Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8.946Nuclei 4.390Metasploit 3.501✓ só verificadosrecentespopularesrisco
3.501 exploits
Metasploit300
Plixer Scrutinizer NetFlow and sFlow Analyzer HTTP Authentication Bypass
cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not requir
50RISCO
abrir ↗Metasploit600
Symantec Web Gateway 5.0.2.18 pbcontrol.php Command Injection
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary comman
50RISCO
abrir ↗Metasploit600
Dell SonicWALL (Plixer) Scrutinizer 9 SQL Injection
SQL injection vulnerability in d4d/statusFilter.php in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.2
50RISCO
abrir ↗Metasploit300
Simple Web Server Connection Header Buffer Overflow
Simple Web Server Connection Header Buffer Overflow
63RISCO
abrir ↗Metasploit300
Cisco Linksys PlayerPT ActiveX Control SetSource sURL Argument Buffer Overflow
Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.o
50RISCO
abrir ↗Metasploit300
WebPageTest Directory Traversal
www/getfile.php in WPO WebPageTest 19.04 on Windows allows Directory Traversal (for reading arbitrary files) because of
18RISCO
abrir ↗Metasploit600
WebPageTest Arbitrary PHP File Upload
WebPageTest Arbitrary PHP File Upload RCE
63RISCO
abrir ↗Metasploit300
HP Operations Agent Opcode coda.exe 0x34 Buffer Overflow
Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via u
50RISCO
abrir ↗Metasploit300
HP Operations Agent Opcode coda.exe 0x8c Buffer Overflow
Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via u
50RISCO
abrir ↗Metasploit600
EGallery PHP File Upload Vulnerability
EGallery 1.2 Arbitrary PHP File Upload
63RISCO
abrir ↗Metasploit600
Sflog! CMS 1.0 Arbitrary File Upload Vulnerability
Sflog! CMS 1.0 Arbitrary File Upload RCE
36RISCO
abrir ↗Metasploit600
SPIP connect Parameter PHP Injection
The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, all
23RISCO
abrir ↗Metasploit600
Wordpress Front-end Editor File Upload
Front-end Editor < 2.3 - Arbitrary File Upload
63RISCO
abrir ↗Metasploit600
Tiki Wiki unserialize() PHP Code Execution
TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted
50RISCO
abrir ↗Metasploit300
ALLMediaServer 0.8 Buffer Overflow
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow
50RISCO
abrir ↗Metasploit600
Avaya IP Office Customer Call Reporter ImageUpload.ashx Remote Command Execution
Unrestricted file upload vulnerability in ImageUpload.ashx in the Wallboard application in Avaya IP Office Customer Call
50RISCO
abrir ↗Metasploit600
Basilic 1.5.14 diff.php Arbitrary Command Execution
Config/diff.php in Basilic 1.5.14 allows remote attackers to execute arbitrary commands via shell metacharacters in the
50RISCO
abrir ↗Metasploit600
Umbraco CMS Remote Command Execution
Umbraco CMS < 4.7.1 codeEditorSave.asmx RCE
63RISCO
abrir ↗Metasploit600
KeyHelp ActiveX LaunchTriPane Remote Code Execution Vulnerability
An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Pl
50RISCO
abrir ↗Metasploit600
SugarCRM unserialize() PHP Code Execution
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers
50RISCO
abrir ↗Metasploit500
Adobe Flash Player AVM Verification Logic Array Indexing Code Execution
Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android,
60RISCO
abrir ↗Metasploit600
Open-FTPD 1.2 Arbitrary File Upload
Open&Compact FTP Server (Open-FTPD) 1.2 and earlier allows remote attackers to bypass authentication by sending (1) LIST
43RISCO
abrir ↗Metasploit600
IBM Lotus Notes Client URL Handler Command Injection
The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted
50RISCO
abrir ↗Metasploit600
EZHomeTech EzServer Stack Buffer Overflow Vulnerability
EzServer 6.4.017 allows a denial of service (daemon crash) via a long string, such as one for the RNTO command.
36RISCO
abrir ↗Metasploit600
qdPM v7 Arbitrary PHP File Upload Vulnerability
Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6)
23RISCO
abrir ↗Metasploit400
MS12-043 Microsoft XML Core Services MSXML Uninitialized Memory Corruption
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attacker
100RISCO
abrir ↗Metasploit300
Free Float FTP Server USER Command Buffer Overflow
FreeFloat FTP Server USER Command Buffer Overflow
28RISCO
abrir ↗Metasploit300
MS12-037 Microsoft Internet Explorer Same ID Property Deleted Object Handling Memory Corruption
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbit
50RISCO
abrir ↗Metasploit300
MS12-037 Microsoft Internet Explorer Fixed Table Col Span Heap Overflow
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allo
50RISCO
abrir ↗Metasploit500
FreeBSD Intel SYSRET Privilege Escalation
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.