Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.497GitHub PoC 13.627VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB
RedaxScript CMS 2.2.0 - SQL Injection
SQL injection vulnerability in the search_post function in includes/search.php in Redaxscript before 2.3.0 allows remote
23RISCO
abrir ↗Exploit-DB
Fork CMS 3.8.5 - SQL Injection
Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to exec
23RISCO
abrir ↗Exploit-DB
u5CMS 3.9.3 - 'deletefile.php' Arbitrary File Deletion
Directory traversal vulnerability in u5admin/deletefile.php in u5CMS before 3.9.4 allows remote attackers to write to ar
23RISCO
abrir ↗Exploit-DB
u5CMS 3.9.3 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in u5CMS before 3.9.4 allow remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir ↗Exploit-DB
ManageEngine OpManager / Applications Manager / IT360 - 'FailOverServlet' Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpMan
28RISCO
abrir ↗Exploit-DB
Achat 0.150 beta7 - Remote Buffer Overflow
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RISCO
abrir ↗Exploit-DB
Achat 0.150 beta7 - Remote Buffer Overflow
Directory traversal vulnerability in u5admin/deletefile.php in u5CMS before 3.9.4 allows remote attackers to write to ar
23RISCO
abrir ↗Exploit-DB
Magento Server MAGMI Plugin - Multiple Vulnerabilities
Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento
50RISCO
abrir ↗Exploit-DB
Magento Server MAGMI Plugin - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server a
43RISCO
abrir ↗Exploit-DB
AVG Internet Security 2015.0.5315 - Arbitrary Write Privilege Escalation
The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protec
23RISCO
abrir ↗Exploit-DB
K7 Computing (Multiple Products) - Arbitrary Write Privilege Escalation
K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users
23RISCO
abrir ↗Exploit-DB
BullGuard (Multiple Products) - Arbitrary Write Privilege Escalation
bdagent.sys in BullGuard Antivirus, Internet Security, Premium Protection, and Online Backup before 15.0.288 allows loca
23RISCO
abrir ↗Exploit-DB
Pragyan CMS 3.0 - SQL Injection
SQL injection vulnerability in userprofile.lib.php in Pragyan CMS 3.0 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Hewlett-Packard (HP) UCMDB - JMX-Console Authentication Bypass
HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to o
35RISCO
abrir ↗Exploit-DB
ManageEngine Desktop Central 9 Build 90087 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Remote Desktop Services - Web Proxy IE Sandbox Escape (MS15-004) (Metasploit)
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7
100RISCO
abrir ↗Exploit-DB
Sefrengo CMS 1.6.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Sefrengo before 1.6.2 allow (1) remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Exploit-DB
Symantec Altiris Agent 6.9 (Build 648) - Local Privilege Escalation
Buffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local us
23RISCO
abrir ↗Exploit-DB
Trend Micro 8.0.1133 (Multiple Products) - Local Privilege Escalation
The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows lo
23RISCO
abrir ↗Exploit-DB
McAfee Data Loss Prevention Endpoint - Arbitrary Write Privilege Escalation
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, an
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector 8.x - Remote Command Execution
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Encryption Management Server < 3.2.0 MP6 - Remote Command Injection
Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrator
23RISCO
abrir ↗Exploit-DB
Microsoft Windows Server 2003 SP2 - Local Privilege Escalation (MS14-070)
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RISCO
abrir ↗Exploit-DB
ManageEngine Firewall Analyzer 8.0 - Directory Traversal / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inje
38RISCO
abrir ↗Exploit-DB
Apple Mac OSX < 10.10.x - GateKeeper Bypass
LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypas
23RISCO
abrir ↗Exploit-DB
ManageEngine Firewall Analyzer 8.0 - Directory Traversal / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers t
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD - Multiple Vulnerabilities
Multiple array index errors in the Stream Control Transmission Protocol (SCTP) module in FreeBSD 10.1 before p5, 10.0 be
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD - Multiple Vulnerabilities
Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows
23RISCO
abrir ↗Exploit-DB
Exim ESMTP 4.80 - glibc gethostbyname Denial of Service
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RISCO
abrir ↗Exploit-DB
jclassifiedsmanager - Multiple Vulnerabilities
SQL injection vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to execu
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.