Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.941exploits catalogados
32.192CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.297VulnCheck XDB 8.176Nuclei 4.217Metasploit 3.462✓ só verificadosrecentespopularesrisco
22.786 exploits
Exploit-DB
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclosure
XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380h
23RISCO
abrir ↗Exploit-DB
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclosure
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before f
23RISCO
abrir ↗Exploit-DB
Apache Struts - REST Plugin With Dynamic Method Invocation Remote Code Execution
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RISCO
abrir ↗Exploit-DB
Apple Safari 10.1 - Spread Operator Integer Overflow Remote Code Execution
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
28RISCO
abrir ↗Exploit-DB
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclosure
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw
50RISCO
abrir ↗Exploit-DB
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclosure
Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b30
23RISCO
abrir ↗Exploit-DB
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclosure
CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_
23RISCO
abrir ↗Exploit-DB
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclosure
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-
23RISCO
abrir ↗Exploit-DB
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclosure
XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_38
23RISCO
abrir ↗Exploit-DB
Subsonic 6.1.1 - Server-Side Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attacke
23RISCO
abrir ↗Exploit-DB
Wireshark 2.2.6 - IPv6 Dissector Denial of Service
In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by vali
28RISCO
abrir ↗Exploit-DB
DNSTracer 1.8.1 - Buffer Overflow (PoC)
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RISCO
abrir ↗Exploit-DB
BIND 9.10.5 - Unquoted Service Path Privilege Escalation
Windows service and uninstall paths are not quoted when BIND is installed
41RISCO
abrir ↗Exploit-DB
Subsonic 6.1.1 - Cross-Site Request Forgery / Cross-Site Scripting
Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote atta
28RISCO
abrir ↗Exploit-DB
Subsonic 6.1.1 - XML External Entity Injection
XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to
28RISCO
abrir ↗Exploit-DB
Wireshark 2.2.0 < 2.2.12 - ROS Dissector Denial of Service
In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/d
28RISCO
abrir ↗Exploit-DB
Subsonic 6.1.1 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target u
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Event List < 0.7.8 - SQL Injection
SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitra
23RISCO
abrir ↗Exploit-DB
WordPress Plugin WP-Testimonials < 3.4.1 - SQL Injection
SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute ar
23RISCO
abrir ↗Exploit-DB
HPE Intelligent Management Center (iMC) 7.2 (E0403P10) - Code Execution
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
35RISCO
abrir ↗Exploit-DB
Sungard eTRAKiT3 <= 3.2.1.17 - SQL Injection
The Sungard eTRAKiT3 software version 3.2.1.17 may be vulnerable to SQL injection which may allow a remote unauthenticated attacker to run a subset of SQL commands against the back-end database
28RISCO
abrir ↗Exploit-DB
WebKit - CachedFrame does not Detach Openers Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RISCO
abrir ↗Exploit-DB
WebKit JSC - 'JSObject::ensureLength' ensureLengthSlow Check Failure
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RISCO
abrir ↗Exploit-DB
WebKit JSC - Incorrect Check in emitPutDerivedConstructorToArrowFunctionContextScope
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RISCO
abrir ↗Exploit-DB
IBM Informix Dynamic Server / Informix Open Admin Tool - DLL Injection / Remote Code Execution / Heap Buffer Overflow
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system a
60RISCO
abrir ↗Exploit-DB
Microsoft MsMpEng - Use-After-Free via Saved Callers
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
35RISCO
abrir ↗Exploit-DB
Microsoft MsMpEng - Remote Use-After-Free Due to Design Issue in GC Engine
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
93RISCO
abrir ↗Exploit-DB
Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RISCO
abrir ↗Exploit-DB
Samba 3.5.0 < 4.4.14/4.5.10/4.6.4 - 'is_known_pipename()' Arbitrary Module Load (Metasploit)
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir ↗Exploit-DB
Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.