Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.930exploits catalogados
37.572CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 23.973GitHub PoC 15.478VulnCheck XDB 9.069Nuclei 4.426Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.482 exploits
Exploit-DB✓ VexDay Proof
Easy Online Shop - SQL Injection
SQL injection vulnerability in content.php in MH Products Easy Online Shop allows remote attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Win32k Pointer Dereferencement (PoC) (MS10-098)
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate user-
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Immo Makler Script - SQL Injection
SQL injection vulnerability in news.php in Immo Makler allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Radius Manager 3.6 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Radius Manager 3.8.0 allow remote authenticated administrators to
23RISCO
abrir ↗Exploit-DB
Radius Manager 3.8.0 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Radius Manager 3.8.0 allow remote authenticated administrators to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Altap Salamander 2.5 PE Viewer - Local Buffer Overflow (Metasploit)
Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (Englis
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe PDF - Escape EXE Social Engineering (No JavaScript) (Metasploit)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component JRadio - Local File Inclusion
Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to r
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Exim4 < 4.69 - string_format Function Heap Buffer Overflow (Metasploit)
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to exe
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Exim4 < 4.69 - string_format Function Heap Buffer Overflow (Metasploit)
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specif
91RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe PDF - Embedded EXE Social Engineering (Metasploit)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISCO
abrir ↗Exploit-DB
Blog:CMS 4.2.1e - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in admin/libs/ADMIN.php in BLOG:CMS 4.2.1.e, and possibly earlier, allow
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Java - 'Statement.invoke()' Trusted Method Chain (Metasploit)
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18,
100RISCO
abrir ↗Exploit-DB
Mantis Bug Tracker 1.2.3 - 'db_type' Local File Inclusion
Directory traversal vulnerability in admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to in
23RISCO
abrir ↗Exploit-DB
Mantis Bug Tracker 1.2.3 - 'db_type' Cross-Site Scripting / Full Path Disclosure
admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to obtain sensitive information via an inv
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 8 - CSS Parser
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in msh
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Tivoli Storage Manager (TSM) - Local Privilege Escalation
Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in
23RISCO
abrir ↗Exploit-DB
Mantis Bug Tracker 1.2.3 - 'db_type' Cross-Site Scripting / Full Path Disclosure
Cross-site scripting (XSS) vulnerability in admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attacker
23RISCO
abrir ↗Exploit-DB
Pointter PHP Content Management System - Unauthorized Privilege Escalation
Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative pr
23RISCO
abrir ↗Exploit-DB
Blog:CMS 4.2.1e - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to
23RISCO
abrir ↗Exploit-DB
BEdita 3.0.1.2550 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in BEdita before 3.1 allow remote attackers to hijack the aut
23RISCO
abrir ↗Exploit-DB
Pointter PHP Micro-Blogging Social Network - Unauthorized Privilege Escalation
Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrativ
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
gitWeb 1.7.3.3 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web s
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'search.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.1.3712 allows remote attack
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Axis2 / SAP BusinessObjects - (Authenticated) Code Execution (via SOAP) (Metasploit)
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISCO
abrir ↗Exploit-DB
FontForge - '.BDF' Font File Stack Buffer Overflow (PoC)
Stack-based buffer overflow in FontForge 20100501 allows remote attackers to cause a denial of service (application cras
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Axis2 - (Authenticated) Code Execution (via REST) (Metasploit)
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - DHTML Behaviour Use-After-Free (MS10-018) (Metasploit)
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, an
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to exe
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.