Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.781exploits catalogados
36.771CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.305GitHub PoC 15.197VulnCheck XDB 8.932Nuclei 4.379Metasploit 3.493✓ só verificadosrecentespopularesrisco
24.475 exploits
Exploit-DB✓ VexDay Proof
Microsoft DirectWrite - Invalid Read in SplicePixel While Processing OTF Fonts
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft DirectWrite - Out-of-Bounds Read in sfac_GetSbitBitmap While Processing TTF Fonts
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
28RISCO
abrir ↗Exploit-DB
WordPress Plugin Photo Gallery 1.5.34 - SQL Injection
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/control
28RISCO
abrir ↗Exploit-DB
WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting (2)
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
October CMS - Upload Protection Bypass Code Execution (Metasploit)
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
LibreNMS - Collectd Command Injection (Metasploit)
An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/dev
60RISCO
abrir ↗Exploit-DB
Enigma NMS 65.0.0 - Cross-Site Request Forgery
A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to tri
23RISCO
abrir ↗Exploit-DB
Enigma NMS 65.0.0 - OS Command Injection
An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows
43RISCO
abrir ↗Exploit-DB
Enigma NMS 65.0.0 - SQL Injection
A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows a
23RISCO
abrir ↗Exploit-DB
FusionPBX 4.4.8 - Remote Code Execution
FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service
28RISCO
abrir ↗Exploit-DB
Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Remote Code Execution
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AwindInc SNMP Service - Command Injection (Metasploit)
Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote
60RISCO
abrir ↗Exploit-DB
DASAN Zhone ZNID GPON 2426A EU - Multiple Cross-Site Scripting
Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devic
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Download Manager 2.9.93 - Cross-Site Scripting
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by t
53RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Data Center Network Manager - Unauthenticated Remote Code Execution (Metasploit)
Cisco Data Center Network Manager Information Disclosure Vulnerability
70RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Data Center Network Manager - Unauthenticated Remote Code Execution (Metasploit)
Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability
85RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco RV110W/RV130(W)/RV215W Routers Management Interface - Remote Command Execution (Metasploit)
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco UCS Director - default scpuser password (Metasploit)
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
85RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Data Center Network Manager - Unauthenticated Remote Code Execution (Metasploit)
Cisco Data Center Network Manager Authentication Bypass Vulnerability
85RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ktsuss 1.4 - suid Privilege Escalation (Metasploit)
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified com
60RISCO
abrir ↗Exploit-DB
Craft CMS 2.7.9/3.2.5 - Information Disclosure
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images whe
23RISCO
abrir ↗Exploit-DB
Alkacon OpenCMS 10.5.x - Cross-Site Scripting
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
23RISCO
abrir ↗Exploit-DB
Alkacon OpenCMS 10.5.x - Local File inclusion
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an atta
23RISCO
abrir ↗Exploit-DB
Alkacon OpenCMS 10.5.x - Cross-Site Scripting
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.
23RISCO
abrir ↗Exploit-DB
Alkacon OpenCMS 10.5.x - Cross-Site Scripting (2)
In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the man
23RISCO
abrir ↗Exploit-DB
Opencart 3.x - Cross-Site Scripting
OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing fe
23RISCO
abrir ↗Exploit-DB
Asus Precision TouchPad 11.0.0.25 - Denial of Service
AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP devic
28RISCO
abrir ↗Exploit-DB
DomainMod 4.13 - Cross-Site Scripting
In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.
38RISCO
abrir ↗Exploit-DB
WordPress Plugin WooCommerce Product Feed 2.2.18 - Cross-Site Scripting
WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.