Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.432exploits catalogados
34.424CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.493GitHub PoC 13.618VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
50RISCO
abrir ↗Exploit-DB
WordPress Plugin WP Symposium 15.1 - 'get_album_item.php' SQL Injection
SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbi
60RISCO
abrir ↗Exploit-DB
Cisco Unified Communications Manager - Multiple Vulnerabilities
Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manage
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers t
50RISCO
abrir ↗Exploit-DB
Cisco Unified Communications Manager - Multiple Vulnerabilities
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows HTA (HTML Application) - Remote Code Execution (MS14-064)
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5
60RISCO
abrir ↗Exploit-DB
Mozilla Firefox < 39.03 - 'pdf.js' Same Origin Policy
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
98RISCO
abrir ↗Exploit-DB
Zend Framework 2.4.2 - PHP FPM XML eXternal Entity Injection
The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x befor
23RISCO
abrir ↗Exploit-DB
Google Chrome 43.0 - Certificate MIME Handling Integer Overflow
Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a denial of service o
23RISCO
abrir ↗Exploit-DB
Microsoft Windows 8.1 - DCOM DCE/RPC Local NTLM Reflection Privilege Escalation (MS15-076)
The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP
23RISCO
abrir ↗Exploit-DB
Microsoft Internet Explorer - CTreeNode::GetCascadedLang Use-After-Free (MS15-079)
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RISCO
abrir ↗Exploit-DB
Microsoft Windows Server 2003 SP2 - TCP/IP IOCTL Privilege Escalation (MS14-070)
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RISCO
abrir ↗Exploit-DB
Dell Netvault Backup 10.0.1.24 - Denial of Service
Dell Netvault Backup before 10.0.5 allows remote attackers to cause a denial of service (crash) via a crafted request.
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Job Manager 0.7.22 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Job Manager plugin 0.7.22 and earlier for WordPress allows remote attack
23RISCO
abrir ↗Exploit-DB
Microsoft Windows XP SP3 (x86) / 2003 SP2 (x86) - 'NDProxy' Local Privilege Escalation (MS14-002)
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges
98RISCO
abrir ↗Exploit-DB
ISC BIND 9 - TKEY Remote Denial of Service (PoC)
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISCO
abrir ↗Exploit-DB
Linux Kernel - 'espfix64' Nested NMIs Interrupting Privilege Escalation
arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform improperly relies on espfix64 during n
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ISC BIND 9 - TKEY (PoC)
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sudo 1.8.14 (RHEL 5/6/7 / Ubuntu) - 'Sudoedit' Unauthorized Privilege Escalation
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is d
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Libuser Library - Multiple Vulnerabilities
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
38RISCO
abrir ↗Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Count Per Day 3.4 - SQL Injection
SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote
23RISCO
abrir ↗Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attack
43RISCO
abrir ↗Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sit
38RISCO
abrir ↗Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers t
28RISCO
abrir ↗Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
Multiple hardcoded credentials in Xsuite 2.x.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Libuser Library - Multiple Vulnerabilities
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RISCO
abrir ↗Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the sy
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.