Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8.946Nuclei 4.390Metasploit 3.501✓ só verificadosrecentespopularesrisco
3.501 exploits
Metasploit300
HP OpenView Network Node Manager ov.dll _OVBuildPath Buffer Overflow
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute
50RISCO
abrir ↗Metasploit300
NJStar Communicator 3.00 MiniSMTP Buffer Overflow
Buffer overflow in MiniSmtp 3.0.11818 in NJStar Communicator allows remote attackers to execute arbitrary code via a cra
50RISCO
abrir ↗Metasploit600
phpLDAPadmin query_engine Remote PHP Code Injection
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary
50RISCO
abrir ↗Metasploit300
HP Power Manager 'formExportDataLogs' Buffer Overflow
Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to ex
60RISCO
abrir ↗Metasploit300
AdminStudio LaunchHelp.dll ActiveX Arbitrary Code Execution
Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in Laun
50RISCO
abrir ↗Metasploit600
Java Applet Rhino Script Engine Remote Code Execution
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and
100RISCO
abrir ↗Metasploit600
Java RMI Server Insecure Default Configuration Java Code Execution
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RISCO
abrir ↗Metasploit300
Java RMI Server Insecure Endpoint Code Execution Scanner
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RISCO
abrir ↗Metasploit300
Apple Safari file:// Arbitrary Code Execution
Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers
50RISCO
abrir ↗Metasploit400
ScriptFTP LIST Remote Buffer Overflow
Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long file
50RISCO
abrir ↗Metasploit600
myBB 1.6.4 Backdoor Arbitrary Command Execution
myBB 1.6.4 Backdoor Arbitrary Command Execution
63RISCO
abrir ↗Metasploit200
PcVue 10.0 SV.UIGrdCtrl.1 'LoadObject()/SaveObject()' Trusted DWORD Vulnerability
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows
43RISCO
abrir ↗Metasploit600
Spreecommerce 0.60.1 Arbitrary Command Execution
Spreecommerce < 0.60.2 Search Parameter RCE
63RISCO
abrir ↗Metasploit600
Plone and Zope XMLTools Remote Command Execution
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, a
60RISCO
abrir ↗Metasploit400
Cytel Studio 9.0 (CY3 File) Stack Buffer Overflow
Cytel Studio <= 9.0 .CY3 File Stack Buffer Overflow
43RISCO
abrir ↗Metasploit600
Apache Struts ParametersInterceptor Remote Code Execution
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class an
60RISCO
abrir ↗Metasploit500
Sunway Forcecontrol SNMP NetDBServer.exe Opcode 0x57
Sunway Forcecontrol SNMP NetDBServer.exe Opcode 0x57
63RISCO
abrir ↗Metasploit600
Snortreport nmap.php/nbtscan.php Remote Command Execution
Snort Report nmap.php/nbtscan.php RCE
63RISCO
abrir ↗Metasploit600
Measuresoft ScadaPro Remote Command Execution
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the
50RISCO
abrir ↗Metasploit300
Beckhoff TwinCAT SCADA PLC 2.11.0.2004 DoS
Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to U
50RISCO
abrir ↗Metasploit400
DaqFactory HMI NETB Request Overflow
Stack-based buffer overflow in Azeotech DAQFactory 5.85 build 1853 and earlier allows remote attackers to cause a denial
60RISCO
abrir ↗Metasploit500
CyberLink Power2Go name Attribute (p2g) Stack Buffer Overflow Exploit
Multiple stack-based buffer overflows in CyberLink Power2Go 7 (build 196) and 8 (build 1031) allow remote attackers to e
50RISCO
abrir ↗Metasploit400
ScadaTEC ScadaPhone Stack Buffer Overflow
Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC Modb
43RISCO
abrir ↗Metasploit400
ACDSee FotoSlate PLP File id Parameter Overflow
Multiple stack-based buffer overflows in ACDSee FotoSlate 4.0 Build 146 allow remote attackers to execute arbitrary code
50RISCO
abrir ↗Metasploit200
CTEK SkyRouter 4200 and 4300 Command Execution
apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via sh
50RISCO
abrir ↗Metasploit300
Procyon Core Server HMI Coreservice.exe Stack Buffer Overflow
Core Server HMI Service (Coreservice.exe) in Scadatec Limited Procyon SCADA 1.06, and other versions before 1.14, allows
50RISCO
abrir ↗Metasploit300
eSignal and eSignal Pro File Parsing Buffer Overflow in QUO
WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly ex
50RISCO
abrir ↗Metasploit300
rsyslog Long Tag Off-By-Two DoS
Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before
23RISCO
abrir ↗Metasploit500
Free MP3 CD Ripper 1.1 WAV File Stack Buffer Overflow
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.