Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.334VulnCheck XDB 8.195Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
20.023 exploits
Referência
CVE-2018-16299
The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter.
50RISCO
abrir ↗Referência
CVE-2021-40352
OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can re
23RISCO
abrir ↗Referência
CVE-2014-5074
Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device
23RISCO
abrir ↗Referência
XAMPP for Windows 1.6.0a - 'mssql_connect()' Remote Buffer Overflow
The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the
23RISCO
abrir ↗Referência
Google Chrome 0.2.149.27 - A HREF Denial of Service
Stack-based buffer overflow in chrome/common/gfx/url_elider.cc in Google Chrome 0.2.149.27 and other versions before 0.2
23RISCO
abrir ↗Referência
Neostrada Livebox Router - Remote Network Down (PoC)
The Neostrada Livebox ADSL Router allows remote attackers to cause a denial of service (network outage) via multiple HTT
23RISCO
abrir ↗Referência
GNUEDU 1.3b2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in gnuedu 1.3b2 allow remote attackers to execute arbitrary PHP code
23RISCO
abrir ↗Referência
CVE-2018-15576
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited
23RISCO
abrir ↗Referência
CVE-2018-15576
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited
23RISCO
abrir ↗Referência
OpenDock FullCore 4.4 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in OpenDock FullCore 4.4 and earlier allow remote attackers to execut
23RISCO
abrir ↗Referência
CVE-2014-0995
The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of serv
23RISCO
abrir ↗Referência
CVE-2008-3408
Stack-based buffer overflow in CoolPlayer 2.18, and possibly other versions, allows user-assisted remote attackers to ex
23RISCO
abrir ↗Referência
CVE-2017-0259
The Windows kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703,
23RISCO
abrir ↗Referência
Build it Fast (bif3) 0.4.1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Build it Fast (bif3) 0.4.1 allow remote attackers to execute arbit
23RISCO
abrir ↗Referência
AjPortal2Php - 'PagePrefix' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in AjPortal2Php allow remote attackers to execute arbitrary PHP code
23RISCO
abrir ↗Referência
CVE-2020-11699
An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php woul
23RISCO
abrir ↗Referência
CVE-2018-1235
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command inje
35RISCO
abrir ↗Referência
Java SE Runtime Environment JRE 6 Update 13 - Multiple Vulnerabilities
The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 1
23RISCO
abrir ↗Referência
CVE-2019-6716
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 thr
23RISCO
abrir ↗Referência
CVE-2019-6716
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 thr
23RISCO
abrir ↗Referência
CVE-2017-3546
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChann
23RISCO
abrir ↗Referência
CVE-2019-19516
Intelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a pa
23RISCO
abrir ↗Referência
CVE-2016-0145
The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
35RISCO
abrir ↗Referência
CVE-2017-11346
Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors invo
35RISCO
abrir ↗Referência
CVE-2019-19516
Intelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a pa
23RISCO
abrir ↗Referência
CVE-2011-2506
setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restric
23RISCO
abrir ↗Referência
CVE-2012-1011
actions.php in the AllWebMenus plugin 1.1.8 for WordPress allows remote attackers to bypass intended access restrictions
23RISCO
abrir ↗Referência
osTicket 1.12 - Formula Injection
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the ex
23RISCO
abrir ↗Referência
CVE-2012-1661
ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, wh
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.