Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.666exploits catalogados
32.032CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.896GitHub PoC 13.204VulnCheck XDB 8.127Nuclei 4.191Metasploit 3.462✓ só verificadosrecentespopularesrisco
22.786 exploits
Exploit-DB
DomainMOD 4.11.01 - Owner name Field Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field.
38RISCO
abrir ↗Exploit-DB
NUUO NVRMini2 3.9.1 - (Authenticated) Command Injection
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted reques
28RISCO
abrir ↗Exploit-DB
Microsoft Lync for Mac 2011 - Injection Forced Browsing/Download
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messa
35RISCO
abrir ↗Exploit-DB
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass
An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/rem
35RISCO
abrir ↗Exploit-DB
DomainMOD 4.11.01 - Custom SSL Fields Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields.
38RISCO
abrir ↗Exploit-DB
NEC Univerge Sv9100 WebPro - 6.00 - Predictable Session ID / Clear Text Password Storage
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
28RISCO
abrir ↗Exploit-DB
FreshRSS 1.11.1 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject
23RISCO
abrir ↗Exploit-DB
DomainMOD 4.11.01 - Custom Domain Fields Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Doma
23RISCO
abrir ↗Exploit-DB
Apache Superset < 0.23 - Remote Code Execution
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to pos
35RISCO
abrir ↗Exploit-DB
CyberArk 9.7 - Memory Disclosure
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay
28RISCO
abrir ↗Exploit-DB
Schneider Electric PLC - Session Calculation Authentication Bypass
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware ver
35RISCO
abrir ↗Exploit-DB
xorg-x11-server < 1.20.3 - 'modulepath' Local Privilege Escalation
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISCO
abrir ↗Exploit-DB
VBScript - 'OLEAUT32!VariantClear' and 'scrrun!VBADictionary::put_Item' Use-After-Free
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
35RISCO
abrir ↗Exploit-DB
VBScript - 'rtFilter' Out-of-Bounds Read
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which coul
35RISCO
abrir ↗Exploit-DB
PhpSpreadsheet < 1.5.0 - XML External Entity (XXE)
securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 enco
23RISCO
abrir ↗Exploit-DB
Unitrends Enterprise Backup - bpserverd Privilege Escalation (Metasploit)
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL i
50RISCO
abrir ↗Exploit-DB
WebKit JIT - 'ByteCodeParser::handleIntrinsicCall' Type Confusion
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISCO
abrir ↗Exploit-DB
WebKit JSC - BytecodeGenerator::hoistSloppyModeFunctionIfNecessary Does not Invalidate the 'ForInContext' Object
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISCO
abrir ↗Exploit-DB
WebKit JSC JIT - 'JSPropertyNameEnumerator' Type Confusion
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
35RISCO
abrir ↗Exploit-DB
Mac OS X - libxpc MITM Privilege Escalation (Metasploit)
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
43RISCO
abrir ↗Exploit-DB
PHP imap_open - Remote Code Execution (Metasploit)
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh c
60RISCO
abrir ↗Exploit-DB
Linux - Nested User Namespace idmap Limit Local Privilege Escalation (Metasploit)
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISCO
abrir ↗Exploit-DB
Netgear Devices - (Unauthenticated) Remote Command Execution (Metasploit)
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear
100RISCO
abrir ↗Exploit-DB
Xorg X11 Server - SUID privilege escalation (Metasploit)
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISCO
abrir ↗Exploit-DB
Ticketly 1.0 - 'kind_id' SQL Injection
AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and
23RISCO
abrir ↗Exploit-DB
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (ldpreload Method)
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISCO
abrir ↗Exploit-DB
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (cron Method)
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISCO
abrir ↗Exploit-DB
Microsoft Windows - DfMarshal Unsafe Unmarshaling Privilege Escalation
An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerabili
23RISCO
abrir ↗Exploit-DB
ImageMagick - Memory Leak
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that ha
35RISCO
abrir ↗Exploit-DB
DomainMOD 4.11.01 - 'raid' Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.
38RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.