Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.497GitHub PoC 13.627VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB
CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows r
23RISCO
abrir ↗Exploit-DB
Mulesoft ESB Runtime 3.5.1 - Privilege Escalation
Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows
23RISCO
abrir ↗Exploit-DB
Filemaker Pro 13.03 / Advanced 12.04 - Authentication Bypass / Privilege Escalation
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP Operations Agent - Cross-Site Scripting iFrame Injection
Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communicatio
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Centreon - SQL Injection / Command Injection (Metasploit)
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3
60RISCO
abrir ↗Exploit-DB
Magento Server MAGMI Plugin 0.7.17a - Remote File Inclusion
Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a an
23RISCO
abrir ↗Exploit-DB
Dell EqualLogic Storage - Directory Traversal
Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary
23RISCO
abrir ↗Exploit-DB
WordPress Plugin 0.9.7 / Joomla! Component 2.0.0 Creative Contact Form - Arbitrary File Upload
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RISCO
abrir ↗Exploit-DB
Microsoft Windows - OLE Remote Code Execution 'Sandworm' (MS14-060)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISCO
abrir ↗Exploit-DB
Microsoft Windows - OLE Remote Code Execution 'Sandworm' (MS14-060)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISCO
abrir ↗Exploit-DB
Axway Secure Transport 5.1 SP2 - Arbitrary File Upload (via Cross-Site Request Forgery)
Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to
23RISCO
abrir ↗Exploit-DB
iBackup 10.0.0.32 - Local Privilege Escalation
iBackup 10.0.0.32 and earlier uses weak permissions (Everyone: Full Control) for ib_service.exe, which allows local user
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Numara / BMC Track-It! FileStorageService - Arbitrary File Upload (Metasploit)
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbit
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Akeeba Kickstart - Unserialize Remote Code Execution (Metasploit)
Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeb
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-060) (Metasploit)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux PolicyKit - Race Condition Privilege Escalation (Metasploit)
Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privil
38RISCO
abrir ↗Exploit-DB
Aireplay-ng 1.2 beta3 - 'tcp_test' Length Stack Overflow
Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attac
28RISCO
abrir ↗Exploit-DB
Microsoft Windows - OLE Package Manager SandWorm
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISCO
abrir ↗Exploit-DB
Microsoft Windows - OLE Package Manager SandWorm
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-060) (Metasploit)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (2)
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SAP NetWeaver Enqueue Server - Denial of Service
The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of serv
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (1)
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Bluetooth Personal Area Networking - 'BthPan.sys' Local Privilege Escalation (Metasploit)
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Centreon < 2.5.1 / Centreon Enterprise Server < 2.2 - SQL Injection / Command Injection (Metasploit)
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remot
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Centreon < 2.5.1 / Centreon Enterprise Server < 2.2 - SQL Injection / Command Injection (Metasploit)
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
YourMembers Plugin - Blind SQL Injection
SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for Wor
23RISCO
abrir ↗Exploit-DB
Tenda A32 Router - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN a
23RISCO
abrir ↗Exploit-DB
Croogo 2.0.0 - Multiple Persistent Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary we
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.