Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8.176Nuclei 4.202Metasploit 3.462✓ só verificadosrecentespopularesrisco
22.786 exploits
Exploit-DB
WildMIDI 0.4.2 - Multiple Vulnerabilities
The _WM_SetupMidiEvent function in internal_midi.c:2122 in WildMIDI 0.4.2 can cause a denial of service (invalid memory
23RISCO
abrir ↗Exploit-DB
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 all
28RISCO
abrir ↗Exploit-DB
WildMIDI 0.4.2 - Multiple Vulnerabilities
The _WM_SetupMidiEvent function in internal_midi.c:2318 in WildMIDI 0.4.2 can cause a denial of service (invalid memory
28RISCO
abrir ↗Exploit-DB
WildMIDI 0.4.2 - Multiple Vulnerabilities
The _WM_ParseNewMidi function in f_midi.c in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and appli
23RISCO
abrir ↗Exploit-DB
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-296
28RISCO
abrir ↗Exploit-DB
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remot
35RISCO
abrir ↗Exploit-DB
VMware WorkStation 12.5.5 - Virtual Machine Escape
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 ha
28RISCO
abrir ↗Exploit-DB
Unitrends UEB 9.1 - Authentication Bypass / Remote Command Execution
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RISCO
abrir ↗Exploit-DB
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allo
28RISCO
abrir ↗Exploit-DB
Unitrends UEB 9.1 - 'Unitrends bpserverd' Remote Command Execution
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xin
50RISCO
abrir ↗Exploit-DB
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers
28RISCO
abrir ↗Exploit-DB
Unitrends UEB 9.1 - Privilege Escalation
It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR env
28RISCO
abrir ↗Exploit-DB
WildMIDI 0.4.2 - Multiple Vulnerabilities
The _WM_SetupMidiEvent function in internal_midi.c:2315 in WildMIDI 0.4.2 can cause a denial of service (invalid memory
23RISCO
abrir ↗Exploit-DB
Microsoft Windows - '.LNK' Shortcut File Code Execution
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISCO
abrir ↗Exploit-DB
Tiandy IP Cameras 5.56.17.120 - Sensitive Information Disclosure
Tiandy IP cameras 5.56.17.120 do not properly restrict a certain proprietary protocol, which allows remote attackers to
23RISCO
abrir ↗Exploit-DB
VirtualBox 5.1.22 - Windows Process DLL Signature Bypass Privilege Escalation
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RISCO
abrir ↗Exploit-DB
DNSTracer 1.9 - Local Buffer Overflow
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RISCO
abrir ↗Exploit-DB
VirtualBox 5.1.22 - Windows Process DLL UNC Path Signature Bypass Privilege Escalation
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RISCO
abrir ↗Exploit-DB
Technicolor TC7337 - 'SSID' Persistent Cross-Site Scripting
Persistent XSS through the SSID of nearby Wi-Fi devices on Technicolor TC7337 routers 08.89.17.20.00 allows an attacker
23RISCO
abrir ↗Exploit-DB
Horde Groupware 5.2.21 - Unauthorized File Download
The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication
23RISCO
abrir ↗Exploit-DB
Nitro Pro PDF Reader 11.0.3.173 - Javascript API Code Execution (Metasploit)
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory tra
50RISCO
abrir ↗Exploit-DB
libmad 0.15.1b - 'mp3' Memory Corruption
mpg321.c in mpg321 0.3.2-1 does not properly manage memory for use with libmad 0.15.1b, which allows remote attackers to
23RISCO
abrir ↗Exploit-DB
SOL.Connect ISET-mpp meter 1.2.4.2 - SQL Injection
SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitra
23RISCO
abrir ↗Exploit-DB
Advantech SUSIAccess < 3.0 - Directory Traversal / Information Disclosure (Metasploit)
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system
23RISCO
abrir ↗Exploit-DB
Advantech SUSIAccess < 3.0 - 'RecoveryMgmt' File Upload
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system
23RISCO
abrir ↗Exploit-DB
Advantech SUSIAccess < 3.0 - 'RecoveryMgmt' File Upload
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error
23RISCO
abrir ↗Exploit-DB
Apple macOS/iOS - 'xpc_data' Objects Sandbox Escape Privilege Escalation
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS
23RISCO
abrir ↗Exploit-DB
Sound eXchange (SoX) 14.4.2 - Multiple Vulnerabilities
The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (div
23RISCO
abrir ↗Exploit-DB
Sound eXchange (SoX) 14.4.2 - Multiple Vulnerabilities
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (d
23RISCO
abrir ↗Exploit-DB
libao 1.2.0 - Denial of Service
The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of servic
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.