Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.554GitHub PoC 13.689VulnCheck XDB 8.216Nuclei 4.223Metasploit 3.464✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB
Asus RT56U 3.0.0.4.360 - Remote Command Injection
The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware befo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - textNode Use-After-Free (MS13-037) (Metasploit)
Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a cr
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell ZENworks Mobile Device Managment 2.6.1/2.7.0 - Local File Inclusion (Metasploit)
Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote at
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 3.3.5 - 'b43' Wireless Driver Privilege Escalation
Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Quick TFTP Server Pro 2.2 - Denial of Service
Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service o
50RISCO
abrir ↗Exploit-DB
Imperva SecureSphere Operations Manager 9.0.0.5 - Multiple Vulnerabilities
The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MiniUPnPd 1.0 - Remote Stack Buffer Overflow Remote Code Execution (Metasploit)
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP
50RISCO
abrir ↗Exploit-DB
Imperva SecureSphere Operations Manager 9.0.0.5 - Multiple Vulnerabilities
plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 all
23RISCO
abrir ↗Exploit-DB
Imperva SecureSphere Operations Manager 9.0.0.5 - Multiple Vulnerabilities
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent att
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
QNAP VioStor NVR / QNAP NAS - Remote Code Execution
cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in Q
23RISCO
abrir ↗Exploit-DB
Imperva SecureSphere Operations Manager 9.0.0.5 - Multiple Vulnerabilities
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocom
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Xpient - Cash Drawer Operation
Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary
28RISCO
abrir ↗Exploit-DB
Imperva SecureSphere Operations Manager 9.0.0.5 - Multiple Vulnerabilities
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to o
23RISCO
abrir ↗Exploit-DB
DS3 Authentication Server - Multiple Vulnerabilities
ServerAdmin/TestDRConnection.jsp in DS3 Authentication Server allows remote attackers to obtain sensitive information vi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts - OGNL Expression Injection
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted acti
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts - includeParams Remote Code Execution (Metasploit)
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts - includeParams Remote Code Execution (Metasploit)
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle WebCenter Content - 'CheckOutAndOpen.dll' ActiveX Remote Code Execution (Metasploit)
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Plesk < 9.5.4 - Remote Command Execution
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has a
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Server - DirectoryService Buffer Overflow
Directory Service in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial o
28RISCO
abrir ↗Exploit-DB
DS3 Authentication Server - Multiple Vulnerabilities
ServerAdmin/TestTelnetConnection.jsp in DS3 Authentication Server allows remote authenticated users to execute arbitrary
23RISCO
abrir ↗Exploit-DB
DS3 Authentication Server - Multiple Vulnerabilities
ServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote attackers to inject arbitrary error-page text via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MongoDB - 'conn' Mongo Object Remote Code Execution
The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Telaen 2.7.x - Cross-Site Scripting
Cross-site Scripting (XSS) in Telaen before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Telaen 2.7.x - Open Redirection
Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victim
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT/2000/2003/2008/XP/Vista/7/8 - 'EPATHOBJ' Local Ring
The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vist
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Telaen - Information Disclosure
Telean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT/2000/2003/2008/XP/Vista/7/8 - 'EPATHOBJ' Local Ring
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windo
98RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT/2000/2003/2008/XP/Vista/7/8 - 'EPATHOBJ' Local Ring
20RISCO
abrir ↗Exploit-DB
ModSecurity - Remote Null Pointer Dereference
The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NUL
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.