 stores cfshopkart52.mdb under the web root with insufficient access control, which allows remote attac
23RISCO
abrir ↗Referência✓ VexDay Proof
TopList 1.3.8 - 'phpBB Hack' Remote File Inclusion (1)
PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enab
28RISCO
abrir ↗Referência✓ VexDay Proof
PhShoutBox 1.5 - Insecure Cookie Handling
phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain p
23RISCO
abrir ↗Referência✓ VexDay Proof
DreamPics Builder - 'page' SQL Injection
SQL injection vulnerability in index.php in DreamPics Builder allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
Oracle 10g - 'LT.FINDRICSET' SQL Injection (IDS Evasion)
SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.
50RISCO
abrir ↗Referência✓ VexDay Proof
HIOX Banner Rotator 1.3 - 'hm' Remote File Inclusion
PHP remote file inclusion vulnerability in hioxBannerRotate.php in HIOX Banner Rotator (HBR) 1.3, when register_globals
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component BibTeX 1.3 - Blind SQL Injection
SQL injection vulnerability in index.php in the BibTeX component (com_jombib) 1.3 and earlier for Joomla! allows remote
23RISCO
abrir ↗Referência✓ VexDay Proof
CcMail 1.0.1 - Insecure Cookie Handling
Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session
23RISCO
abrir ↗Referência✓ VexDay Proof
Download Accelerator Plus DAP 8.x - '.m3u' File Buffer Overflow
Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allow
23RISCO
abrir ↗Referência✓ VexDay Proof
TOWeLS 0.1 - 'scripture.php' Remote File Inclusion
PHP remote file inclusion vulnerability in src/scripture.php in The Online Web Library Site (TOWels) 0.1 allows remote a
28RISCO
abrir ↗Referência✓ VexDay Proof
CCLeague Pro 1.2 - Insecure Cookie Authentication
admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin
23RISCO
abrir ↗Referência✓ VexDay Proof
4Images 1.7.7 - Filter Bypass HTML Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPizabi 0.848b C1 HFP3 - Database Information Disclosure
The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings del
23RISCO
abrir ↗Referência✓ VexDay Proof
Dokeos 1.6.5 - 'courseLog.php?scormcontopen' SQL Injection
SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arb
23RISCO
abrir ↗Referência✓ VexDay Proof
DreamNews Manager - 'id' SQL Injection
SQL injection vulnerability in dreamnews-rss.php in DreamNews Manager allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Referência✓ VexDay Proof
P2P Foxy - Out of Memory Denial of Service
Foxy P2P software allows remote attackers to cause a denial of service (memory consumption) via a foxy URI with a downlo
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Pony Gallery 1.5 - SQL Injection
SQL injection vulnerability in index.php in the Pony Gallery (com_ponygallery) 1.5 and earlier component for Joomla! all
23RISCO
abrir ↗Referência✓ VexDay Proof
xGB 2.0 - 'xGB.php' Remote Security Bypass
xGB.php in xGB 2.0 does not require authentication for an admin edit action, which allows remote attackers to make unspe
23RISCO
abrir ↗Referência✓ VexDay Proof
Papoo CMS 3.x - 'pfadhier' Local File Inclusion
Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled an
23RISCO
abrir ↗Referência✓ VexDay Proof
MySpeach 2.1b - 'up.php' Remote File Inclusion
PHP remote file inclusion vulnerability in up.php in MySpeach 2.1 beta and possibly earlier allows remote attackers to e
23RISCO
abrir ↗Referência✓ VexDay Proof
iziContents rc6 - Local/Remote File Inclusion
Multiple incomplete blacklist vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute arbitra
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP Project Management 0.8.10 - Multiple Local/Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers t
35RISCO
abrir ↗Referência✓ VexDay Proof
phpBB Ajax Shoutbox 0.0.5 - Remote File Inclusion
PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows r
23RISCO
abrir ↗Referência✓ VexDay Proof
zFeeder 1.6 - 'admin.php' Admin Bypass
zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php.
23RISCO
abrir ↗Referência✓ VexDay Proof
MiniGal b13 - Remote Code Execution
The imagecomments function in classes.php in MiniGal b13 allows remote attackers to inject arbitrary PHP code into a fil
23RISCO
abrir ↗Referência✓ VexDay Proof
VWar 1.5.0 R15 - 'mvcw.php' Remote File Inclusion
PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote at
23RISCO
abrir ↗Referência✓ VexDay Proof
Scribe 0.2 - 'index.php' Local File Inclusion
Directory traversal vulnerability in index.php in Scribe 0.2 allows remote attackers to read arbitrary local files via a
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.