Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.554GitHub PoC 13.689VulnCheck XDB 8.216Nuclei 4.223Metasploit 3.464✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB✓ VexDay Proof
Lianja SQL 1.0.0RC5.1 - db_netserver Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in db_netserver in Lianja SQL Server before 1.0.0RC5.2 allows remote attackers to cause a de
50RISCO
abrir ↗Exploit-DB
Monkey HTTPd 1.1.1 - Crash (PoC)
The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of serv
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM SPSS SamplePower C1Tab - ActiveX Heap Overflow (Metasploit)
Buffer overflow in the c1sizer ActiveX control in C1sizer.ocx in IBM SPSS SamplePower 3.0 before FP1 allows remote attac
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zavio IP Cameras Firmware 1.6.03 - Multiple Vulnerabilities
A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is dis
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TP-Link IP Cameras Firmware 1.6.18P12 - Multiple Vulnerabilities
A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cam
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TP-Link IP Cameras Firmware 1.6.18P12 - Multiple Vulnerabilities
A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 d
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MayGion IP Cameras Firmware 09.27 - Multiple Vulnerabilities
Buffer overflow in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to execute arbitra
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zavio IP Cameras Firmware 1.6.03 - Multiple Vulnerabilities
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to t
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MayGion IP Cameras Firmware 09.27 - Multiple Vulnerabilities
Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zavio IP Cameras Firmware 1.6.03 - Multiple Vulnerabilities
An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zavio IP Cameras Firmware 1.6.03 - Multiple Vulnerabilities
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Nginx 1.3.9 < 1.4.0 - Chuncked Encoding Stack Buffer Overflow (Metasploit)
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RISCO
abrir ↗Exploit-DB
RadioCMS 2.2 - 'menager.php?playlist_id' SQL Injection
SQL injection vulnerability in meneger.php in RadioCMS 2.2 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AdobeCollabSync - Local Buffer Overflow / Adobe Reader X Sandbox Bypass (Metasploit)
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attacke
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Win32k!EPATHOBJ::pprFlattenRec Uninitialized Next Pointer Testcase
The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vist
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Win32k!EPATHOBJ::pprFlattenRec Uninitialized Next Pointer Testcase
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windo
98RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Win32k!EPATHOBJ::pprFlattenRec Uninitialized Next Pointer Testcase
20RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Python RRDtool Module - Function Format String
Format string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attacker
28RISCO
abrir ↗Exploit-DB
Nginx 1.3.9 < 1.4.0 - Denial of Service (PoC)
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RISCO
abrir ↗Exploit-DB
Exponent CMS 2.2.0 Beta 3 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Exponent CMS before 2.2.0 release candidate 1 allow remote attackers to execut
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mutiny 5 - Arbitrary File Upload (Metasploit)
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Mail On Update - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote at
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin WP Cleanfix - Cross-Site Request Forgery
WordPress WP Cleanfix Plugin 2.4.4 has CSRF
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jojo CMS - 'x-forwarded-for' HTTP header SQL Injection
SQL injection vulnerability in the checkEmailFormat function in plugins/jojo_core/classes/Jojo.php in Jojo before 1.2.2
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Serva 32 TFTP 2.1.0 - Buffer Overflow (Denial of Service) (PoC)
Buffer overflow in the TFTPD service in Serva32 2.1.0 allows remote attackers to cause a denial of service (daemon crash
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jojo CMS - 'search' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in plugins/jojo_core/forgot_password.php in Jojo before 1.2.2 allows remote att
23RISCO
abrir ↗Exploit-DB
UMI CMS 2.9 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Umisoft UMI.CMS before 2.9 build 21905 allows remote attackers to hij
23RISCO
abrir ↗Exploit-DB
Linux Kernel 2.6.32 < 3.x (CentOS 5/6) - 'PERF_EVENTS' Local Privilege Escalation (1)
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RISCO
abrir ↗Exploit-DB
Linux Kernel < 3.8.x - open-time Capability 'file_ns_capable()' Local Privilege Escalation
kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_m
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ERS Viewer 2011 - '.ERS' File Handling Buffer Overflow (Metasploit)
Stack-based buffer overflow in the ERM_convert_to_correct_webpath function in ermapper_u.dll in ERDAS ER Viewer before 1
43RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.