Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8.946Nuclei 4.390Metasploit 3.501✓ só verificadosrecentespopularesrisco
3.501 exploits
Metasploit300
Mozilla Firefox 3.6.16 mChannel Use-After-Free Vulnerability
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allo
60RISCO
abrir ↗Metasploit400
ICONICS WebHMI ActiveX Buffer Overflow
Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0
50RISCO
abrir ↗Metasploit300
SPlayer 3.7 Content-Type Buffer Overflow
SPlayer 3.7 Content-Type Header Buffer Overflow
36RISCO
abrir ↗Metasploit300
Tom Sawyer Software GET Extension Factory Remote Code Execution
Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.2
50RISCO
abrir ↗Metasploit400
MJM Core Player 2011 .s3m Stack Buffer Overflow
MJM Core Player 2011 .s3m File Stack-Based Buffer Overflow
36RISCO
abrir ↗Metasploit400
MJM QuickPlayer 1.00 Beta 60a / QuickPlayer 2010 .s3m Stack Buffer Overflow
MJM QuickPlayer <= 2010 .s3m Stack-Based Buffer Overflow
36RISCO
abrir ↗Metasploit300
NetOp Remote Control Client 9.5 Buffer Overflow
NetOp Remote Control Client 9.5 .dws File Buffer Overflow
36RISCO
abrir ↗Metasploit300
Subtitle Processor 7.7.1 .M3U SEH Unicode Buffer Overflow
Subtitle Processor 7.7.1 .m3u SEH Unicode Buffer Overflow
36RISCO
abrir ↗Metasploit400
Magix Musik Maker 16 .mmm Stack Buffer Overflow
Magix Musik Maker <= v16 .mmm Stack-Based Buffer Overflow
36RISCO
abrir ↗Metasploit400
Wireshark packet-dect.c Stack Buffer Overflow
Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allow
50RISCO
abrir ↗Metasploit400
Wireshark packet-dect.c Stack Buffer Overflow (local)
Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allow
50RISCO
abrir ↗Metasploit600
CA Total Defense Suite reGenerateReports Stored Procedure SQL Injection
Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before S
60RISCO
abrir ↗Metasploit300
Microsoft Windows DNSAPI.dll LLMNR Buffer Underrun DoS
DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Wi
55RISCO
abrir ↗Metasploit400
VeryTools Video Spirit Pro
Buffer overflow in VideoSpirit Pro 1.6.8.1 and possibly earlier versions, and VideoSpirit Lite 1.4.0.1 and possibly othe
50RISCO
abrir ↗Metasploit300
Adobe Flash Player 10.2.153.1 SWF Memory Corruption Vulnerability
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; A
100RISCO
abrir ↗Metasploit600
Log1 CMS writeInfo() PHP Code Injection
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RISCO
abrir ↗Metasploit400
VeryTools Video Spirit Pro
Buffer overflow in VideoSpirit Pro 1.6.8.1, 1.68, and earlier; and VideoSpirit Lite 1.4.0.1 and possibly other versions;
50RISCO
abrir ↗Metasploit200
VideoLAN VLC ModPlug ReadS3M Stack Buffer Overflow
Stack-based buffer overflow in the ReadS3M method in load_s3m.cpp in libmodplug before 0.8.8.2 allows remote attackers t
50RISCO
abrir ↗Metasploit300
S40 0.4.2 CMS Directory Traversal Vulnerability
S40 CMS 0.4.2 Path Traversal
36RISCO
abrir ↗Metasploit400
Blue Coat Authentication and Authorization Agent (BCAAA) 5 Buffer Overflow
Stack-based buffer overflow in the BCAAA component before build 60258, as used by Blue Coat ProxySG 4.2.3 through 6.1 an
50RISCO
abrir ↗Metasploit300
Real Networks Arcade Games StubbyUtil.ProcessMgr ActiveX Arbitrary Code Execution
RealNetworks Arcade Games StubbyUtil.ProcessMgr ActiveX Arbitrary Code Execution
36RISCO
abrir ↗Metasploit500
Linux PolicyKit Race Condition Privilege Escalation
Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privil
38RISCO
abrir ↗Metasploit600
7-Technologies IGSS 9 Data Server/Collector Packet Handling Vulnerabilities
Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA Syst
50RISCO
abrir ↗Metasploit400
7-Technologies IGSS IGSSdataServer.exe Stack Buffer Overflow
Multiple stack-based buffer overflows in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Grap
50RISCO
abrir ↗Metasploit600
7-Technologies IGSS 9 Data Server/Collector Packet Handling Vulnerabilities
Directory traversal vulnerability in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphica
50RISCO
abrir ↗Metasploit300
7-Technologies IGSS 9 IGSSdataServer .RMS Rename Buffer Overflow
Multiple stack-based buffer overflows in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Grap
50RISCO
abrir ↗Metasploit400
VLC AMV Dangling Pointer Vulnerability
libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a
60RISCO
abrir ↗Metasploit500
DATAC RealWin SCADA Server 2 On_FC_CONNECT_FCS_a_FILE Buffer Overflow
Multiple stack-based buffer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier
60RISCO
abrir ↗Metasploit600
Interactive Graphical SCADA System Remote Command Injection
Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA Syst
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.