Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.104GitHub PoC 15.075VulnCheck XDB 8.883Nuclei 4.365Metasploit 3.493✓ só verificadosrecentespopularesrisco
24.466 exploits
Exploit-DB
Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RISCO
abrir ↗Exploit-DB
Microsoft Excel 365 MSO (Version 2302 Build 16.0.16130.20186) 64-bit - Remote Code Execution (RCE)
Microsoft Excel Remote Code Execution Vulnerability
41RISCO
abrir ↗Exploit-DB
Adobe Connect 11.4.5 - Local File Disclosure
Adobe Connect Improper Access Control Security feature bypass
70RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! v4.2.8 - Unauthenticated information disclosure
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗Exploit-DB
RSA NetWitness Platform 12.2 - Incorrect Access Control / Code Execution
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Wi
23RISCO
abrir ↗Exploit-DB
ENTAB ERP 1.0 - Username PII leak
ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames
33RISCO
abrir ↗Exploit-DB
Palo Alto Cortex XSOAR 6.5.0 - Stored Cross-Site Scripting (XSS)
Cortex XSOAR: Stored Cross-Site Scripting (XSS) Vulnerability in Web Interface
33RISCO
abrir ↗Exploit-DB
X2CRM v6.6/6.9 - Reflected Cross-Site Scripting (XSS) (Authenticated)
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability v
33RISCO
abrir ↗Exploit-DB
Suprema BioStar 2 v2.8.16 - SQL Injection
Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/abs
33RISCO
abrir ↗Exploit-DB
Goanywhere Encryption helper 7.1.1 - Remote Code Execution (RCE)
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISCO
abrir ↗Exploit-DB
Symantec Messaging Gateway 10.7.4 - Stored Cross-Site Scripting (XSS)
An authenticated user can embed malicious content with XSS into the admin group policy page.
33RISCO
abrir ↗Exploit-DB
Altenergy Power Control Software C1.2.5 - OS command injection
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISCO
abrir ↗Exploit-DB
Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RISCO
abrir ↗Exploit-DB
ZCBS/ZBBS/ZPBS v4.14k - Reflected Cross-Site Scripting (XSS)
ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Manageme
33RISCO
abrir ↗Exploit-DB
X2CRM v6.6/6.9 - Stored Cross-Site Scripting (XSS) (Authenticated)
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via
33RISCO
abrir ↗Exploit-DB
pfsenseCE v2.6.0 - Anti-brute force protection bypass
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22
48RISCO
abrir ↗Exploit-DB
Wondershare Dr Fone 12.9.6 - Privilege Escalation
Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability all
41RISCO
abrir ↗Exploit-DB
Docker based datastores for IBM Instana 241-2 243-0 - No Authentication
IBM Observability with Instana missing authentication
48RISCO
abrir ↗Exploit-DB
NotrinosERP 0.7 - Authenticated Blind SQL Injection
NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/s
23RISCO
abrir ↗Exploit-DB
Tenda N300 F3 12.01.01.48 - Malformed HTTP Request Header Processing
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISCO
abrir ↗Exploit-DB
MAC 1200R - Directory Traversal
A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-stati
41RISCO
abrir ↗Exploit-DB
IBM Aspera Faspex 4.4.1 - YAML deserialization (RCE)
IBM Aspera Faspex code execution
100RISCO
abrir ↗Exploit-DB
modoboa 2.0.4 - Admin TakeOver
Authentication Bypass by Primary Weakness in modoboa/modoboa
61RISCO
abrir ↗Exploit-DB
Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal and LFI
A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before
50RISCO
abrir ↗Exploit-DB
ABUS Security Camera TVIP 20000-21150 - LFI_ RCE and SSH Root Access
ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin
53RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Employee Task Management System v1.0 - Broken Authentication
SourceCodester Employee Task Management System changePasswordForEmployee.php improper authentication
41RISCO
abrir ↗Exploit-DB
TitanFTP 2.0.1.2102 - Path traversal to Remote Code Execution (RCE)
An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the
61RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.