Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.554GitHub PoC 13.689VulnCheck XDB 8.216Nuclei 4.223Metasploit 3.464✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB✓ VexDay Proof
HP Intelligent Management Center - Arbitrary File Upload (Metasploit)
Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Netw
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin 5.0.0 Beta 11 < 5.0.0 Beta 28 - SQL Injection
SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Atmail WebMail - 'INBOX.Trash?mailId' Reflected Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote attackers to inject arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Atmail WebMail - 'searchResultsTab5?filter' Reflected Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote attackers to inject arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Atmail WebMail - Message Attachment File Name Reflected Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote attackers to inject arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mitsubishi MX ActiveX Component 3 - 'ActUWzd.dll' 'WzTitle' Remote Heap Spray
Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3, as distributed in Citect CitectFacilities
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
KingView - Log File Parsing Buffer Overflow (Metasploit)
Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mutiny - Remote Command Execution (Metasploit)
Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, re
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenCart 1.5.5.1 - 'FileManager.php' Directory Traversal Arbitrary File Access
In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cool PDF Image Stream - Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in the reader in CoolPDF 3.0.2.256 allows remote attackers to execute arbitrary code via a P
43RISCO
abrir ↗Exploit-DB
GnuTLS libgnutls - Double-Free Certificate List Parsing Remote Denial of Service
Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (app
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts - 'ParametersInterceptor' Remote Code Execution (Metasploit)
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class an
60RISCO
abrir ↗Exploit-DB
ViewGit 0.0.6 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbi
23RISCO
abrir ↗Exploit-DB
Verizon Fios Router MI424WR-GEN3I - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I rout
23RISCO
abrir ↗Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and
23RISCO
abrir ↗Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
Directory traversal vulnerability in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev
23RISCO
abrir ↗Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 befo
23RISCO
abrir ↗Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does
23RISCO
abrir ↗Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
OXUpdater in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not verify X.509
23RISCO
abrir ↗Exploit-DB
Cisco Video Surveillance Operations Manager 6.3.2 - Multiple Vulnerabilities
Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages,
23RISCO
abrir ↗Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses weak permissions (group "othe
23RISCO
abrir ↗Exploit-DB
WordPress Plugin LeagueManager 3.8 - SQL Injection
SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote at
23RISCO
abrir ↗Exploit-DB
Cisco Video Surveillance Operations Manager 6.3.2 - Multiple Vulnerabilities
Multiple directory traversal vulnerabilities in Cisco Video Surveillance Manager (VSM) before 7.0.0 allow remote attacke
28RISCO
abrir ↗Exploit-DB
Cisco Video Surveillance Operations Manager 6.3.2 - Multiple Vulnerabilities
Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive,
23RISCO
abrir ↗Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses the crypt and SHA-1 algorithm
23RISCO
abrir ↗Exploit-DB
Linux Kernel 3.7.10 (Ubuntu 12.10 x64) - 'sock_diag_handlers' Local Privilege Escalation (2)
Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows l
23RISCO
abrir ↗Exploit-DB
Apache Rave 0.11 < 0.20 - User Information Disclosure
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain s
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Honeywell HSC Remote Deployer - ActiveX Remote Code Execution (Metasploit)
An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R
43RISCO
abrir ↗Exploit-DB
Linux Kernel - 'SCTP_GET_ASSOC_STATS()' Stack Buffer Overflow (PoC)
The sctp_getsockopt_assoc_stats function in net/sctp/socket.c in the Linux kernel before 3.8.4 does not validate a size
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Silverlight - ScriptObject Unsafe Memory Access (MS13-022/MS13-087) (Metasploit)
Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, wh
90RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.