Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.475 exploits
Exploit-DB✓ VexDay Proof
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit)
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗Exploit-DB
Joomla! Component jDownloads 3.2.58 - Cross Site Scripting
The jDownloads extension before 3.2.59 for Joomla! has XSS.
23RISCO
abrir ↗Exploit-DB
Brave Browser < 0.13.0 - 'long alert() argument' Denial of Service
Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ultra MiniHTTPd 1.2 - 'GET' Remote Stack Buffer Overflow (PoC)
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQuerySystemInformation (SystemPageFileInformation(Ex))' Kernel 64-bit Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryAttributesFile' Kernel Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryInformationProcess (ProcessImageFileName)' Kernel 64-bit Pool/Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryVolumeInformationFile' Kernel Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryVirtualMemory (MemoryImageInformation)' Kernel 64-bit Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir ↗Exploit-DB
Sophos Cyberoam UTM CR25iNG - 10.6.3 MR-5 - Direct Object Reference
Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via dir
23RISCO
abrir ↗Exploit-DB
CloudMe Sync 1.11.0 - Local Buffer Overflow
An issue was discovered in CloudMe 1.11.0. An unauthenticated local attacker that can connect to the "CloudMe Sync" clie
23RISCO
abrir ↗Exploit-DB
Cobub Razor 0.8.0 - SQL injection
A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryFullAttributesFile' Kernel Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryVirtualMemory (Memory(Privileged)BasicInformation)' Kernel 64-bit Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'CiSetFileCache' TOCTOU Incomplete Fix
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryInformationTransactionManager (TransactionManagerRecoveryInformation)' Kernel Pool Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir ↗Exploit-DB
AMD Plays.tv 1.27.5.0 - 'plays_service.exe' Arbitrary File Execution
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC)
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗Exploit-DB
Microsoft Credential Security Support Provider - Remote Code Execution
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 S
45RISCO
abrir ↗Exploit-DB
MikroTik 6.41.4 - FTP daemon Denial of Service (PoC)
A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU a
28RISCO
abrir ↗Exploit-DB
Joomla! Convert Forms version 2.0.3 - Formula Injection (CSV Injection)
The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that
23RISCO
abrir ↗Exploit-DB
WordPress Plugin File Upload 4.3.2 - Stored Cross-Site Scripting
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
23RISCO
abrir ↗Exploit-DB
DVD X Player Standard 5.5.3.9 - Buffer Overflow
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RISCO
abrir ↗Exploit-DB
iScripts Easycreate 3.2.1 - Stored Cross-Site Scripting
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field.
23RISCO
abrir ↗Exploit-DB
Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Control
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection A
50RISCO
abrir ↗Exploit-DB
WordPress Plugin Activity Log 2.4.0 - Stored Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote a
23RISCO
abrir ↗Exploit-DB
iScripts Easycreate 3.2.1 - Stored Cross-Site Scripting
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.
23RISCO
abrir ↗Exploit-DB
WUZHI CMS 4.1.0 - Cross-Site Request Forgery (Add Admin)
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=
23RISCO
abrir ↗Exploit-DB
WordPress Plugin File Upload 4.3.3 - Stored Cross-Site Scripting (PoC)
The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.