Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.902exploits catalogados
34.597CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.624GitHub PoC 13.727VulnCheck XDB 8.410Nuclei 4.231Metasploit 3.467✓ só verificadosrecentespopularesrisco
21.624 exploits
Referência
CVE-2015-3315
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impac
38RISCO
abrir ↗Referência
CVE-2015-6100
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RISCO
abrir ↗Referência
CVE-2017-15374
Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management
23RISCO
abrir ↗Referência
CVE-2009-2961
Stack-based buffer overflow in Thaddy de Konng KOL Player 1.0 allows remote attackers to cause a denial of service (cras
23RISCO
abrir ↗Referência
CVE-2009-3947
Buffer overflow in the FTP service on the Tandberg MXP F7.0 allows remote attackers to cause a denial of service (proces
23RISCO
abrir ↗Referência
CVE-2009-4759
Buffer overflow in BrotherSoft BMXPlay 0.4.4b allows remote attackers to cause a denial of service (application crash) o
23RISCO
abrir ↗Referência✓ VexDay Proof
Winamp 5.21 - '.Midi' File Header Handling Buffer Overflow (PoC)
Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary
28RISCO
abrir ↗Referência✓ VexDay Proof
PHP 5.x COM - Safe Mode / disable_functions Bypass
The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restricti
23RISCO
abrir ↗Referência✓ VexDay Proof
dBpowerAMP Audio Player 2 - '.m3u' Buffer Overflow (PoC)
Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file w
23RISCO
abrir ↗Referência✓ VexDay Proof
Alstrasoft SendIt Pro - Arbitrary File Upload
Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute ar
23RISCO
abrir ↗Referência✓ VexDay Proof
Simple PHP News 1.0 - Remote Command Execution
Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
Stack-based buffer overflow in Trident PowerZip 7.2 might allow remote attackers to execute arbitrary code via a crafted
23RISCO
abrir ↗Referência
CVE-2009-2852
WP-Syntax plugin 0.9.1 and earlier for Wordpress, with register_globals enabled, allows remote attackers to execute arbi
23RISCO
abrir ↗Referência
CVE-2010-2349
H264WebCam 3.7 allows remote attackers to cause a denial of service (crash) via a long URI in a GET request, which trigg
23RISCO
abrir ↗Referência
BSA Radar 1.6.7234.24750 - Authenticated Privilege Escalation
A privilege escalation vulnerability exists within Global RADAR BSA Radar 1.6.7234.24750 and earlier that allows an auth
28RISCO
abrir ↗Referência
CVE-2009-3574
Tuniac 090517c allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a lon
23RISCO
abrir ↗Referência
CVE-2018-16071
A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap
23RISCO
abrir ↗Referência
CVE-2010-4170
The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allow
38RISCO
abrir ↗Referência
CVE-2010-4170
The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allow
38RISCO
abrir ↗Referência
CVE-2010-4170
The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allow
38RISCO
abrir ↗Referência
CVE-2017-0299
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISCO
abrir ↗Referência
CVE-2012-1904
mp4fformat.dll in the QuickTime File Format plugin in RealNetworks RealPlayer 15 and earlier, and RealPlayer SP 1.1.4 Bu
23RISCO
abrir ↗Referência
CVE-2018-4218
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
23RISCO
abrir ↗Referência
CVE-2015-1057
Cross-site scripting (XSS) vulnerability in usersettings.php in e107 2.0.0 allows remote attackers to inject arbitrary w
23RISCO
abrir ↗Referência
CVE-2016-1819
Use-after-free vulnerability in the IOAccelContext2::clientMemoryForType method in Apple iOS before 9.3.2, OS X before 1
23RISCO
abrir ↗Referência
CVE-2016-1819
Use-after-free vulnerability in the IOAccelContext2::clientMemoryForType method in Apple iOS before 9.3.2, OS X before 1
23RISCO
abrir ↗Referência✓ VexDay Proof
Integramod Portal 2.x - 'functions_portal.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows rem
23RISCO
abrir ↗Referência
CVE-2014-1842
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RISCO
abrir ↗Referência
CVE-2013-7187
SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.