Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.697exploits catalogados
36.715CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.264GitHub PoC 15.172VulnCheck XDB 8.920Nuclei 4.373Metasploit 3.493✓ só verificadosrecentespopularesrisco
24.475 exploits
Exploit-DB
qdPM 9.1 - Remote Code Execution
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Reliable Datagram Sockets (RDS) - rds_atomic_free_op NULL pointer dereference Privilege Escalation (Metasploit)
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning
43RISCO
abrir ↗Exploit-DB
Citrix XenMobile Server 10.8 - XML External Entity Injection
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 befor
23RISCO
abrir ↗Exploit-DB
Ricoh Printer Drivers - Local Privilege Escalation
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attacker
38RISCO
abrir ↗Exploit-DB
Microsoft SharePoint - Deserialization Remote Code Execution
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISCO
abrir ↗Exploit-DB
Centreon 19.04 - Authenticated Remote Code Execution (Metasploit)
Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code
28RISCO
abrir ↗Exploit-DB
Easy XML Editor 1.7.8 - XML External Entity Injection
Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Plantronics Hub 3.13.2 - SpokesUpdateService Privilege Escalation (Metasploit)
A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application
38RISCO
abrir ↗Exploit-DB
Jenkins Gitlab Hook Plugin 1.4.2 - Reflected Cross-Site Scripting
Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a ref
60RISCO
abrir ↗Exploit-DB
Citrix Application Delivery Controller (ADC) and Gateway 13.0 - Path Traversal
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗Exploit-DB
WordPress Plugin Postie 1.9.40 - Persistent Cross-Site Scripting
The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginn
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Barco WePresent - file_transfer.cgi Command Injection (Metasploit)
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RISCO
abrir ↗Exploit-DB
Microsoft Windows - CryptoAPI (Crypt32.dll) Elliptic Curve Cryptography (ECC) Spoof Code-Signing Certificate
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Android - ashmem Readonly Bypasses via remap_file_pages() and ASHMEM_UNPIN
In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This
23RISCO
abrir ↗Exploit-DB
Digi AnywhereUSB 14 - Reflective Cross-Site Scripting
Digi AnywhereUSB 14 allows XSS via a link for the Digi Page.
23RISCO
abrir ↗Exploit-DB
Citrix Application Delivery Controller and Gateway 10.5 - Remote Code Execution (Metasploit)
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗Exploit-DB
Citrix Application Delivery Controller and Citrix Gateway - Remote Code Execution (PoC)
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗Exploit-DB
Citrix Application Delivery Controller and Citrix Gateway - Remote Code Execution
Cisco Firepower Threat Defense Software Stream Reassembly Bypass Vulnerability
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TotalAV 2020 4.14.31 - Privilege Escalation
TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junctio
23RISCO
abrir ↗Exploit-DB
PixelStor 5000 K:4.0.1580-20150629 - Remote Code Execution
languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to re
53RISCO
abrir ↗Exploit-DB
Oracle Weblogic 10.3.6.0.0 - Remote Command Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISCO
abrir ↗Exploit-DB
EBBISLAND EBBSHAVE 6100-09-04-1441 - Remote Buffer Overflow
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported ve
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
JetBrains TeamCity 2018.2.4 - Remote Code Execution
An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in
28RISCO
abrir ↗Exploit-DB
Cisco DCNM JBoss 10.4 - Credential Leakage
Cisco Data Center Network Manager JBoss EAP Unauthorized Access Vulnerability
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
piSignage 2.6.4 - Directory Traversal
The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user)
23RISCO
abrir ↗Exploit-DB
Microsoft Windows 10 (19H1 1901 x64) - 'ws2ifsl.sys' Use After Free Local Privilege Escalation (kASLR kCFG SMEP)
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Win
76RISCO
abrir ↗Exploit-DB
Microsoft Windows - Shell COM Server Registrar Local Privilege Escalation
Windows Elevation of Privilege Vulnerability
55RISCO
abrir ↗Exploit-DB✓ VexDay Proof
nostromo 1.9.6 - Remote Code Execution
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir ↗Exploit-DB
Sony Playstation 4 (PS4) < 6.72 - WebKit Code Execution (PoC)
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD - Dynamic Loader chpass Privilege Escalation (Metasploit)
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.