Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
82.322exploits catalogados
38.524CVEs com exploração pública
24.695testados em laboratório
TodosReferência 24.711Exploit-DB 24.485GitHub PoC 15.927VulnCheck XDB 9.231Nuclei 4.455Metasploit 3.513✓ só verificadosrecentespopularesrisco
82.322 exploits
VulnCheck XDB
local
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISCO
abrir ↗Exploit-DB
Froxlor 2.0.3 Stable - Remote Code Execution (RCE)
Command Injection in froxlor/froxlor
78RISCO
abrir ↗Exploit-DB
Apache Tomcat 10.1 - Denial Of Service
EncryptInterceptor does not provide complete protection on insecure networks
45RISCO
abrir ↗Exploit-DB
Dell EMC Networking PC5500 firmware versions 4.1.0.22 and Cisco Sx / SMB - Information Disclosure
Cisco Small Business Switches Information Disclosure Vulnerability
46RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Answerdev 1.0.3 - Account Takeover
Improper Access Control in answerdev/answer
48RISCO
abrir ↗Exploit-DB
D-Link DIR-846 - Remote Command Execution (RCE) vulnerability
D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan
46RISCO
abrir ↗Exploit-DB
Liferay Portal 6.2.5 - Insecure Permissions
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The
53RISCO
abrir ↗Metasploit300
ThinManager Path Traversal (CVE-2023-27855) Arbitrary File Upload
Rockwell Automation ThinManager ThinServer Path Traversal Upload
48RISCO
abrir ↗Metasploit300
ThinManager Path Traversal (CVE-2023-27856) Arbitrary File Download
Rockwell Automation ThinManager ThinServer Path Traversal Download
58RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BTCPay Server v1.7.4 - HTML Injection
Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Responsive FileManager 9.9.5 - Remote Code Execution (RCE)
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RISCO
abrir ↗GitHub PoC★ 3
brosck/CVE-2006-3392
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISCO
abrir ↗VulnCheck XDB
initial-access
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RISCO
abrir ↗VulnCheck XDB
initial-access
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗Metasploit600
Pentaho Business Server Auth Bypass and Server Side Template Injection RCE
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RISCO
abrir ↗Metasploit600
Pentaho Business Server Auth Bypass and Server Side Template Injection RCE
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RISCO
abrir ↗VulnCheck XDB
initial-access
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir ↗VulnCheck XDB
infoleak
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗GitHub PoC★ 2
CVE-2014-6287
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir ↗VulnCheck XDB
initial-access
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RISCO
abrir ↗GitHub PoC
docker for CVE-2022-42889
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗GitHub PoC★ 8
Poc for CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗Exploit-DB
Metform Elementor Contact Form Builder v3.1.2 - Unauthenticated Stored Cross-Site Scripting (XSS)
Metform Elementor Contact Form Builder <= 3.1.2 - Unauthenticated Stored Cross-Site Scripting
46RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Roxy WI v6.1.0.0 - Improper Authentication Control
Authentication Bypass in Roxy-wi
53RISCO
abrir ↗VulnCheck XDB
infoleak
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗Exploit-DB
GLPI v10.0.2 - SQL Injection (Authentication Depends on Configuration)
SQL injection with _actor parameter in GLPI
48RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE)
Unauthenticated Remote Code Execution in Roxy-wi
75RISCO
abrir ↗Exploit-DB
GLPI 4.0.2 - Unauthenticated Local File Inclusion on Manageentities plugin
The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.p
41RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.