Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8.176Nuclei 4.202Metasploit 3.462✓ só verificadosrecentespopularesrisco
3.462 exploits
Metasploit300
Cyrus IMAPD pop3d popsubfolders USER Buffer Overflow
Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allow
50RISCO
abrir ↗Metasploit300
RealVNC NULL Authentication Mode Bypass
RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers t
60RISCO
abrir ↗Metasploit200
FreeFTPd 1.0.10 Key Exchange Algorithm String Buffer Overflow
Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other produc
60RISCO
abrir ↗Metasploit200
FreeSSHd 1.0.9 Key Exchange Algorithm String Buffer Overflow
Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other produc
60RISCO
abrir ↗Metasploit600
AWStats migrate Remote Command Execution
The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbit
50RISCO
abrir ↗Metasploit300
Oracle DB SQL Injection via DBMS_EXPORT_EXTENSION
Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via the GET_DOMAIN_INDEX_METADA
43RISCO
abrir ↗Metasploit300
Juniper SSL-VPN IVE JuniperSetupDLL.dll ActiveX Control Buffer Overflow
Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juni
50RISCO
abrir ↗Metasploit200
Novell Messenger Server 2.0 Accept-Language Overflow
Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute ar
60RISCO
abrir ↗Metasploit600
MS06-014 Microsoft Internet Explorer COM CreateObject Code Execution
Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScript
50RISCO
abrir ↗Metasploit600
MS06-014 Microsoft Internet Explorer COM CreateObject Code Execution
Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and dis
60RISCO
abrir ↗Metasploit300
UltraVNC 1.0.1 Client Buffer Overflow
Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-ass
50RISCO
abrir ↗Metasploit600
PAJAX Remote Command Execution
Eval injection vulnerability in pajax_call_dispatcher.php in PAJAX 0.5.1 and earlier allows remote attackers to execute
50RISCO
abrir ↗Metasploit300
MS06-013 Microsoft Internet Explorer createTextRange() Code Execution
Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arb
50RISCO
abrir ↗Metasploit200
Mercur v5.0 IMAP SP3 SELECT Buffer Overflow
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause
50RISCO
abrir ↗Metasploit200
Mercur Messaging 2005 IMAP Login Buffer Overflow
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause
50RISCO
abrir ↗Metasploit200
PeerCast URL Handling Buffer Overflow
Multiple stack-based buffer overflows in the procConnectArgs function in servmgr.cpp in PeerCast before 0.1217 allow rem
60RISCO
abrir ↗Metasploit200
PeerCast URL Handling Buffer Overflow
Multiple stack-based buffer overflows in the procConnectArgs function in servmgr.cpp in PeerCast before 0.1217 allow rem
60RISCO
abrir ↗Metasploit0
Mail.app Image Attachment Command Execution
The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an
50RISCO
abrir ↗Metasploit0
Mail.app Image Attachment Command Execution
Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDoub
50RISCO
abrir ↗Metasploit300
Microsoft Internet Explorer isComponentInstalled Overflow
Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Win
50RISCO
abrir ↗Metasploit600
Safari Archive Metadata Command Execution
The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to ex
50RISCO
abrir ↗Metasploit200
Bomberclone 0.11.6 Buffer Overflow
Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error
50RISCO
abrir ↗Metasploit400
HTML Help Workshop 4.74 (hhp Project File) Buffer Overflow
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISCO
abrir ↗Metasploit400
HTML Help Workshop 4.74 (hhp Project File) Buffer Overflow
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISCO
abrir ↗Metasploit300
Firefox location.QueryInterface() Code Execution
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attac
60RISCO
abrir ↗Metasploit500
Winamp Playlist UNC Path Computer Name Overflow
Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with
60RISCO
abrir ↗Metasploit300
KarjaSoft Sami FTP Server v2.0.2 USER Overflow
Buffer overflow in KarjaSoft Sami FTP Server 2.0.2 and earlier allows remote attackers to execute arbitrary code via a l
50RISCO
abrir ↗Metasploit300
KarjaSoft Sami FTP Server v2.0.2 USER Overflow
Stack-based buffer overflow in Sami FTP Server 2.0.1 allows remote attackers to execute arbitrary code via a long USER c
60RISCO
abrir ↗Metasploit500
Windows XP/2003/Vista Metafile Escape() SetAbortProc Code Execution
The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbit
60RISCO
abrir ↗Metasploit500
Qualcomm WorldMail 3.0 IMAPD LIST Buffer Overflow
Stack-based buffer overflow in Qualcomm WorldMail 3.0 allows remote attackers to execute arbitrary code via a long IMAP
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.