Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.858exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.346GitHub PoC 15.209VulnCheck XDB 8.944Nuclei 4.383Metasploit 3.501✓ só verificadosrecentespopularesrisco
3.501 exploits
Metasploit200
VirtualBox Guest Additions VBoxGuest.sys Privilege Escalation
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.2
38RISCO
abrir ↗Metasploit300
Flash "Rosetta" JSONP GET/POST Response Disclosure
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Ad
23RISCO
abrir ↗Metasploit600
Wordpress MailPoet Newsletters (wysija-newsletters) Unauthenticated File Upload
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authen
50RISCO
abrir ↗Metasploit600
Gitlist Unauthenticated Remote Command Execution
Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in
60RISCO
abrir ↗Metasploit600
VMTurbo Operations Manager vmtadmin.cgi Remote Command Execution
vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands
60RISCO
abrir ↗Metasploit600
Wing FTP Server Authenticated Command Execution
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir ↗Metasploit600
ManageEngine Desktop Central / Password Manager LinkViewFetchServlet.dat SQL Injection
SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central
50RISCO
abrir ↗Metasploit300
OpenSSL DTLS Fragment Buffer Overflow DoS
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0
40RISCO
abrir ↗Metasploit300
OpenSSL Server-Side ChangeCipherSpec Injection Scanner
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCiph
60RISCO
abrir ↗Metasploit0
Chkrootkit Local Privilege Escalation
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a
38RISCO
abrir ↗Metasploit300
Ericom AccessNow Server Buffer Overflow
Stack-based buffer overflow in AccessServer32.exe in Ericom AccessNow Server allows remote attackers to execute arbitrar
50RISCO
abrir ↗Metasploit300
Yokogawa CS3000 BKFSim_vhfd.exe Buffer Overflow
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM V
50RISCO
abrir ↗Metasploit300
D-Link info.cgi POST Request Buffer Overflow
D-Link info.cgi POST Request Stack-Based Buffer Overflow RCE
63RISCO
abrir ↗Metasploit300
Easy File Management Web Server Stack Buffer Overflow
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code
60RISCO
abrir ↗Metasploit300
D-Link HNAP Request Remote Buffer Overflow
Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06
60RISCO
abrir ↗Metasploit600
Symantec Workspace Streaming ManagementAgentServer.putFile XMLRPC Request Arbitrary File Upload
The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functional
50RISCO
abrir ↗Metasploit300
AlienVault Authenticated SQL Injection Arbitrary File Read
SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL
43RISCO
abrir ↗Metasploit300
Belkin Play N750 login.cgi Buffer Overflow
Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote a
50RISCO
abrir ↗Metasploit600
AlienVault OSSIM av-centerd Command Injection
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a
60RISCO
abrir ↗Metasploit600
Android 'Towelroot' Futex Requeue Kernel Exploit
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISCO
abrir ↗Metasploit0
Cogent DataHub Command Injection
GetPermissions.asp in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary
50RISCO
abrir ↗Metasploit500
Adobe Flash Player Shader Buffer Overflow
Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS
60RISCO
abrir ↗Metasploit300
Wireshark CAPWAP Dissector DoS
The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.
50RISCO
abrir ↗Metasploit500
Adobe Flash Player ByteArray UncompressViaZlibVariant Use After Free
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Window
100RISCO
abrir ↗Metasploit600
AlienVault OSSIM SQL Injection and Remote Code Execution
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5
43RISCO
abrir ↗Metasploit600
Oracle Event Processing FileUploadServlet Arbitrary File Upload
Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote
50RISCO
abrir ↗Metasploit500
Adobe Flash Player domainMemory ByteArray Use After Free
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and
60RISCO
abrir ↗Metasploit400
Adobe Reader for Android addJavascriptInterface Exploit
The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows r
60RISCO
abrir ↗Metasploit300
Cisco ASA SSL VPN Privilege Escalation Vulnerability
Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.48), 8.3 before 8.3(2.40), 8.4 before 8.4(7.9), 8.6 be
23RISCO
abrir ↗Metasploit300
Advantech WebAccess DBVisitor.dll ChartThemeConfig SQL Injection
Advantech WebAccess SQL Injection
41RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.