Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.476 exploits
Exploit-DB
Hotspot Shield - Information Disclosure
Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sen
28RISCO
abrir ↗Exploit-DB
systemd (systemd-tmpfiles) < 236 - 'fs.protected_hardlinks=0' Local Privilege Escalation
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle WebLogic - wls-wsat Component Deserialization Remote Code Execution (Metasploit)
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
macOS - 'sysctl_vfs_generic_conf' Stack Leak Through Struct Padding
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS
23RISCO
abrir ↗Exploit-DB
iBall WRA150N - Multiple Vulnerabilities
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands
23RISCO
abrir ↗Exploit-DB
Arq 5.10 - Local Privilege Escalation (1)
The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently g
23RISCO
abrir ↗Exploit-DB
Arq 5.10 - Local Privilege Escalation (2)
The standardrestorer binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequen
23RISCO
abrir ↗Exploit-DB
Task Rabbit Clone 1.0 - 'id' SQL Injection
SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter.
23RISCO
abrir ↗Exploit-DB
Artifex MuJS 1.0.2 - Denial of Service
The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent v
23RISCO
abrir ↗Exploit-DB
Joomla! Component Jtag Members Directory 5.3.7 - Arbitrary File Download
Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter
50RISCO
abrir ↗Exploit-DB
Hot Scripts Clone - 'subctid' SQL Injection
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
23RISCO
abrir ↗Exploit-DB
Multilanguage Real Estate MLM Script 3.0 - 'srch' SQL Injection
SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.
23RISCO
abrir ↗Exploit-DB
KeystoneJS < 4.0.0-beta.7 - Cross-Site Request Forgery
KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureL
23RISCO
abrir ↗Exploit-DB
TSiteBuilder 1.0 - SQL Injection
SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php.
23RISCO
abrir ↗Exploit-DB
Buddy Zone 2.9.9 - SQL Injection
SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parame
23RISCO
abrir ↗Exploit-DB
Joomla! Component JS Support Ticket 1.1.0 - Cross-Site Request Forgery
CSRF exists in the JS Support Ticket 1.1.0 component for Joomla! and allows attackers to inject HTML or edit a ticket.
23RISCO
abrir ↗Exploit-DB
Nexpose < 6.4.66 - Cross-Site Request Forgery
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated A
23RISCO
abrir ↗Exploit-DB
Artifex MuJS 1.0.2 - Integer Overflow
jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows re
23RISCO
abrir ↗Exploit-DB
BMC BladeLogic 8.3.00.64 - Remote Command Execution
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux a
60RISCO
abrir ↗Exploit-DB
BMC BladeLogic 8.3.00.64 - Remote Command Execution
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U
60RISCO
abrir ↗Exploit-DB
Dodocool DC38 N300 - Cross-site Request Forgery
An issue was discovered on DODOCOOL DC38 3-in-1 N300 Mini Wireless Range Extend RTN2-AW.GD.R3465.1.20161103 devices. A C
23RISCO
abrir ↗Exploit-DB
BMC BladeLogic 8.3.00.64 - Remote Command Execution
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote atta
23RISCO
abrir ↗Exploit-DB
Exodus Wallet (ElectronJS Framework) - Remote Code Execution
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro
60RISCO
abrir ↗Exploit-DB
Professional Local Directory Script 1.0 - SQL Injection
SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter,
28RISCO
abrir ↗Exploit-DB
Telerik UI for ASP.NET AJAX 2012.3.1308 < 2017.1.118 - Encryption Keys Disclosure
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISCO
abrir ↗Exploit-DB
Oracle VirtualBox < 5.1.30 / < 5.2-rc1 - Guest to Host Escape
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISCO
abrir ↗Exploit-DB
Telerik UI for ASP.NET AJAX 2012.3.1308 < 2017.1.118 - Arbitrary File Upload
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RISCO
abrir ↗Exploit-DB
Telerik UI for ASP.NET AJAX 2012.3.1308 < 2017.1.118 - Arbitrary File Upload
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which a
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GoAhead Web Server 2.5 < 3.6.5 - HTTPd 'LD_PRELOAD' Arbitrary Module Load (Metasploit)
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Kaltura - Remote PHP Code Execution over Cookie (Metasploit)
The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, wh
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.