Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8.946Nuclei 4.390Metasploit 3.501✓ só verificadosrecentespopularesrisco
3.501 exploits
Metasploit600
Interactive Graphical SCADA System Remote Command Injection
Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA Syst
50RISCO
abrir ↗Metasploit200
MPlayer Lite M3U Buffer Overflow
MPlayer Lite r33064 M3U Stack-Based Buffer Overflow
36RISCO
abrir ↗Metasploit400
Adobe Flash Player AVM Bytecode Verification Vulnerability
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.1
98RISCO
abrir ↗Metasploit300
Majordomo2 _list_file_get() Directory Traversal
The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct d
60RISCO
abrir ↗Metasploit300
Majordomo2 _list_file_get() Directory Traversal
Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allo
60RISCO
abrir ↗Metasploit300
Foxit PDF Reader 4.2 Javascript File Write
Foxit PDF Reader < 4.3.1.0218 JavaScript File Write
36RISCO
abrir ↗Metasploit600
LotusCMS 3.0 eval() Remote Command Execution
Directory traversal vulnerability in core/lib/router.php in LotusCMS Fraise 3.0, when magic_quotes_gpc is disabled, allo
43RISCO
abrir ↗Metasploit300
Wireshark CLDAP Dissector DOS
Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in W
23RISCO
abrir ↗Metasploit300
Solar FTP Server Malformed USER Denial of Service
Solar FTP Server <= 2.1.1 Malformed USER Denial of Service
36RISCO
abrir ↗Metasploit600
Sun Java Applet2ClassLoader Remote Code Execution
Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for B
60RISCO
abrir ↗Metasploit300
xRadio 0.95b Buffer Overflow
SQL injection vulnerability in pages/index.php in BASIC-CMS allows remote attackers to execute arbitrary SQL commands vi
43RISCO
abrir ↗Metasploit300
HP Data Protector 6.1 EXEC_CMD Command Execution
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute
60RISCO
abrir ↗Metasploit500
EMC Replication Manager Command Execution
The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x
50RISCO
abrir ↗Metasploit600
HP Data Protector 6 EXEC_CMD Remote Code Execution
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute
60RISCO
abrir ↗Metasploit600
QuickShare File Server 1.2.1 Directory Traversal Vulnerability
QuickShare File Server 1.2.1 Path Traversal RCE
63RISCO
abrir ↗Metasploit300
VSFTPD 2.3.2 and Earlier STAT Denial of Service
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a deni
60RISCO
abrir ↗Metasploit300
Mozilla Firefox "nsTreeRange" Dangling Pointer Vulnerability
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange da
60RISCO
abrir ↗Metasploit400
VideoLAN VLC MKV Memory Corruption
demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to
50RISCO
abrir ↗Metasploit300
AOL Desktop 9.6 RTX Buffer Overflow
AOL Desktop 9.6 RTX Stack-Based Buffer Overflow
36RISCO
abrir ↗Metasploit600
HP OpenView Performance Insight Server Backdoor Account Code Execution
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.secu
60RISCO
abrir ↗Metasploit400
Real Networks Netzip Classic 7.5.1 86 File Parsing Buffer Overflow Vulnerability
Real Networks Netzip Classic 7.5.1.86 File Parsing Buffer Overflow
43RISCO
abrir ↗Metasploit200
GoldenFTP PASS Stack Buffer Overflow
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (
50RISCO
abrir ↗Metasploit600
Oracle Database Client System Analyzer Arbitrary File Upload
Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and En
60RISCO
abrir ↗Metasploit500
Sielco Sistemi Winlog Buffer Overflow
Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows
50RISCO
abrir ↗Metasploit300
HP OpenView NNM nnmRptConfig nameParams Buffer Overflow
Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers t
60RISCO
abrir ↗Metasploit300
HP OpenView NNM nnmRptConfig.exe schdParams Buffer Overflow
Multiple buffer overflows in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote at
60RISCO
abrir ↗Metasploit200
NetSupport Manager Agent Remote Buffer Overflow
Stack-based buffer overflow in NetSupport Manager Agent for Linux 11.00, for Solaris 9.50, and for Mac OS X 11.00 allows
50RISCO
abrir ↗Metasploit300
HP Data Protector Manager RDS DOS
The RDS service (rds.exe) in HP Data Protector Manager 6.11 allows remote attackers to cause a denial of service (crash)
50RISCO
abrir ↗Metasploit300
Synology Forget Password User Enumeration Scanner
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RISCO
abrir ↗Metasploit600
Axis2 / SAP BusinessObjects Authenticated Code Execution (via SOAP)
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.