Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.662GitHub PoC 13.743VulnCheck XDB 8.460Nuclei 4.233Metasploit 3.467✓ só verificadosrecentespopularesrisco
21.662 exploits
Referência
CVE-2020-13160
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execut
60RISCO
abrir ↗Referência
CVE-2009-2436
SQL injection vulnerability in page.php in Online Dating Software MyPHPDating 1.0 allows remote attackers to execute arb
23RISCO
abrir ↗Referência
CVE-2018-12464
Unauthenticated SQL injection in Micro Focus Secure Messaging Gateway
85RISCO
abrir ↗Referência
CVE-2021-21425
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RISCO
abrir ↗Referência
CVE-2021-21425
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RISCO
abrir ↗Referência
CVE-2017-12557
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and e
60RISCO
abrir ↗Referência
CVE-2017-0037
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilde
93RISCO
abrir ↗Referência
CVE-2020-14871
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RISCO
abrir ↗Referência
CVE-2020-14871
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RISCO
abrir ↗Referência
CVE-2023-22952
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because o
100RISCO
abrir ↗Referência
CVE-2009-2439
Multiple SQL injection vulnerabilities in Web Development House Alibaba Clone allow remote attackers to execute arbitrar
23RISCO
abrir ↗Referência
CVE-2015-7387
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RISCO
abrir ↗Referência
CVE-2015-7387
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RISCO
abrir ↗Referência
CVE-2015-7387
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RISCO
abrir ↗Referência
CVE-2017-16666
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name
60RISCO
abrir ↗Referência
CVE-2017-16666
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name
60RISCO
abrir ↗Referência
CVE-2014-4872
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbit
60RISCO
abrir ↗Referência
CVE-2019-11600
A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbi
45RISCO
abrir ↗Referência
CVE-2016-6563
D-Link DIR routers contain a stack-based buffer overflow in the HNAP Login action
60RISCO
abrir ↗Referência
CVE-2018-18809
TIBCO JasperReports Library Directory Traversal Vulnerability
100RISCO
abrir ↗Referência
CVE-2015-3043
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457
100RISCO
abrir ↗Referência✓ VexDay Proof
Ubuntu 6.06 - DHCPd Remote Denial of Service
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some othe
45RISCO
abrir ↗Referência✓ VexDay Proof
SAP MaxDB 7.6.03.07 - Remote Command Execution
SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell me
60RISCO
abrir ↗Referência✓ VexDay Proof
OpenSSL < 0.9.8i - DTLS ChangeCipherSpec Remote Denial of Service
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.