Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.583exploits catalogados
34.507CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.554GitHub PoC 13.686VulnCheck XDB 8.213Nuclei 4.223Metasploit 3.464✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB✓ VexDay Proof
Cisco Unified Communications Manager - TFTP Service
The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sens
41RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP LoadRunner EmulationAdmin - Web Service Directory Traversal (Metasploit)
Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arb
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe ColdFusion 9 - Administrative Authentication Bypass (Metasploit)
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and pos
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IcoFX 2.5.0.0 - '.ico' Buffer Overflow (PoC)
Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCoun
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
eduTrac - 'showmask' Directory Traversal
Directory traversal vulnerability in 7 Media Web Solutions eduTrac before 1.1.2 allows remote attackers to read arbitrar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin 5 - 'index.php/ajax/api/reputation/vote?nodeid' SQL Injection (Metasploit)
SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier
43RISCO
abrir ↗Exploit-DB
EMC Data Protection Advisor DPA Illuminator - EJBInvokerServlet Remote Code Execution
The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP)
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
eFront 3.6.14 (build 18012) - Multiple Persistent Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Piranha - Remote Security Bypass
The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attac
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 3.0.5 - 'ath9k_htc_set_bssid_mask()' Information Disclosure
The ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Download Manager Free & Pro 2.5.8 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attacke
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Enorth Webpublisher CMS - 'thisday' SQL Injection
SQL injection vulnerability in m_worklog/log_searchday.jsp in Enorth Webpublisher CMS, possibly 5.0 and earlier, allows
23RISCO
abrir ↗Exploit-DB
D-Link DSR Router Series - Remote Command Execution
Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.0
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zimbra 2009-2013 - Local File Inclusion
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RISCO
abrir ↗Exploit-DB
SonicWALL Gms 7.x - Filter Bypass / Persistent
Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell So
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Steinberg MyMp3PRO 5.0 - Local Buffer Overflow (SEH) (DEP Bypass + ROP)
Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 5.0.x - IF Query Handling Remote Denial of Service
The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-depen
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft - Tagged Image File Format '.TIFF' Integer Overflow (Metasploit)
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compati
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Prime Data Center Network Manager - Arbitrary File Upload (Metasploit)
Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Chamilo Lms 1.9.6 - 'profile.php?password' SQL Injection
SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlie
23RISCO
abrir ↗Exploit-DB
Dokeos 2.2 RC2 - 'index.php?language' SQL Injection
SQL injection vulnerability in Dokeos 2.2 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'NDPROXY' SYSTEM Privilege Escalation (MS14-002)
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges
98RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Formcraft - SQL Injection
SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers
23RISCO
abrir ↗Exploit-DB
TVT TD-2308SS-B DVR - Directory Traversal
Directory traversal vulnerability in the TVT TD-2308SS-B DVR with firmware 3.2.0.P-3520A-00 and earlier allows remote at
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Kingsoft Office Writer 2012 8.1.0.3385 - '.wps' Local Buffer Overflow (SEH)
Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allow
23RISCO
abrir ↗Exploit-DB
Scientific-Atlanta_ Inc. DPR2320R2 - Multiple Cross-Site Request Forgery Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader - ASLR + DEP Bypass with Sandbox Bypass
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute
93RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - COALineDashStyleArray Unsafe Memory Access (MS12-022) (Metasploit)
Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML obj
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - CardSpaceClaimCollection ActiveX Integer Underflow (MS13-090) (Metasploit)
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.