Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.797GitHub PoC 13.885VulnCheck XDB 8.484Nuclei 4.237Metasploit 3.467✓ só verificadosrecentespopularesrisco
21.797 exploits
Referência
CVE-2010-0470
Cross-site scripting (XSS) vulnerability in scvrtsrv.cmd in Comtrend CT-507IT ADSL Router allows remote attackers to inj
23RISCO
abrir ↗Referência
CVE-2015-5353
Directory traversal vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to include and execute arbitrary lo
23RISCO
abrir ↗Referência
CVE-2015-5353
Directory traversal vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to include and execute arbitrary lo
23RISCO
abrir ↗Referência
CVE-2014-2477
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.2
38RISCO
abrir ↗Referência
CVE-2018-4087
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RISCO
abrir ↗Referência✓ VexDay Proof
Maxum Rumpus 6.0 - Multiple Remote Buffer Overflow Vulnerabilities
Multiple buffer overflows in Rumpus before 6.0.1 allow remote attackers to (1) cause a denial of service (segmentation f
23RISCO
abrir ↗Referência
CVE-2017-6192
Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arb
23RISCO
abrir ↗Referência
CVE-2017-6192
Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arb
23RISCO
abrir ↗Referência
CTROMS Terminal OS Port Portal - 'Password Reset' Authentication Bypass (Metasploit)
An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-res
23RISCO
abrir ↗Referência✓ VexDay Proof
Mini-stream Ripper - '.m3u' Local Stack Overflow (PoC)
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RISCO
abrir ↗Referência✓ VexDay Proof
Quantum Game Library 0.7.2c - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Quantum Game Library 0.7.2c allow remote attackers to execute arbi
28RISCO
abrir ↗Referência✓ VexDay Proof
HydraIrc 0.3.164 - Remote Denial of Service
HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and applicat
23RISCO
abrir ↗Referência✓ VexDay Proof
D-Link MPEG4 SHM Audio Control - 'VAPGDecoder.dll 1.7.0.5' Remote Buffer Overflow
Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 a
23RISCO
abrir ↗Referência
CVE-2010-0631
Multiple SQL injection vulnerabilities in index.php in Eicra Car Rental-Script, when the plugin_id parameter is 4, allow
23RISCO
abrir ↗Referência
CVE-2010-0632
SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote at
23RISCO
abrir ↗Referência
CVE-2021-25160
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in v
23RISCO
abrir ↗Referência
CVE-2013-5639
Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrar
23RISCO
abrir ↗Referência
CVE-2013-5639
Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrar
23RISCO
abrir ↗Referência
CVE-2020-11700
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.
23RISCO
abrir ↗Referência✓ VexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
MicroSmarts Enterprise ZipItFast! 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file that tri
23RISCO
abrir ↗Referência
CVE-2013-1465
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to un
23RISCO
abrir ↗Referência
CVE-2013-1465
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to un
23RISCO
abrir ↗Referência
CVE-2015-2315
Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject
23RISCO
abrir ↗Referência✓ VexDay Proof
32bit FTP (09.04.24) - 'Banner' Remote Buffer Overflow (PoC)
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
23RISCO
abrir ↗Referência✓ VexDay Proof
RealPlayer 10 - '.ra' Remote Denial of Service
RealNetworks RealPlayer 10 Gold allows remote attackers to cause a denial of service (memory consumption) via a certain
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP Multiple Newsletters 2.7 - Local File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote a
23RISCO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin E-Commerce 3.4 - Arbitrary File Upload
Unrestricted file upload vulnerability in image_processing.php in the e-Commerce Plugin 3.4 and earlier for Wordpress al
23RISCO
abrir ↗Referência
CVE-2014-4688
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RISCO
abrir ↗Referência
CVE-2011-4810
Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read a
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.