Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.930exploits catalogados
37.572CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 23.973GitHub PoC 15.478VulnCheck XDB 9.069Nuclei 4.426Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.482 exploits
Exploit-DB✓ VexDay Proof
Comcast DOCSIS 3.0 Business Gateways - Multiple Vulnerabilities
A certain Comcast Business Gateway configuration of the SMC SMCD3G-CCR with firmware before 1.4.0.49.2 has a default pas
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Comcast DOCSIS 3.0 Business Gateways - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the SMC SMCD3G-CCR (aka Comcast Busin
23RISCO
abrir ↗Exploit-DB
VideoLAN VLC Media Player 1.1 - Subtitle 'StripTags()' Memory Corruption
The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text decoder (modules/code
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Majordomo2 - 'SMTP/HTTP' Directory Traversal
Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allo
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark 1.4.3 - '.pcap' Memory Corruption
Wireshark 1.2.0 through 1.2.14, 1.4.0 through 1.4.3, and 1.5.0 frees an uninitialized pointer during processing of a .pc
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Majordomo2 - 'SMTP/HTTP' Directory Traversal
The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct d
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Tandberg E & EX & C Series Endpoints - Default Root Account Credentials
The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with softwar
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RedaxScript 0.3.2 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in includes/password.php in Redaxscript 0.3.2 allow remote attackers to execute a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Terminal Server Client - '.rdp' Denial of Service
Multiple stack-based buffer overflows in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tscli
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zikula CMS 1.2.4 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Terminal Server Client - '.rdp' Denial of Service
Stack-based buffer overflow in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 0.9.4 - TiVo Buffer Overflow (Metasploit)
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Moodle 2.0.1 - 'PHPCOVERAGE_HOME' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Spike PHPCoverage (aka spikephpcoverage) library, as used in Moodle 2.0.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Java - Floating-Point Value Denial of Service
The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenVAS Manager - Command Injection
The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authent
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - MHTML Protocol Handler Cross-Site Scripting
The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Wind
45RISCO
abrir ↗Exploit-DB
Oracle - Document Capture Insecure READ Method
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 all
28RISCO
abrir ↗Exploit-DB
Oracle Document Capture - Actbar2.ocx Insecure Method
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 all
28RISCO
abrir ↗Exploit-DB
Oracle Document Capture 10.1.3.5 - Insecure Method / Buffer Overflow
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 all
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AWCM 2.2 Final - Local File Inclusion
Multiple directory traversal vulnerabilities in AR Web Content Manager (AWCM) 2.2 allow remote attackers to read arbitra
23RISCO
abrir ↗Exploit-DB
Oracle Document Capture - 'empop3.dll' Insecure Methods
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 all
28RISCO
abrir ↗Exploit-DB
Sun Microsystems SunScreen Firewall - Privilege Escalation
Multiple untrusted search path vulnerabilities in the Java Service in Sun Microsystems SunScreen Firewall on SunOS 5.9 a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PivotX 2.2 - '/pivotx/includes/timwrapper.php?src' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow rem
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PivotX 2.2 - '/pivotx/includes/blogroll.php?color' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow rem
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PivotX 2.2.2 - 'module_image.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attacke
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ActiveWeb Professional 3.0 - Arbitrary File Upload
Unrestricted file upload vulnerability in the EasyEdit module in Lomtec ActiveWeb Professional 3.0 allows remote attacke
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Automated Solutions Modbus/TCP OPC Server - Remote Heap Corruption (PoC)
Heap-based buffer overflow in Automated Solutions Modbus/TCP Master OPC Server before 3.0.2 allows remote attackers to c
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server - sp_replwritetovarbin Memory Corruption (MS09-004) (Metasploit)
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Golden FTP Server 4.70 - 'PASS' Buffer Overflow
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin RSS Feed Reader 0.1 - 'rss_url' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in RSS Feed Reader 0.1 for WordPress allo
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.