Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.104GitHub PoC 15.075VulnCheck XDB 8.883Nuclei 4.365Metasploit 3.493✓ só verificadosrecentespopularesrisco
24.466 exploits
Exploit-DB
WinterCMS < 1.2.3 - Persistent Cross-Site Scripting
Winter CMS vulnerable to stored XSS through privileged upload of SVG file
28RISCO
abrir ↗Exploit-DB
Cisco UCS-IMC Supervisor 2.2.0.0 - Authentication Bypass
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Authentication Bypass Vulnerability
85RISCO
abrir ↗Exploit-DB
Icinga Web 2.10 - Authenticated Remote Code Execution
Arbitrary code execution for authenticated users in Icinga Web 2
46RISCO
abrir ↗Exploit-DB
BuildaGate5library v5 - Reflected Cross-Site Scripting (XSS)
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code
23RISCO
abrir ↗Exploit-DB
MiniTool Partition Wizard ShadowMaker v.12.7 - Unquoted Service Path _MTAgentService_
20RISCO
abrir ↗Exploit-DB
MiniTool Partition Wizard ShadowMaker v.12.7 - Unquoted Service Path _MTSchedulerService_
20RISCO
abrir ↗Exploit-DB
Spring Cloud 3.2.2 - Remote Command Execution (RCE)
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗Exploit-DB
Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir ↗Exploit-DB
Microsoft Outlook Microsoft 365 MSO (Version 2306 Build 16.0.16529.20100) 32-bit - Remote Code Execution
Microsoft Outlook Remote Code Execution Vulnerability
41RISCO
abrir ↗Exploit-DB
Lost and Found Information System v1.0 - SQL Injection
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RISCO
abrir ↗Exploit-DB
Microsoft Edge 114.0.1823.67 (64-bit) - Information Disclosure
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
33RISCO
abrir ↗Exploit-DB
Sales of Cashier Goods v1.0 - Cross Site Scripting (XSS)
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parame
38RISCO
abrir ↗Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 32-bit - Remote Code Execution (RCE)
Microsoft Excel Remote Code Execution Vulnerability
41RISCO
abrir ↗Exploit-DB
FuguHub 8.1 - Remote Code Execution
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RISCO
abrir ↗Exploit-DB
POS Codekop v2.0 - Authenticated Remote Code Execution (RCE)
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename p
23RISCO
abrir ↗Exploit-DB
TP-Link TL-WR940N V4 - Buffer OverFlow
TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6Cfg
35RISCO
abrir ↗Exploit-DB
WP AutoComplete 1.0.4 - Unauthenticated SQLi
WP AutoComplete Search <= 1.0.4 - Unauthenticated SQLi
48RISCO
abrir ↗Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit - Remote Code Execution (RCE)
Microsoft Office Remote Code Execution Vulnerability
41RISCO
abrir ↗Exploit-DB
Azure Apache Ambari 2302250400 - Spoofing
Azure Apache Ambari Spoofing Vulnerability
33RISCO
abrir ↗Exploit-DB
Windows 11 22h2 - Kernel Privilege Elevation
Windows Kernel Elevation of Privilege Vulnerability
41RISCO
abrir ↗Exploit-DB
PrestaShop Winbiz Payment module - Improper Limitation of a Pathname to a Restricted Directory
Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download
41RISCO
abrir ↗Exploit-DB
Microsoft SharePoint Enterprise Server 2016 - Spoofing
Microsoft SharePoint Server Spoofing Vulnerability
41RISCO
abrir ↗Exploit-DB
NCH Express Invoice - Clear Text Password Storage and Account Takeover
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
23RISCO
abrir ↗Exploit-DB
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the
68RISCO
abrir ↗Exploit-DB
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via Display
41RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SPIP v4.2.0 - Remote Code Execution (Unauthenticated)
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir ↗Exploit-DB
WP Sticky Social 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting (XSS)
The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,
33RISCO
abrir ↗Exploit-DB
Nokia ASIKA 7.13.52 - Hard-coded private key disclosure
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures
33RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.