Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8.946Nuclei 4.390Metasploit 3.501✓ só verificadosrecentespopularesrisco
3.501 exploits
Metasploit300
KingView Log File Parsing Buffer Overflow
Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView
50RISCO
abrir ↗Metasploit300
CUPS 1.6.1 Root File Read
CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator
18RISCO
abrir ↗Metasploit300
NFR Agent FSFUI Record Arbitrary Remote File Access
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrar
60RISCO
abrir ↗Metasploit300
NFR Agent SRS Record Arbitrary Remote File Access
Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbi
50RISCO
abrir ↗Metasploit300
NFR Agent Heap Overflow Vulnerability
Heap-based buffer overflow in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to execute arbitrary co
30RISCO
abrir ↗Metasploit500
NFR Agent FSFUI Record File Upload RCE
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and ex
60RISCO
abrir ↗Metasploit600
NetIQ Privileged User Manager 2.3.1 ldapagnt_eval() Remote Perl Code Execution
Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manage
50RISCO
abrir ↗Metasploit600
WordPress Plugin Advanced Custom Fields Remote File Inclusion
WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusion
63RISCO
abrir ↗Metasploit600
Narcissus Image Configuration Passthru Vulnerability
Narcissus backend.php Image Configuration Command Injection
63RISCO
abrir ↗Metasploit300
VMWare OVF Tools Format String Vulnerability
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Pl
50RISCO
abrir ↗Metasploit300
VMWare OVF Tools Format String Vulnerability
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Pl
50RISCO
abrir ↗Metasploit300
Apple QuickTime 7.7.2 TeXML Style Element font-table Field Stack Buffer Overflow
Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a de
50RISCO
abrir ↗Metasploit300
Apple QuickTime 7.7.2 MIME Type Buffer Overflow
Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause
50RISCO
abrir ↗Metasploit300
Axigen Arbitrary File Read and Delete
Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote att
60RISCO
abrir ↗Metasploit600
Invision IP.Board unserialize() PHP Code Execution
Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3
43RISCO
abrir ↗Metasploit300
ClanSphere 2011.3 Local File Inclusion Vulnerability
ClanSphere 2011.3 Local File Inclusion via cs_lang Cookie
36RISCO
abrir ↗Metasploit300
Bitweaver overlay_type Directory Traversal
Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to rea
50RISCO
abrir ↗Metasploit600
Mutiny Remote Command Execution
Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, re
43RISCO
abrir ↗Metasploit300
Drupal OpenID External Entity Injection
The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE d
23RISCO
abrir ↗Metasploit600
Ektron 8.02 XSLT Transform Remote Code Execution
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true
50RISCO
abrir ↗Metasploit600
Sun Java Web Start Double Quote Injection
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and
50RISCO
abrir ↗Metasploit600
Java Applet AverageRangeStatisticImpl Remote Code Execution
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
100RISCO
abrir ↗Metasploit600
Java Applet JAX-WS Remote Code Execution
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
100RISCO
abrir ↗Metasploit600
Java Applet Method Handle Remote Code Execution
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
60RISCO
abrir ↗Metasploit500
Windows Escalate Service Permissions Local Privilege Escalation
Active Directory Domain Services Elevation of Privilege Vulnerability
41RISCO
abrir ↗Metasploit300
MS11-081 Microsoft Internet Explorer Option Element Use-After-Free
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to exe
50RISCO
abrir ↗Metasploit600
Project Pier Arbitrary File Upload Vulnerability
Project Pier <= 0.8.8 Arbitrary File Upload RCE
63RISCO
abrir ↗Metasploit600
PhpTax pfilez Parameter Exec Remote Code Injection
PhpTax pfilez Parameter Exec Remote Code Injection
63RISCO
abrir ↗Metasploit0
D-Link DIR-605L Captcha Handling Buffer Overflow
D-Link DIR-605L Captcha Handling Buffer Overflow
63RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.