Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.032exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.260VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.476 exploits
Exploit-DB
gps-server.net GPS Tracking Software < 3.1 - Multiple Vulnerabilities
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords
23RISCO
abrir ↗Exploit-DB
Gespage 7.4.8 - SQL Injection
Multiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands
28RISCO
abrir ↗Exploit-DB
Cisco IOS - Remote Code Execution
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti
93RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ayukov NFTP FTP Client 2.0 - Remote Buffer Overflow (Metasploit)
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows win32k - Using SetClassLong to Switch Between CS_CLASSDC and CS_OWNDC Corrupts DC Cache
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wi
28RISCO
abrir ↗Exploit-DB
Linksys WVBR0-25 - User-Agent Command Execution (Metasploit)
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authe
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Xplico - Remote Code Execution (Metasploit)
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name
60RISCO
abrir ↗Exploit-DB
Multiple CPUs - 'Spectre' Information Disclosure
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass / SQL Injection
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RISCO
abrir ↗Exploit-DB
EMC xPression 4.5SP1 Patch 13 - 'model.jobHistoryId' SQL Injection
xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL I
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass / SQL Injection
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthentica
35RISCO
abrir ↗Exploit-DB
Multiple CPUs - 'Spectre' Information Disclosure
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle WebLogic < 10.3.6 - 'wls-wsat' Component Deserialisation Remote Command Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cambium ePMP1000 - 'get_chart' Shell via Command Injection (Metasploit)
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP Mercury LoadRunner Agent magentproc.exe - Remote Command Execution (Metasploit)
Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote
60RISCO
abrir ↗Exploit-DB
PHP Melody 2.7.1 - 'playlist' SQL Injection
PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.
23RISCO
abrir ↗Exploit-DB
NetTransport 2.96L - Remote Buffer Overflow (DEP Bypass)
A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remot
50RISCO
abrir ↗Exploit-DB
ALLMediaServer 0.95 - Remote Buffer Overflow (Metasploit)
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SysGauge Server 3.6.18 - Denial of Service
In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafte
23RISCO
abrir ↗Exploit-DB
ALLMediaServer 0.95 - Buffer Overflow (PoC)
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow
50RISCO
abrir ↗Exploit-DB
Joomla! Component JEXTN FAQ Pro 4.0.0 - 'id' SQL Injection
The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.
23RISCO
abrir ↗Exploit-DB
GetGo Download Manager 5.3.0.2712 - Buffer Overflow
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to exec
28RISCO
abrir ↗Exploit-DB
Trustwave SWG 11.8.0.27 - SSH Unauthorized Access
Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the de
28RISCO
abrir ↗Exploit-DB
Biometric Shift Employee Management System 3.0 - Local File Disclosure
Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a u
23RISCO
abrir ↗Exploit-DB
Oracle WebLogic Server 10.3.6.0.0 / 12.x - Remote Command Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗Exploit-DB
Ubiquiti UniFi Video 3.7.3 - Local Privilege Escalation
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local u
23RISCO
abrir ↗Exploit-DB
Huawei Router HG532 - Arbitrary Command Execution
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could se
45RISCO
abrir ↗Exploit-DB
Iopsys Router - 'dhcp' Remote Code Execution
Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying th
28RISCO
abrir ↗Exploit-DB
BEIMS ContractorWeb 5.18.0.0 - SQL Injection
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, ass
23RISCO
abrir ↗Exploit-DB
Ability Mail Server 3.3.2 - Cross-Site Scripting
Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code execute
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.