Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8.176Nuclei 4.202Metasploit 3.462✓ só verificadosrecentespopularesrisco
22.786 exploits
Exploit-DB
Microsoft Internet Explorer 11 (Windows 7 x86) - 'mshtml.dll' Remote Code Execution (MS17-007)
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilde
93RISCO
abrir ↗Exploit-DB
Microsoft Internet Explorer 11 (Windows 7 x86) - 'mshtml.dll' Remote Code Execution (MS17-007)
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via
75RISCO
abrir ↗Exploit-DB
3CX Phone System 15.5.3554.1 - Directory Traversal
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory t
23RISCO
abrir ↗Exploit-DB
Linux Kernel < 3.16.39 (Debian 8 x64) - 'inotfiy' Local Privilege Escalation
Race condition in the fsnotify implementation in the Linux kernel through 4.12.4 allows local users to gain privileges o
23RISCO
abrir ↗Exploit-DB
Ikraus Anti Virus 2.16.7 - Remote Code Execution
An active network attacker (MiTM) can achieve remote code execution on a machine that runs IKARUS Anti Virus 2.16.7. IKA
23RISCO
abrir ↗Exploit-DB
Webmin 1.850 - Multiple Vulnerabilities
SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/h
23RISCO
abrir ↗Exploit-DB
Webmin 1.850 - Multiple Vulnerabilities
Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Down
23RISCO
abrir ↗Exploit-DB
Webmin 1.850 - Multiple Vulnerabilities
CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker
23RISCO
abrir ↗Exploit-DB
Logitech Media Server - Cross-Site Scripting
DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1
23RISCO
abrir ↗Exploit-DB
phpMyFAQ 2.9.8 - Cross-Site Scripting (2)
Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web scrip
23RISCO
abrir ↗Exploit-DB
FiberHome - Directory Traversal
On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a cra
43RISCO
abrir ↗Exploit-DB
AlienVault Unified Security Management (USM) 5.4.2 - Cross-Site Request Forgery
AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/
23RISCO
abrir ↗Exploit-DB
Dreambox Plugin BouquetEditor - Cross-Site Scripting
There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouq
38RISCO
abrir ↗Exploit-DB
TP-Link TL-MR3220 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows
23RISCO
abrir ↗Exploit-DB
OctoberCMS 1.0.425 (Build 425) - Cross-Site Scripting
Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG fil
23RISCO
abrir ↗Exploit-DB
ASX to MP3 3.1.3.7 - '.m3u' Local Buffer Overflow
ASX to MP3 converter 3.1.3.7.2010.11.05 has a buffer overflow via a crafted M3U file, a related issue to CVE-2009-1324.
23RISCO
abrir ↗Exploit-DB
Trend Micro OfficeScan 11.0/XG (12.0) - Remote Code Execution (Metasploit)
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitr
50RISCO
abrir ↗Exploit-DB
binutils 2.29.51.20170921 - 'read_1_byte' Heap Buffer Overflow
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.
23RISCO
abrir ↗Exploit-DB
QNAP HelpDesk < 1.1.12 - SQL Injection
QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection
23RISCO
abrir ↗Exploit-DB
PHP Melody 2.7.3 - Multiple Vulnerabilities
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.
23RISCO
abrir ↗Exploit-DB
VX Search Enterprise 10.1.12 - Remote Buffer Overflow
Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginni
23RISCO
abrir ↗Exploit-DB
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (2)
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISCO
abrir ↗Exploit-DB
PHP Melody 2.7.3 - Multiple Vulnerabilities
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.
23RISCO
abrir ↗Exploit-DB
PyroBatchFTP 3.17 - Buffer Overflow (SEH)
EmTec PyroBatchFTP before 3.18 allows remote servers to cause a denial of service (application crash).
23RISCO
abrir ↗Exploit-DB
Microsoft Windows 10 RS2 (x64) - 'win32kfull!bFill' Pool Overflow
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1;
76RISCO
abrir ↗Exploit-DB
WebKit JSC - 'BytecodeGenerator::emitGetByVal' Incorrect Optimization (2)
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
28RISCO
abrir ↗Exploit-DB
Webkit (Safari) - Universal Cross-site Scripting
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
23RISCO
abrir ↗Exploit-DB
EPESI 1.8.2 rev20170830 - Cross-Site Scripting
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.
23RISCO
abrir ↗Exploit-DB
EPESI 1.8.2 rev20170830 - Cross-Site Scripting
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.
23RISCO
abrir ↗Exploit-DB
Webkit (Chome < 61) - 'MHTML' Universal Cross-site Scripting
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.