Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8.946Nuclei 4.390Metasploit 3.501✓ só verificadosrecentespopularesrisco
3.501 exploits
Metasploit300
Enterasys NetSight nssyslogd.exe Buffer Overflow
Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1
60RISCO
abrir ↗Metasploit300
MS11-093 Microsoft Windows OLE Object File Handling Remote Code Execution
Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote a
60RISCO
abrir ↗Metasploit300
IpSwitch WhatsUp Gold TFTP Directory Traversal
Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read a
50RISCO
abrir ↗Metasploit600
Traq admincp/common.php Remote Code Execution
Traq 2.0–2.3 admincp/common.php RCE
63RISCO
abrir ↗Metasploit600
Splunk Search Remote Code Execution
mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python
43RISCO
abrir ↗Metasploit600
Solarwinds Storage Manager 5.1.0 SQL Injection
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Prof
50RISCO
abrir ↗Metasploit400
TrendMicro Control Manger CmdProcessor.exe Stack Buffer Overflow
Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcess
50RISCO
abrir ↗Metasploit200
Firefox nsSVGValue Out-of-Bounds Access Vulnerability
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAtt
50RISCO
abrir ↗Metasploit200
Firefox 8/9 AttributeChildRemoved() Use-After-Free
Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 thr
50RISCO
abrir ↗Metasploit200
Adobe Reader U3D Memory Corruption Vulnerability
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, a
100RISCO
abrir ↗Metasploit600
QEMU Monitor HMP 'migrate' Command Execution
The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote
23RISCO
abrir ↗Metasploit300
SCADA 3S CoDeSys CmpWebServer Stack Buffer Overflow
Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB
60RISCO
abrir ↗Metasploit200
MS11-080 AfdJoinLeaf Privilege Escalation
afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly valid
98RISCO
abrir ↗Metasploit600
WikkaWiki 1.3.2 Spam Logging PHP Injection
libs/Wakka.class.php in WikkaWiki 1.3.1 and 1.3.2, when the spam_logging option is enabled, allows remote attackers to w
43RISCO
abrir ↗Metasploit400
CCMPlayer 1.5 m3u Playlist Stack Based Buffer Overflow
Stack-based buffer overflow in Castillo Bueno Systems CCMPlayer 1.5 allows remote attackers to execute arbitrary code vi
50RISCO
abrir ↗Metasploit600
Family Connections less.php Remote Command Execution
dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers t
50RISCO
abrir ↗Metasploit300
Avid Media Composer 5.5 - Avid Phonetic Indexer Buffer Overflow
Stack-based buffer overflow in the Phonetic Indexer (AvidPhoneticIndexer.exe) in Avid Media Composer 5.5.3 and earlier a
50RISCO
abrir ↗Metasploit600
V-CMS PHP File Upload and Execute
Unrestricted file upload vulnerability in includes/inline_image_upload.php in AutoSec Tools V-CMS 1.0 allows remote atta
50RISCO
abrir ↗Metasploit300
Yaws Web Server Directory Traversal
Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user cou
23RISCO
abrir ↗Metasploit600
Hastymail 2.1.1 RC1 Command Injection
Hastymail2 2.1.1 before RC2 allows remote attackers to execute arbitrary commands via the (1) rs or (2) rsargs[] paramet
43RISCO
abrir ↗Metasploit300
VMware Update Manager 4 Directory Traversal
The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 bef
50RISCO
abrir ↗Metasploit600
HP StorageWorks P4000 Virtual SAN Appliance Command Execution
lhn/public/network/ping in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to exe
50RISCO
abrir ↗Metasploit600
Support Incident Tracker Remote Command Execution
Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote
43RISCO
abrir ↗Metasploit600
Support Incident Tracker Remote Command Execution
ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive in
43RISCO
abrir ↗Metasploit400
Aviosoft Digital TV Player Professional 1.0 Stack Buffer Overflow
Buffer overflow in Aviosoft DTV Player 1.0.1.2 allows remote attackers to execute arbitrary code via a crafted .plf (aka
23RISCO
abrir ↗Metasploit600
PmWiki pagelist.php Remote PHP Code Injection Exploit
The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitra
50RISCO
abrir ↗Metasploit300
AbsoluteFTP 1.9.6 - 2.2.10 LIST Command Remote Buffer Overflow
Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute ar
43RISCO
abrir ↗Metasploit600
InduSoft Web Studio Arbitrary Upload Remote Code Execution
CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require au
50RISCO
abrir ↗Metasploit600
Novell ZENworks Asset Management Remote Execution
Directory traversal vulnerability in the rtrlet component in Novell ZENworks Asset Management (ZAM) 7.5 allows remote at
60RISCO
abrir ↗Metasploit600
HP Data Protector 6.10/6.11/6.20 Install Service
The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that ref
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.