Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.432exploits catalogados
34.424CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.493GitHub PoC 13.618VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB✓ VexDay Proof
Publish-It - '.PUI' Local Buffer Overflow (SEH) (Metasploit)
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RISCO
abrir ↗Exploit-DB
Citrix Nitro SDK - Command Injection
Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote
23RISCO
abrir ↗Exploit-DB
Citrix Command Center - Credential Disclosure
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Exim - 'GHOST' glibc gethostbyname Buffer Overflow (Metasploit)
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RISCO
abrir ↗Exploit-DB
Websense Appliance Manager - Command Injection
The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Fortinet Single Sign On - Stack Overflow
Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attac
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - PCRE Regex (Metasploit)
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442
60RISCO
abrir ↗Exploit-DB
Moodle 2.5.9/2.6.8/2.7.5/2.8.3 - Block Title Handler Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript-static.js in Moodle through 2.5.9, 2.6.x before 2.
23RISCO
abrir ↗Exploit-DB
WordPress Plugin WPML 3.1.9 - Multiple Vulnerabilities
SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary S
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ElasticSearch - Search Groovy Sandbox Bypass (Metasploit)
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IPass Control Pipe - Remote Command Execution (Metasploit)
The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin SEO by Yoast 1.7.3.3 - Blind SQL Injection
Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin be
23RISCO
abrir ↗Exploit-DB
WordPress Plugin WPML 3.1.9 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject
23RISCO
abrir ↗Exploit-DB
WordPress Plugin WPML 3.1.9 - Multiple Vulnerabilities
The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts
28RISCO
abrir ↗Exploit-DB
Foxit Reader 7.0.6.1126 - Unquoted Service Path Privilege Escalation
Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.
23RISCO
abrir ↗Exploit-DB
Intel Network Adapter Diagnostic Driver - IOCTL Handling
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISCO
abrir ↗Exploit-DB
WoltLab Community Gallery - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to i
23RISCO
abrir ↗Exploit-DB
ArcSight Logger - Arbitrary File Upload / Code Execution
Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated att
28RISCO
abrir ↗Exploit-DB
Citrix Netscaler NS10.5 - WAF Bypass (Via HTTP Header Pollution)
Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restriction
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - ByteArray UncompressViaZlibVariant Use-After-Free (Metasploit)
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Window
100RISCO
abrir ↗Exploit-DB
Ubuntu 15.04 (Development) - 'Upstart' Logrotation Privilege Escalation
The logrotation script (/etc/cron.daily/upstart) in the Ubuntu Upstart package before 1.13.2-0ubuntu9, as used in Ubuntu
23RISCO
abrir ↗Exploit-DB
Foxit Products GIF Conversion - 'DataSubBlock' Memory Corruption
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory c
28RISCO
abrir ↗Exploit-DB
Foxit Products GIF Conversion - 'LZWMinimumCodeSize' Memory Corruption
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory c
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ElasticSearch - Remote Code Execution
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Text Services Memory Corruption (MS15-020)
Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
28RISCO
abrir ↗Exploit-DB
CS-Cart 4.2.4 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of
23RISCO
abrir ↗Exploit-DB
CodoForum 2.5.1 - Arbitrary File Download
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which
23RISCO
abrir ↗Exploit-DB
GeniXCMS 0.0.1 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack th
23RISCO
abrir ↗Exploit-DB
GeniXCMS 0.0.1 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary S
23RISCO
abrir ↗Exploit-DB
GeniXCMS 0.0.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.