Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.697exploits catalogados
36.715CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.264GitHub PoC 15.172VulnCheck XDB 8.920Nuclei 4.373Metasploit 3.493✓ só verificadosrecentespopularesrisco
24.475 exploits
Exploit-DB
xglance-bin 11.00 - Privilege Escalation
Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via u
38RISCO
abrir ↗Exploit-DB
Kronos WebTA 4.0 - Authenticated Remote Privilege Escalation
In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate se
41RISCO
abrir ↗Exploit-DB
Kronos WebTA 4.0 - Authenticated Remote Privilege Escalation
A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via
33RISCO
abrir ↗Exploit-DB
Verodin Director Web Console 3.5.4.0 - Remote Authenticated Password Disclosure (PoC)
An Information Disclosure issue in Verodin Director 3.5.3.1 and earlier reveals usernames and passwords of integrated se
23RISCO
abrir ↗Exploit-DB
Sudo 1.8.25p - 'pwfeedback' Buffer Overflow (PoC)
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir ↗Exploit-DB
School ERP System 1.0 - Cross Site Request Forgery (Add Admin)
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.
23RISCO
abrir ↗Exploit-DB
IceWarp WebMail 11.4.4.1 - Reflective Cross-Site Scripting
In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.
43RISCO
abrir ↗Exploit-DB
BearFTP 0.1.0 - 'PASV' Denial of Service
IKTeam BearFTP before 0.2.0 allows remote attackers to achieve denial of service via a large volume of connections to th
28RISCO
abrir ↗Exploit-DB
Jira 8.3.4 - Information Disclosure (Username Enumeration)
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate username
60RISCO
abrir ↗Exploit-DB
School ERP System 1.0 - Cross Site Request Forgery (Add Admin)
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrati
23RISCO
abrir ↗Exploit-DB
Cacti 1.2.8 - Authenticated Remote Code Execution
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISCO
abrir ↗Exploit-DB
Cacti 1.2.8 - Unauthenticated Remote Code Execution
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISCO
abrir ↗Exploit-DB
Schneider Electric U.Motion Builder 1.3.4 - Authenticated Command Injection
The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Ele
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSMTPD 6.6.1 - Remote Code Execution
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
rConfig 3.9.3 - Authenticated Remote Code Execution
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a
60RISCO
abrir ↗Exploit-DB
Satellian 1.12 - Remote Code Execution
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RISCO
abrir ↗Exploit-DB
Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php
23RISCO
abrir ↗Exploit-DB
Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
23RISCO
abrir ↗Exploit-DB
Microsoft Windows 10 - Theme API 'ThemePack' File Parsing
A remote code execution vulnerability exists when "Windows Theme API" does not properly decompress files, aka "Windows T
35RISCO
abrir ↗Exploit-DB
XMLBlueprint 16.191112 - XML External Entity Injection
XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password)
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
23RISCO
abrir ↗Exploit-DB
Octeth Oempro 4.8 - 'CampaignID' SQL Injection
Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
23RISCO
abrir ↗Exploit-DB
Microsoft Windows Kernel - Information Disclosure
Windows Kernel Information Disclosure Vulnerability
33RISCO
abrir ↗Exploit-DB
TP-Link TP-SG105E 1.0.0 - Unauthenticated Remote Reboot
The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the
35RISCO
abrir ↗Exploit-DB
Genexis Platinum-4410 2.1 - Authentication Bypass
An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cl
23RISCO
abrir ↗Exploit-DB
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
35RISCO
abrir ↗Exploit-DB
qdPM 9.1 - Remote Code Execution
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir ↗Exploit-DB
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Reliable Datagram Sockets (RDS) - rds_atomic_free_op NULL pointer dereference Privilege Escalation (Metasploit)
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning
43RISCO
abrir ↗Exploit-DB
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.