Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.526exploits catalogados
36.593CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.152GitHub PoC 15.158VulnCheck XDB 8.883Nuclei 4.365Metasploit 3.493✓ só verificadosrecentespopularesrisco
19.066 exploits
Exploit-DB✓ VexDay Proof
Routers2 2.24 - Cross-Site Scripting
A Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 8.1/2012 R2 - SMBv3 Null Pointer Dereference Denial of Service
The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Asterisk chan_pjsip 15.2.0 - 'INVITE' Denial of Service
An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asteris
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Asterisk chan_pjsip 15.2.0 - 'SUBSCRIBE' Stack Corruption
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Ce
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AsusWRT LAN - Remote Code Execution (Metasploit)
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, pro
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AsusWRT LAN - Remote Code Execution (Metasploit)
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpn
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CloudMe Sync 1.10.9 - Stack-Based Buffer Overflow (Metasploit)
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to exe
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
Reflected cross-site scripting (XSS) vulnerabilities in two Trend Micro Email Encryption Gateway 5.5 configuration files
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log fi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allo
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
An XML external entity injection (XXE) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an authenti
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 11 - 'Js::RegexHelper::RegexReplace' Use-After-Free
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'nt!RtlpCopyLegacyContextX86' Stack Memory Disclosure
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Window
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - StorSvc SvcMoveFileInheritSecurity Arbitrary File Creation Privilege Escalation
Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, versi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Constrained Impersonation Capability Privilege Escalation
AppContainer in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Global Reparse Point Security Feature Bypass/Elevation of Privilege
NTFS in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an eleva
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - NPFS Symlink Security Feature Bypass/Elevation of Privilege/Dangerous Behavior
The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MagniComp SysInfo - mcsiwrapper Privilege Escalation (Metasploit)
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component JB Bus 2.3 - 'order_number' SQL Injection
SQL Injection exists in the JB Bus 2.3 component for Joomla! via the order_number parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Project Log 1.5.3 - 'search' SQL Injection
SQL Injection exists in the Project Log 1.5.3 component for Joomla! via the search parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component JomEstate PRO 3.7 - 'id' SQL Injection
SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed acti
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Fastball 2.5 - 'season' SQL Injection
SQL Injection exists in the Fastball 2.5 component for Joomla! via the season parameter in a view=player action.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.