Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.432exploits catalogados
34.424CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.493GitHub PoC 13.618VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB
WordPress Plugin WP Symposium 15.1 - '&show=' SQL Injection
SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to
23RISCO
abrir ↗Exploit-DB
WordPress Plugin WP Membership 1.2.3 - Multiple Vulnerabilities
The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an i
23RISCO
abrir ↗Exploit-DB
WordPress Plugin WP Membership 1.2.3 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authent
23RISCO
abrir ↗Exploit-DB
Comodo GeekBuddy < 4.18.121 - Local Privilege Escalation
Comodo GeekBuddy before 4.18.121 does not restrict access to the VNC server, which allows local users to gain privileges
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin FeedWordPress 2015.0426 - SQL Injection
SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for W
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Phoenix Contact ILC 150 ETH PLC - Remote Control Script
Phoenix Contact Software ProConOs and MultiProg Missing Authentication for Critical Function
85RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 8.0/8.1 (x64) - 'TrackPopupMenu' Local Privilege Escalation (MS14-058)
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RISCO
abrir ↗Exploit-DB
BulletProof FTP Client 2010 - Local Buffer Overflow (DEP Bypass)
Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB
ElasticSearch < 1.4.5 / < 1.5.2 - Directory Traversal
Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, a
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RISCO
abrir ↗Exploit-DB
QEMU - Floppy Disk Controller (FDC) (PoC)
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RISCO
abrir ↗Exploit-DB
Microsoft Windows - 'CNG.SYS' Kernel Security Feature Bypass (MS15-052)
The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not pr
23RISCO
abrir ↗Exploit-DB
Burning Board < 2.3.1 - SQL Injection
SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attacker
23RISCO
abrir ↗Exploit-DB
D-Link DSL-500B Gen 2 - Parental Control Configuration Panel Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated use
75RISCO
abrir ↗Exploit-DB
D-Link DSL-500B Gen 2 - URL Filter Configuration Panel Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated use
75RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - NetConnection Type Confusion (Metasploit)
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451
60RISCO
abrir ↗Exploit-DB
Syncrify Server 3.6 Build 833 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Sy
23RISCO
abrir ↗Exploit-DB
SynTail 1.5 Build 566 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Sy
23RISCO
abrir ↗Exploit-DB
Xeams 4.5 Build 5755 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies Xeams 4.5 Build 5755 and earlier
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - domainMemory ByteArray Use-After-Free (Metasploit)
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and
60RISCO
abrir ↗Exploit-DB
SynaMan 3.4 Build 1436 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Sy
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin RevSlider 3.0.95 - Arbitrary File Upload / Execution (Metasploit)
The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell ZENworks Configuration Management - Arbitrary File Upload (Metasploit)
Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11
60RISCO
abrir ↗Exploit-DB
IBM Websphere Portal - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 C
23RISCO
abrir ↗Exploit-DB
Dell SonicWALL Secure Remote Access (SRA) Appliance - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.