Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8.946Nuclei 4.390Metasploit 3.501✓ só verificadosrecentespopularesrisco
3.501 exploits
Metasploit500
Turbo FTP Server 1.30.823 PORT Overflow
Turbo FTP Server 1.30.823/826 PORT Command Buffer Overflow
43RISCO
abrir ↗Metasploit300
phpMyAdmin 3.5.2.2 server_sync.php Backdoor
phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an e
60RISCO
abrir ↗Metasploit600
Kloxo Local Privilege Escalation
Kloxo <= 6.1.12 Local Privilege Escalation
36RISCO
abrir ↗Metasploit400
MS12-063 Microsoft Internet Explorer execCommand Use-After-Free Vulnerability
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 al
100RISCO
abrir ↗Metasploit600
Auxilium RateMyPet Arbitrary File Upload Vulnerability
Auxilium RateMyPet Arbitrary File Upload RCE
63RISCO
abrir ↗Metasploit600
ZEN Load Balancer Filelog Command Execution
ZEN Load Balancer Filelog Command Execution
63RISCO
abrir ↗Metasploit300
Webmin edit_html.cgi file Parameter Traversal Arbitrary File Access
file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited
23RISCO
abrir ↗Metasploit600
Webmin /file/show.cgi Remote Command Execution
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir ↗Metasploit600
Openfiler v2.x NetworkCard Command Execution
Openfiler v2.x NetworkCard Command Execution
63RISCO
abrir ↗Metasploit300
EMC Networker Format String
Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.
50RISCO
abrir ↗Metasploit300
HP Intelligent Management Center UAM Buffer Overflow
Stack-based buffer overflow in uam.exe in the User Access Manager (UAM) component in HP Intelligent Management Center (I
50RISCO
abrir ↗Metasploit400
HP SiteScope Remote Code Execution
Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbit
30RISCO
abrir ↗Metasploit400
HP SiteScope Remote Code Execution
Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbit
30RISCO
abrir ↗Metasploit300
ActiveFax (ActFax) 4.3 Client Importer Buffer Overflow
ActFax 4.32 Client Importer Buffer Overflow
43RISCO
abrir ↗Metasploit600
Symantec Messaging Gateway 9.5 Default SSH Password Vulnerability
Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier fo
50RISCO
abrir ↗Metasploit600
Java 7 Applet Remote Code Execution
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow
100RISCO
abrir ↗Metasploit600
XODA 0.4.5 Arbitrary PHP File Upload Vulnerability
XODA 0.4.5 Arbitrary PHP File Upload
63RISCO
abrir ↗Metasploit600
E-Mail Security Virtual Appliance learn-msg.cgi Command Injection
E-Mail Security Virtual Appliance learn-msg.cgi Command Injection
63RISCO
abrir ↗Metasploit600
TestLink v1.9.3 Arbitrary File Upload Vulnerability
Multiple SQL injection vulnerabilities in TestLink 1.9.3, 1.8.5b, and earlier allow remote authenticated users with cert
18RISCO
abrir ↗Metasploit600
Viscosity setuid-set ViscosityHelper Privilege Escalation
A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the se
50RISCO
abrir ↗Metasploit600
Setuid Tunnelblick Privilege Escalation
Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname o
38RISCO
abrir ↗Metasploit600
MobileCartly 1.0 Arbitrary File Creation Vulnerability
MobileCartly 1.0 savepage.php Arbitrary File Creation
63RISCO
abrir ↗Metasploit300
Adobe Flash Player 11.3 Kern Table Parsing Integer Overflow
Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on L
100RISCO
abrir ↗Metasploit600
Cyclope Employee Surveillance Solution v6 SQL Injection
Cyclope Employee Surveillance Solution v6.x SQL Injection
43RISCO
abrir ↗Metasploit400
Zenoss 3 showDaemonXMLConfig Command Execution
Zenoss 3.x showDaemonXMLConfig Command Execution
36RISCO
abrir ↗Metasploit300
Ubisoft uplay 2.0.3 ActiveX Control Arbitrary Code Execution
The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -
50RISCO
abrir ↗Metasploit300
Sysax Multi Server 5.64 Create Folder Buffer Overflow
Stack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users w
50RISCO
abrir ↗Metasploit300
Plixer Scrutinizer NetFlow and sFlow Analyzer HTTP Authentication Bypass
cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not requir
50RISCO
abrir ↗Metasploit600
Plixer Scrutinizer NetFlow and sFlow Analyzer 9 Default MySQL Credential
The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default passwor
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.