Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8.946Nuclei 4.390Metasploit 3.501✓ só verificadosrecentespopularesrisco
3.501 exploits
Metasploit300
Apache Range Header DoS (Apache Killer)
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISCO
abrir ↗Metasploit500
HP Easy Printer Care XMLSimpleAccessor Class ActiveX Control Remote Code Execution
A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to
60RISCO
abrir ↗Metasploit200
RealNetworks Realplayer QCP Parsing Heap Overflow
Heap-based buffer overflow in qcpfformat.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and
43RISCO
abrir ↗Metasploit600
ktsuss suid Privilege Escalation
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified com
60RISCO
abrir ↗Metasploit300
TeeChart Professional ActiveX Control Trusted Integer Dereference
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier,
23RISCO
abrir ↗Metasploit300
MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain leng
60RISCO
abrir ↗Metasploit300
Adobe Flash Player MP4 SequenceParameterSetNALUnit Buffer Overflow
Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adob
60RISCO
abrir ↗Metasploit400
Apple QuickTime PICT PnSize Buffer Overflow
Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a deni
50RISCO
abrir ↗Metasploit300
BisonWare BisonFTP Server Buffer Overflow
Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly
50RISCO
abrir ↗Metasploit600
Sun/Oracle GlassFish Server Authenticated Code Execution
Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Applicati
50RISCO
abrir ↗Metasploit600
CA Arcserve D2D GWT RPC Credential Information Disclosure
BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain
60RISCO
abrir ↗Metasploit600
Apple Safari Webkit libxslt Arbitrary File Creation
WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbi
50RISCO
abrir ↗Metasploit600
Wireshark console.lua Pre-Loading Script Execution
Untrusted search path vulnerability in Wireshark 1.4.x before 1.4.9 and 1.6.x before 1.6.2 allows local users to gain pr
50RISCO
abrir ↗Metasploit300
Citrix Gateway ActiveX Control Stack Based Buffer Overflow Vulnerability
Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Ed
50RISCO
abrir ↗Metasploit600
LifeSize Room Command Injection
The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitra
50RISCO
abrir ↗Metasploit600
WeBid converter.php Remote PHP Code Injection
WeBid 1.0.2 converter.php Remote PHP Code Injection
63RISCO
abrir ↗Metasploit600
VSFTPD 2.3.4 Backdoor Command Execution
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗Metasploit300
Kaillera 0.86 Server Denial of Service
Kaillera 0.86 Server DoS via Malformed UDP Packet
36RISCO
abrir ↗Metasploit400
HP OmniInet.exe Opcode 20 Buffer Overflow
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RISCO
abrir ↗Metasploit500
HP OmniInet.exe Opcode 27 Buffer Overflow
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RISCO
abrir ↗Metasploit300
Mozilla Firefox Array.reduceRight() Integer Overflow
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird bef
60RISCO
abrir ↗Metasploit300
MS11-050 IE mshtml!CObjectElement Use After Free
Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote attackers to execute
50RISCO
abrir ↗Metasploit600
Cisco AnyConnect VPN Client ActiveX URL Property Download and Execute
The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Win
50RISCO
abrir ↗Metasploit400
IBM Tivoli Endpoint Manager POST Query Buffer Overflow
Stack-based buffer overflow in lcfd.exe in Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3
50RISCO
abrir ↗Metasploit300
Sybase Easerver 6.3 Directory Traversal
Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers
30RISCO
abrir ↗Metasploit300
Lotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh Attachment)
Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers
50RISCO
abrir ↗Metasploit400
Lotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh Attachment)
Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers
50RISCO
abrir ↗Metasploit500
VisiWave VWR File Parsing Vulnerability
VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to
50RISCO
abrir ↗Metasploit300
MPlayer SAMI Subtitle File Buffer Overflow
Stack-based buffer overflow in the sub_read_line_sami function in subreader.c in MPlayer, as used in SMPlayer 0.6.9, all
43RISCO
abrir ↗Metasploit300
Mozilla Firefox 3.6.16 mChannel Use-After-Free
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allo
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.