Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.409exploits catalogados
37.196CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.478Referência 23.664GitHub PoC 15.347VulnCheck XDB 9.003Nuclei 4.415Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.478 exploits
Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
20RISCO
abrir ↗Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
20RISCO
abrir ↗Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
20RISCO
abrir ↗Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
20RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Remote Code Execution)
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISCO
abrir ↗Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISCO
abrir ↗Exploit-DB
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Admin Session)
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISCO
abrir ↗Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
20RISCO
abrir ↗Exploit-DB
Progress OpenEdge 11.2 - Directory Traversal
Directory traversal vulnerability in report/reportViewAction.jsp in Progress Software OpenEdge 11.2 allows remote attack
23RISCO
abrir ↗Exploit-DB
Who's Who Script - Cross-Site Request Forgery (Add Admin)
Multiple cross-site request forgery (CSRF) vulnerabilities in Php Scriptlerim Who's Who script allow remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISCO
abrir ↗Exploit-DB
IBM Tivoli Monitoring 6.2.2 kbbacf1 - Local Privilege Escalation
Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Mo
23RISCO
abrir ↗Exploit-DB
Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 - '.wax' File Buffer Overflow (Denial of Service) (PoC) EIP Overwrite
Buffer overflow in Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 allows remote attackers to execute arbitrary code or
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
20RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
20RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
20RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MAARCH 1.4 - Arbitrary File Upload
Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earl
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
20RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗Exploit-DB
Konke Smart Plug K - Authentication Bypass
The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equ
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
20RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Enalean Tuleap 7.4.99.5 - Remote Command Execution
Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - TrackPopupMenu Win32k Null Pointer Dereference (MS14-058) (Metasploit)
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Enalean Tuleap 7.2 - XML External Entity File Disclosure
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Enalean Tuleap 7.4.99.5 - Blind SQL Injection
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL
23RISCO
abrir ↗Exploit-DB
Tapatalk for vBulletin 4.x - Blind SQL Injection
Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Enalean Tuleap 7.2 - XML External Entity File Disclosure
XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP Operations Agent - Cross-Site Scripting iFrame Injection
Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communicatio
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Centreon - SQL Injection / Command Injection (Metasploit)
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.