Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.432exploits catalogados
34.424CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.493GitHub PoC 13.618VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB
Cyberoam Firewall CR500iNG-XP 10.6.2 MR-1 - Blind SQL Injection
SQL injection vulnerability in the Sophos Cyberoam CR500iNG-XP firewall appliance with CyberoamOS 10.6.2 MR-1 and earlie
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Entitlements - 'Rootpipe' Local Privilege Escalation (Metasploit)
Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allow
38RISCO
abrir ↗Exploit-DB
Ganglia Web Frontend < 3.5.1 - PHP Code Execution
Unspecified vulnerability in Ganglia Web before 3.5.1 allows remote attackers to execute arbitrary PHP code via unknown
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Boxoft WAV to MP3 Converter - 'convert' Local Buffer Overflow
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PCMan FTP Server 2.0.7 - 'RENAME' Remote Buffer Overflow
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISCO
abrir ↗Exploit-DB
Wolf CMS - Arbitrary File Upload / Execution
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/
28RISCO
abrir ↗Exploit-DB
Wolf CMS - Arbitrary File Upload / Execution
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle GlassFish Server 4.1 - Directory Traversal
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
QEMU - Programmable Interrupt Timer Controller Heap Overflow
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read
23RISCO
abrir ↗Exploit-DB
Invision Power Board (IP.Board) 4.x - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB,
23RISCO
abrir ↗Exploit-DB
Magento eCommerce - Remote Code Execution
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RISCO
abrir ↗Exploit-DB
Linux Kernel < 3.5.0-23 (Ubuntu 12.04.2 x64) - 'SOCK_DIAG' SMEP Bypass Local Privilege Escalation
Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows l
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2007 - Malformed Document Stack Buffer Overflow
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Server 2010, Web Applica
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin 3.6.0 < 4.2.3 - 'ForumRunner' SQL Injection
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 bef
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2007 - OneTableDocumentStream Invalid Object
Microsoft Word 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruptio
35RISCO
abrir ↗Exploit-DB
Pligg CMS 2.0.2 - Cross-Site Request Forgery (Add Admin)
Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - 'pdf.js' Privileged JavaScript Injection (Metasploit)
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - 'pdf.js' Privileged JavaScript Injection (Metasploit)
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource
50RISCO
abrir ↗Exploit-DB
Netsweeper 4.0.4 - SQL Injection
SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1
23RISCO
abrir ↗Exploit-DB
WordPress Plugin MDC Private Message 1.0.0 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the MDC Private Message plugin 1.0.0 for WordPress allows remote authenticat
23RISCO
abrir ↗Exploit-DB
Netsweeper 3.0.6 - Authentication Bypass
Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla - Maintenance Service Log File Overwrite Privilege Escalation
Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Win
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2007 - 'OGL.dll' DpOutputSpanStretch::OutputSpan Out of Bounds Write (MS15-080)
Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lyn
28RISCO
abrir ↗Exploit-DB
Netsweeper 4.0.8 - Arbitrary File Upload / Execution
Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'ATMFD.DLL' Out-of-Bounds Read Due to Malformed Name INDEX in the CFF Table
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'ATMFD.DLL' Write to Uninitialized Address Due to Malformed CFF Table
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2007 - 'wwlib.dll' Type Confusion (MS15-081)
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, and Office for Mac 2011 allow remote attackers to execute arbit
28RISCO
abrir ↗Exploit-DB
Netsweeper 4.0.8 - SQL Injection / Authentication Bypass
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass aut
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2007 - 'mso.dll' Arbitrary Free (MS15-081)
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office for Mac 2011, Office fo
28RISCO
abrir ↗Exploit-DB
Netsweeper 4.0.8 - Authentication Bypass (via New Profile Creation)
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote att
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.