Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.781exploits catalogados
36.771CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.305GitHub PoC 15.197VulnCheck XDB 8.932Nuclei 4.379Metasploit 3.493✓ só verificadosrecentespopularesrisco
24.475 exploits
Exploit-DB
CBAS-Web 19.0.0 - Username Enumeration
Computrols CBAS 18.0.0 allows Username Enumeration.
23RISCO
abrir ↗Exploit-DB
Optergy 2.3.0a - Remote Code Execution (Backdoor)
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
60RISCO
abrir ↗Exploit-DB
Adrenalin Core HCM 5.4.0 - 'prntDDLCntrlName' Reflected Cross-Site Scripting
Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSe
23RISCO
abrir ↗Exploit-DB
CBAS-Web 19.0.0 - Cross-Site Request Forgery (Add Super Admin)
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
23RISCO
abrir ↗Exploit-DB
Optergy 2.3.0a - Cross-Site Request Forgery (Add Admin)
Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
23RISCO
abrir ↗Exploit-DB
Adrenalin Core HCM 5.4.0 - 'strAction' Reflected Cross-Site Scripting
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
An out-of-bounds read was addressed with improved input validation.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed OTF Font (CFF Table)
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
rConfig - install Command Execution (Metasploit)
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISCO
abrir ↗Exploit-DB
Adive Framework 2.0.7 - Privilege Escalation
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an ad
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Android Janus - APK Signature Bypass (Metasploit)
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RISCO
abrir ↗Exploit-DB
Jenkins build-metrics plugin 1.3 - 'label' Cross-Site Scripting
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
JavaScriptCore - Type Confusion During Bailout when Reconstructing Arguments Objects
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPad
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Micro Focus (HPE) Data Protector - SUID Privilege Escalation (Metasploit)
Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30,
38RISCO
abrir ↗Exploit-DB
Apache Solr 8.2.0 - Remote Code Execution
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Nostromo - Directory Traversal Remote Command Execution (Metasploit)
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir ↗Exploit-DB
MikroTik RouterOS 6.45.6 - DNS Cache Poisoning
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queri
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
JavaScriptCore - GetterSetter Type Confusion During DFG Compilation
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Proc
23RISCO
abrir ↗Exploit-DB
Microsoft Windows Server 2012 - 'Group Policy' Remote Code Execution (MS15-011)
The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Wind
28RISCO
abrir ↗Exploit-DB
rConfig 3.9.2 - Remote Code Execution
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISCO
abrir ↗Exploit-DB
Microsoft Windows Server 2012 - 'Group Policy' Security Feature Bypass (MS15-014)
The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, W
23RISCO
abrir ↗Exploit-DB
PHP-FPM + Nginx - Remote Code Execution
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir ↗Exploit-DB
ClonOs WEB UI 19.09 - Improper Access Control
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests be
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Polkit - pkexec helper PTRACE_TRACEME local root (Metasploit)
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir ↗Exploit-DB
Rocket.Chat 2.1.0 - Cross-Site Scripting
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
23RISCO
abrir ↗Exploit-DB
Moxa EDR-810 - Command Injection / Information Disclosure
Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthor
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Total.js CMS 12 - Widget JavaScript Code Injection (Metasploit)
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote
60RISCO
abrir ↗Exploit-DB
Moxa EDR-810 - Command Injection / Information Disclosure
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.