Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.475 exploits
Exploit-DB
WSO2 Carbon / WSO2 Dashboard Server 5.3.0 - Persistent Cross-Site Scripting
WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
35RISCO
abrir ↗Exploit-DB
Microsoft Windows - Local Privilege Escalation
The Windows kernel in Windows 7 SP1 and Windows Server 2008 R2 SP1 allows an elevation of privilege vulnerability due to
23RISCO
abrir ↗Exploit-DB
VLC Media Player/Kodi/PopcornTime 'Red Chimera' < 2.2.5 - Memory Corruption (PoC)
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an inpu
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Overflow when Playing Sound
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Successful exploitat
28RISCO
abrir ↗Exploit-DB
Ericsson-LG iPECS NMS A.1Ac - Cleartext Credential Disclosure
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and th
23RISCO
abrir ↗Exploit-DB
Easy File Sharing Web Server 7.2 - 'UserID' Remote Buffer Overflow (DEP Bypass)
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RISCO
abrir ↗Exploit-DB
Open-AudIT 2.1 - CSV Macro Injection
Open-AudIT before 2.2 has CSV Injection.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ASUS infosvr - Authentication Bypass Command Execution (Metasploit)
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Overflow in Slab Rendering
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exp
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Info Leak in Image Inflation
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful expl
28RISCO
abrir ↗Exploit-DB
phpMyAdmin 4.8.0 < 4.8.0-1 - Cross-Site Request Forgery
phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_ope
23RISCO
abrir ↗Exploit-DB
PRTG Network Monitor < 18.1.39.1648 - Stack Overflow (Denial of Service)
Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.
23RISCO
abrir ↗Exploit-DB
Monstra cms 3.0.4 - Persitent Cross-Site Scripting
Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload
23RISCO
abrir ↗Exploit-DB
Drupal avatar_uploader v7.x-1.0-beta8 - Arbitrary File Disclosure
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
50RISCO
abrir ↗Exploit-DB
Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISCO
abrir ↗Exploit-DB
Ncomputing vSpace Pro 10/11 - Directory Traversal
An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible t
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Weblogic Server 10.3.6.0 / 12.1.3.0 / 12.2.1.2 / 12.2.1.3 - Deserialization Remote Command Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir ↗Exploit-DB
Cobub Razor 0.8.0 - Physical Path Leakage
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/ma
28RISCO
abrir ↗Exploit-DB
Cobub Razor 0.8.0 - Physical Path Leakage
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, contro
50RISCO
abrir ↗Exploit-DB
Kodi 17.6 - Persistent Cross-Site Scripting
A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/s
35RISCO
abrir ↗Exploit-DB
Geist WatchDog Console 3.2.2 - Multiple Vulnerabilities
Geist WatchDog Console 3.2.2 uses a weak ACL for the C:\ProgramData\WatchDog Console directory, which allows local users
23RISCO
abrir ↗Exploit-DB
Geist WatchDog Console 3.2.2 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to i
23RISCO
abrir ↗Exploit-DB
Lutron Quantum 2.0 - 3.2.243 - Information Disclosure
Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing th
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Match Clone Script 1.0.4 - Cross-Site Scripting
PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" sc
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Caldera Forms 1.5.9.1 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow re
23RISCO
abrir ↗Exploit-DB
Geist WatchDog Console 3.2.2 - Multiple Vulnerabilities
XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to re
23RISCO
abrir ↗Exploit-DB
Easy File Sharing Web Server 7.2 - Stack Buffer Overflow
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RISCO
abrir ↗Exploit-DB
Brave Browser < 0.13.0 - 'long alert() argument' Denial of Service
Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ultra MiniHTTPd 1.2 - 'GET' Remote Stack Buffer Overflow (PoC)
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.