Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.475 exploits
Exploit-DB
Yahei PHP Prober 0.4.7 - Cross-Site Scripting
proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.
23RISCO
abrir ↗Exploit-DB
WolfCMS 0.8.3.1 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - WebAssembly Parsing Does not Correctly Check Section Order
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RISCO
abrir ↗Exploit-DB
WolfCMS 0.8.3.1 - Open Redirection
Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attack
23RISCO
abrir ↗Exploit-DB
Cobub Razor 0.7.2 - Add New Superuser Account
An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/install/inst
28RISCO
abrir ↗Exploit-DB
iScripts SonicBB 1.0 - Reflected Cross-Site Scripting (PoC)
iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Background Takeover < 4.1.4 - Directory Traversal
exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Direct
50RISCO
abrir ↗Exploit-DB
CyberArk Password Vault < 9.7 / < 10 - Memory Disclosure
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay
28RISCO
abrir ↗Exploit-DB
CyberArk Password Vault Web Access < 9.9.5 / < 9.10 / 10.1 - Remote Code Execution
The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute
28RISCO
abrir ↗Exploit-DB
Sophos Endpoint Protection Control Panel 10.7 - Weak Password Encryption
Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Vir
23RISCO
abrir ↗Exploit-DB
Sophos Endpoint Protection 10.7 - Tamper-Protection Bypass
Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKE
23RISCO
abrir ↗Exploit-DB
DotNetNuke DNNarticle Module 11 - Directory Traversal
The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and conseque
35RISCO
abrir ↗Exploit-DB
GNU Beep 1.3 - 'HoleyBeep' Local Privilege Escalation
Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.
23RISCO
abrir ↗Exploit-DB
Adobe Flash < 28.0.0.161 - Use-After-Free
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cobub Razor 0.7.2 - Cross-Site Request Forgery
An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/chann
23RISCO
abrir ↗Exploit-DB
LineageOS 14.1 Blueborne - Remote Code Execution
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RISCO
abrir ↗Exploit-DB
FiberHome VDSL2 Modem HG 150-UB - Authentication Bypass
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
28RISCO
abrir ↗Exploit-DB
WordPress Plugin Activity Log 2.4.0 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote a
23RISCO
abrir ↗Exploit-DB
Joomla! Component JS Jobs 1.2.0 - Cross-Site Scripting
The Joom Sky JS Jobs extension before 1.2.1 for Joomla! has XSS.
23RISCO
abrir ↗Exploit-DB
Z-Blog 1.5.1.1740 - Full Path Disclosure
In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.ph
23RISCO
abrir ↗Exploit-DB
Z-Blog 1.5.1.1740 - Cross-Site Scripting
In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the so
23RISCO
abrir ↗Exploit-DB
WebRTC - Private IP Leakage (Metasploit)
In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client informati
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Multiple Use-After-Free Issues in jscript Array Methods
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
35RISCO
abrir ↗Exploit-DB
YzmCMS 3.6 - Cross-Site Scripting
In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Defender - 'mpengine.dll' Memory Corruption
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a speci
35RISCO
abrir ↗Exploit-DB
GetSimple CMS 3.3.13 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows rem
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Stack-to-Heap Copy (Incomplete Fix) (2)
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution,
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Stack-to-Heap Copy (Incomplete Fix) (1)
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution,
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome V8 - 'ElementsAccessorBase::CollectValuesOrEntriesImpl' Type Confusion
Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Stack-to-Heap Copy (Incomplete Fix) (1)
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution,
35RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.