Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.107exploits catalogados
34.679CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.692GitHub PoC 13.812VulnCheck XDB 8.460Nuclei 4.233Metasploit 3.467✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB✓ VexDay Proof
KnFTP Server - Remote Buffer Overflow
Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MYRE Real Estate Software - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in findagent.php in MYRE Real Estate Software allow remote attackers
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MYRE Real Estate Software - Multiple Vulnerabilities
SQL injection vulnerability in findagent.php in MYRE Real Estate Software allows remote attackers to execute arbitrary S
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BisonWare BisonFTP Server 3.5 - Remote Buffer Overflow (Metasploit)
Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Spring Security - HTTP Header Injection
CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x b
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Event Registration 5.44 - SQL Injection
SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to e
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark 1.6.1 - Malformed Packet Trace File Remote Denial of Service
Wireshark 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (application crash) via a malformed ca
23RISCO
abrir ↗Exploit-DB
DVD X Player 5.5 Pro - Local Overflow (SEH + ASLR + DEP Bypass)
Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DVD X Player 5.5 Pro - Overwrite (SEH)
Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zikula Application Framework 1.2.7/1.3 - 'themename' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme module i
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.36.2 (Ubuntu 10.04) - 'Half-Nelson.c' Econet Privilege Escalation
Stack-based buffer overflow in the econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.36.2 (Ubuntu 10.04) - 'Half-Nelson.c' Econet Privilege Escalation
The ipc subsystem in the Linux kernel before 2.6.37-rc1 does not initialize certain structures, which allows local users
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.36.2 (Ubuntu 10.04) - 'Half-Nelson.c' Econet Privilege Escalation
The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADM
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime - PICT PnSize Buffer Overflow (Metasploit)
Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a deni
50RISCO
abrir ↗Exploit-DB
BroadWin Webaccess Client - Multiple Vulnerabilities
Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code
23RISCO
abrir ↗Exploit-DB
BroadWin Webaccess Client - Multiple Vulnerabilities
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a m
23RISCO
abrir ↗Exploit-DB
Linux Kernel 3.0.0 - 'perf_count_sw_cpu_clock' event Denial of Service
The Performance Events subsystem in the Linux kernel before 3.1 does not properly handle event overflows associated with
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DVD X Player 5.5 - '.plf' Playlist Buffer Overflow (Metasploit)
Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Citrix Gateway - ActiveX Control Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Ed
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MapServer 6.0 - '.Map' File Double-Free Remote Denial of Service
Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Open Admin Tool 2.71 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in index.php in IBM OpenAdmin Tool (OAT) before 2.72 for Informix al
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
LifeSize Room - Command Injection (Metasploit)
The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitra
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Free MP3 CD Ripper 1.1 - Local Buffer Overflow
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RealVNC - Authentication Bypass (Metasploit)
RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers t
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Photoshop CS5 - '.gif' Remote Code Execution
Adobe Photoshop 12.0 in Creative Suite 5 (CS5) and 12.1 in Creative Suite 5.1 (CS5.1) allows remote attackers to execute
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP Easy Printer Care - XMLSimpleAccessor Class ActiveX Control Remote Code Execution (Metasploit)
A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to
60RISCO
abrir ↗Exploit-DB
WordPress Plugin Block-Spam-By-Math-Reloaded - Bypass
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the u
60RISCO
abrir ↗Exploit-DB
Apache - Remote Memory Exhaustion (Denial of Service)
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Secure Backup - Authentication Bypass/Command Injection (Metasploit)
Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect integrity via unknown vecto
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts < 2.2.0 - Remote Command Execution (Metasploit)
The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fishe
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.