Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.865exploits catalogados
36.827CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.346GitHub PoC 15.209VulnCheck XDB 8.944Nuclei 4.390Metasploit 3.501✓ só verificadosrecentespopularesrisco
3.501 exploits
Metasploit300
Mac OS X Safari file:// Redirection Sandbox Escape
The history implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allo
23RISCO
abrir ↗Metasploit500
Oracle Forms and Reports Remote Code Execution
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
60RISCO
abrir ↗Metasploit500
Oracle Forms and Reports Remote Code Execution
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
100RISCO
abrir ↗Metasploit400
KingScada kxClientDownload.ocx ActiveX Remote Code Execution
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before
50RISCO
abrir ↗Metasploit500
HP AutoPass License Server File Upload
Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoP
60RISCO
abrir ↗Metasploit600
GetSimpleCMS PHP File Upload Vulnerability
GetSimple CMS 3.2.1 Authenticated RCE via Arbitrary PHP File Upload
36RISCO
abrir ↗Metasploit500
HP Client Automation Command Injection
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RISCO
abrir ↗Metasploit500
HP Data Protector Backup Client Service Directory Traversal
Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a
50RISCO
abrir ↗Metasploit600
HP Data Protector Backup Client Service Remote Code Execution
The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary
50RISCO
abrir ↗Metasploit500
SerComm Device Remote Code Execution
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x
60RISCO
abrir ↗Metasploit300
SerComm Network Device Backdoor Detection
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x
60RISCO
abrir ↗Metasploit300
IBM Lotus Notes Sametime Room Name Bruteforce
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine whic
18RISCO
abrir ↗Metasploit300
IBM Lotus Notes Sametime User Enumeration
Unspecified vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remot
23RISCO
abrir ↗Metasploit300
IBM Lotus Sametime Version Enumeration
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to obtain unspeci
23RISCO
abrir ↗Metasploit300
RealNetworks RealPlayer Version Attribute Buffer Overflow
Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before
50RISCO
abrir ↗Metasploit300
IcoFX Stack Buffer Overflow
Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCoun
50RISCO
abrir ↗Metasploit500
MS13-097 Registry Symlink IE Sandbox Escape
Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and conseque
43RISCO
abrir ↗Metasploit300
Adobe Flash Player Type Confusion Remote Code Execution
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2
60RISCO
abrir ↗Metasploit600
ElasticSearch Dynamic Script Arbitrary Java Execution
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RISCO
abrir ↗Metasploit600
Zimbra Collaboration Server LFI
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RISCO
abrir ↗Metasploit300
IBM Forms Viewer Unicode Buffer Overflow
Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to exe
50RISCO
abrir ↗Metasploit300
Ruby on Rails Action View MIME Memory Exhaustion
actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allo
23RISCO
abrir ↗Metasploit200
Windows NTUserMessageCall Win32k Kernel Pool Overflow (Schlamperei)
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W
43RISCO
abrir ↗Metasploit600
WordPress OptimizePress Theme File Upload Vulnerability
Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-
23RISCO
abrir ↗Metasploit200
MS14-002 Microsoft Windows ndproxy.sys Local Privilege Escalation
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges
98RISCO
abrir ↗Metasploit300
Total Video Player 1.3.1 (Settings.ini) - SEH Buffer Overflow
Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary
43RISCO
abrir ↗Metasploit300
Ruby on Rails JSON Processor Floating Point Heap Overflow DoS
Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and tru
30RISCO
abrir ↗Metasploit600
Idera Up.Time Monitoring Station 7.0 post2file.php Arbitrary File Upload
Idera Up.Time ≤ 7.2 post2file.php Arbitrary File Upload RCE
63RISCO
abrir ↗Metasploit300
Red Hat CloudForms Management Engine 5.1 miq_policy/explorer SQL Injection
SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and Mana
23RISCO
abrir ↗Metasploit300
Huawei Datacard Information Disclosure Vulnerability
The Huawei E355 adapter with firmware 21.157.37.01.910 does not require authentication for API pages, which allows remot
18RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.