Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.554GitHub PoC 13.689VulnCheck XDB 8.216Nuclei 4.223Metasploit 3.464✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB
vTiger CRM 5.4.0 SOAP - Multiple Vulnerabilities
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute a
28RISCO
abrir ↗Exploit-DB
vTiger CRM 5.4.0 SOAP - Multiple Vulnerabilities
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote atta
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector - CMD Install Service (Metasploit)
The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that ref
50RISCO
abrir ↗Exploit-DB
Western Digital My Net Wireless Routers - Password Disclosure
main_internet.php on the Western Digital My Net N600 and N750 with firmware 1.03.12 and 1.04.16, and the N900 and N900C
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cotonti 0.9.13 - SQL Injection
SQL injection vulnerability in modules/rss/rss.php in Cotonti before 0.9.14 allows remote attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PCMan FTP Server 2.07 - 'PASS' Remote Buffer Overflow
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISCO
abrir ↗Exploit-DB
D-Link DIR-645 1.03B08 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645 Router (Rev. A1) with firmware before 1.04B11 allo
43RISCO
abrir ↗Exploit-DB
vTiger CRM 5.4.0 SOAP - Multiple Vulnerabilities
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities
Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities
MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TP-Link TL-SC3171 IP Cameras - Multiple Vulnerabilities
cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models be
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - HWND_BROADCAST Low to Medium Integrity Privilege Escalation (MS13-005) (Metasploit)
win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Karotz Smart Rabbit 12.07.19.00 - Multiple Vulnerabilities
Karotz API 12.07.19.00: Session Token Information Disclosure
23RISCO
abrir ↗Exploit-DB
Linux Kernel 3.7.6 (RedHat x86/x64) - 'MSR' Driver Privilege Escalation
The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended ca
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TP-Link TL-SC3171 IP Cameras - Multiple Vulnerabilities
cgi-bin/firmwareupgrade in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models be
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SilverStripe CMS - 'MemberLoginForm.php' Information Disclosure
security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jahia xCM - '/engines/manager.jsp?site' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to injec
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Plone - 'in_portal.py' < 4.1.3 Session Hijacking
The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x t
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jahia xCM - '/administration/' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to injec
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell Client 2 SP3 - 'nicm.sys 3.1.11.0' Local Privilege Escalation
The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2
38RISCO
abrir ↗Exploit-DB
TRENDnet TEW-812DRU - Cross-Site Request Forgery/Command Injection Root
Multiple cross-site request forgery (CSRF) vulnerabilities in TRENDnet TEW-812DRU router with firmware before 1.0.9.0 al
23RISCO
abrir ↗Exploit-DB
TRENDnet TEW-812DRU - Cross-Site Request Forgery/Command Injection Root
TRENDnet TEW-812DRU router allows remote authenticated users to execute arbitrary commands via shell metacharacters in t
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Web Gateway 5.1.0.x - Multiple Vulnerabilities
The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote attackers to execute arbit
28RISCO
abrir ↗Exploit-DB
ASUS RT-AC66U - 'acsd' Remote Command Execution
Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. T
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution (Metasploit)
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RISCO
abrir ↗Exploit-DB
Galil-RIO Modbus - Denial of Service
The Galil RIO-47100 Pocket PLC allows remote attackers to cause a denial of service via a session that includes "repeate
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
xmonad XMonad.Hooks.DynamicLog Module - Multiple Remote Command Injection Vulnerabilities
The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.