Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8.946Nuclei 4.390Metasploit 3.501✓ só verificadosrecentespopularesrisco
3.501 exploits
Metasploit600
Java AtomicReferenceArray Type Violation Vulnerability
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Up
100RISCO
abrir ↗Metasploit600
Sun Java Web Start Plugin Command Line Argument Injection
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Up
50RISCO
abrir ↗Metasploit600
Horde 3.3.12 Backdoor Arbitrary PHP Code Execution
Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November
60RISCO
abrir ↗Metasploit300
RabidHamster R4 Log Entry sprintf() Buffer Overflow
RabidHamster R4 Log Entry sprintf() Buffer Overflow
63RISCO
abrir ↗Metasploit600
vBSEO proc_deutf() Remote PHP Code Injection
The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allo
50RISCO
abrir ↗Metasploit600
PolarBear CMS PHP File Upload Vulnerability
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arb
60RISCO
abrir ↗Metasploit600
appRain CMF Arbitrary PHP File Upload Vulnerability
Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote
50RISCO
abrir ↗Metasploit300
General Electric D20 Password Recovery
General Electric D20ME devices are not properly configured and reveal plaintext passwords.
18RISCO
abrir ↗Metasploit600
SonicWALL GMS 6 Arbitrary File Upload
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5
60RISCO
abrir ↗Metasploit300
Irfanview JPEG2000 jp2 Stack Buffer Overflow
Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute a
50RISCO
abrir ↗Metasploit200
HP Diagnostics Server magentservice.exe Overflow
Stack-based buffer overflow in magentservice.exe in the server in HP LoadRunner 11.00 before patch 4 allows remote attac
50RISCO
abrir ↗Metasploit500
HP Easy Printer Care XMLCacheMgr Class ActiveX Control Remote Code Execution
A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to
50RISCO
abrir ↗Metasploit300
NTR ActiveX Control StopModule() Remote Code Execution
The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a
50RISCO
abrir ↗Metasploit300
NTR ActiveX Control Check() Method Buffer Overflow
Multiple stack-based buffer overflows in the NTR ActiveX control before 2.0.4.8 allow remote attackers to execute arbitr
50RISCO
abrir ↗Metasploit600
MS12-005 Microsoft Office ClickOnce Unsafe Object Package Handling Vulnerability
Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Se
60RISCO
abrir ↗Metasploit300
MS12-004 midiOutPlayNextPolyEvent Heap Overflow
Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows
68RISCO
abrir ↗Metasploit600
Apache Struts Remote Command Execution
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during
100RISCO
abrir ↗Metasploit600
Apache Struts 2 Developer Mode OGNL Execution
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers
60RISCO
abrir ↗Metasploit600
OP5 welcome Remote Command Execution
op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers
60RISCO
abrir ↗Metasploit600
OP5 license.php Remote Command Execution
license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execu
60RISCO
abrir ↗Metasploit300
Hashtable Collisions
Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without r
60RISCO
abrir ↗Metasploit300
Hashtable Collisions
Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger ha
60RISCO
abrir ↗Metasploit300
Hashtable Collisions
Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 a
50RISCO
abrir ↗Metasploit300
Hashtable Collisions
PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions pre
60RISCO
abrir ↗Metasploit400
CoCSoft StreamDown 6.8.0 Buffer Overflow
Stack-based buffer overflow in CoCSoft Stream Down 6.8.0 allows remote web servers to execute arbitrary code via a long
43RISCO
abrir ↗Metasploit500
Linux BSD-derived Telnet Service Encryption Key ID Buffer Overflow
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISCO
abrir ↗Metasploit500
FreeBSD Telnet Service Encryption Key ID Buffer Overflow
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISCO
abrir ↗Metasploit600
HP Managed Printing Administration jobAcct Remote Command Execution
Directory traversal vulnerability in the MPAUploader.Uploader.1.UploadFiles method in HP Managed Printing Administration
50RISCO
abrir ↗Metasploit300
7-Technologies IGSS 9 IGSSdataServer.exe DoS
Buffer overflow in 7-Technologies (7T) Interactive Graphical SCADA System (IGSS) 9.0.0.11200 allows remote attackers to
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.