Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.432exploits catalogados
34.424CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.493GitHub PoC 13.618VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
SysAid Help Desk before 15.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a lar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bonita BPM 6.5.1 - Multiple Vulnerabilities
Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arb
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Milw0rm Clone Script 1.0 - 'related.php?program' Blind SQL Injection
SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Nmedia WordPress Member Conversation 1.35.0 - 'doupload.php' Arbitrary File Upload
Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress
28RISCO
abrir ↗Exploit-DB
WordPress Plugin zM Ajax Login & Register 1.0.9 - Local File Inclusion
Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attack
28RISCO
abrir ↗Exploit-DB
WordPress Plugin zM Ajax Login & Register 1.0.9 - Local File Inclusion
Cross-site scripting (XSS) vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SysAid Help Desk Administrator Portal < 14.4 - Arbitrary File Upload (Metasploit)
Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators t
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Realtek SDK - Miniigd UPnP SOAP Command Execution (Metasploit)
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClien
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
D-Link Devices - HNAP SOAPAction-Header Command Execution (Metasploit)
The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute ar
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Airties - login-cgi Buffer Overflow (Metasploit)
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 502
60RISCO
abrir ↗Exploit-DB
Aruba ClearPass Policy Manager - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote at
23RISCO
abrir ↗Exploit-DB
Peercast < 0.1211 - Format String
Format string vulnerability in PeerCast 0.1211 and earlier allows remote attackers to execute arbitrary code via format
28RISCO
abrir ↗Exploit-DB
WordPress Plugin Free Counter 1.1 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Free Counter plugin 1.1 for WordPress allows remote attackers to inject
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sendio ESP - Information Disclosure
The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to o
23RISCO
abrir ↗Exploit-DB
WordPress Plugin church_admin 0.800 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers t
38RISCO
abrir ↗Exploit-DB
Apache JackRabbit - WebDAV XML External Entity
XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin NewStatPress 0.9.8 - Multiple Vulnerabilities
SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remo
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin NewStatPress 0.9.8 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPres
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sendio ESP - Information Disclosure
Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin GigPress 2.3.8 - SQL Injection
Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow rem
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Landing Pages 1.8.4 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Landing Pages 1.8.4 - Multiple Vulnerabilities
SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allo
23RISCO
abrir ↗Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
28RISCO
abrir ↗Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
23RISCO
abrir ↗Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
28RISCO
abrir ↗Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
The font mapper in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Window
23RISCO
abrir ↗Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in M
23RISCO
abrir ↗Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 R2, and
23RISCO
abrir ↗Exploit-DB
Apport (Ubuntu 14.04/14.10/15.04) - Race Condition Privilege Escalation
Race condition in Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ub
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Fuse 2.9.3-15 - Local Privilege Escalation
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as ro
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.