Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.934GitHub PoC 13.235VulnCheck XDB 8.150Nuclei 4.193Metasploit 3.462✓ só verificadosrecentespopularesrisco
22.786 exploits
Exploit-DB
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerabili
28RISCO
abrir ↗Exploit-DB
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateS
23RISCO
abrir ↗Exploit-DB
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser
23RISCO
abrir ↗Exploit-DB
Git Submodule - Arbitrary Code Execution (PoC)
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISCO
abrir ↗Exploit-DB
Cisco Prime Infrastructure - (Unauthenticated) Remote Code Execution
Cisco Prime Infrastructure Arbitrary File Upload and Command Execution Vulnerability
60RISCO
abrir ↗Exploit-DB
RICOH MP C1803 JPN Printer - Cross-Site Scripting
On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding a
23RISCO
abrir ↗Exploit-DB
RICOH MP C1803 JPN Printer - Cross-Site Scripting
On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of add
23RISCO
abrir ↗Exploit-DB
Airties AIR5342 1.0.0.18 - Cross-Site Scripting
AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RISCO
abrir ↗Exploit-DB
Airties AIR5342 1.0.0.18 - Cross-Site Scripting
AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RISCO
abrir ↗Exploit-DB
Airties AIR5342 1.0.0.18 - Cross-Site Scripting
AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RISCO
abrir ↗Exploit-DB
Airties AIR5342 1.0.0.18 - Cross-Site Scripting
AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RISCO
abrir ↗Exploit-DB
Airties AIR5342 1.0.0.18 - Cross-Site Scripting
AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RISCO
abrir ↗Exploit-DB
OPAC EasyWeb Five 5.7 - 'biblio' SQL Injection
An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio par
23RISCO
abrir ↗Exploit-DB
Linux Kernel < 4.11.8 - 'mq_notify: double sock_put()' Local Privilege Escalation
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISCO
abrir ↗Exploit-DB
WUZHICMS 2.0 - Cross-Site Scripting
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.
23RISCO
abrir ↗Exploit-DB
Zahir Enterprise Plus 6 build 10b - Buffer Overflow (SEH)
Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute a
43RISCO
abrir ↗Exploit-DB
PCProtect 4.8.35 - Privilege Escalation
PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users
23RISCO
abrir ↗Exploit-DB
Microsoft Edge - Sandbox Escape
An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privil
28RISCO
abrir ↗Exploit-DB
Microsoft Edge - Sandbox Escape
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont
28RISCO
abrir ↗Exploit-DB
Microsoft Edge - Sandbox Escape
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont
28RISCO
abrir ↗Exploit-DB
Rausoft ID.prove 2.95 - 'Username' SQL injection
An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked q
23RISCO
abrir ↗Exploit-DB
EE 4GEE Mini EE40_00_02.00_44 - Privilege Escalation
The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before
23RISCO
abrir ↗Exploit-DB
Linux Kernel 2.6.x / 3.10.x / 4.14.x (RedHat / Debian / CentOS) (x64) - 'Mutagen Astronomy' Local Privilege Escalation
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with a
76RISCO
abrir ↗Exploit-DB
Linux Kernel - VMA Use-After-Free via Buggy vmacache_flush_all() Fastpath Local Privilege Escalation
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISCO
abrir ↗Exploit-DB
Joomla! Component Jobs Factory 2.0.4 - SQL Injection
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
23RISCO
abrir ↗Exploit-DB
Joomla! Component Raffle Factory 3.5.2 - SQL Injection
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order paramete
23RISCO
abrir ↗Exploit-DB
Joomla! Component Music Collection 3.0.3 - SQL Injection
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
23RISCO
abrir ↗Exploit-DB
Joomla! Component Penny Auction Factory 2.0.4 - SQL Injection
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order p
23RISCO
abrir ↗Exploit-DB
Joomla! Component Article Factory Manager 4.3.9 - SQL Injection
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_e
23RISCO
abrir ↗Exploit-DB
Solaris - 'EXTREMEPARR' dtappgather Privilege Escalation (Metasploit)
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (C
38RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.