Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.814exploits catalogados
32.125CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.248VulnCheck XDB 8.150Nuclei 4.201Metasploit 3.462✓ só verificadosrecentespopularesrisco
22.786 exploits
Exploit-DB
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
60RISCO
abrir ↗Exploit-DB
Online Trade 1 - Information Disclosure
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensiti
28RISCO
abrir ↗Exploit-DB
Skia - Heap Overflow in SkScan::FillPath due to Precision Error
A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds m
23RISCO
abrir ↗Exploit-DB
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
60RISCO
abrir ↗Exploit-DB
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
60RISCO
abrir ↗Exploit-DB
Trivum Multiroom Setup Tool 8.76 - Corss-Site Request Forgery (Admin Bypass)
MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18, all
28RISCO
abrir ↗Exploit-DB
GetGo Download Manager 6.2.1.3200 - Denial of Service (PoC)
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to exec
28RISCO
abrir ↗Exploit-DB
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
Unauthenticated SQL injection in Micro Focus Secure Messaging Gateway
85RISCO
abrir ↗Exploit-DB
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
Remote Code Execution in Micro Focus Secure Messaging Gateway
85RISCO
abrir ↗Exploit-DB
Nagios Core 4.4.1 - Denial of Service
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows atta
23RISCO
abrir ↗Exploit-DB
Nagios Core 4.4.1 - Denial of Service
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to
23RISCO
abrir ↗Exploit-DB
Nagios Core 4.4.1 - Denial of Service
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to
23RISCO
abrir ↗Exploit-DB
Tenda Wireless N150 Router 5.07.50 - Cross-Site Request Forgery (Reboot Router)
Cross-site request forgery (CSRF) vulnerability on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 allo
23RISCO
abrir ↗Exploit-DB
Davolink DVW 3200 Router - Password Disclosure
Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracke
28RISCO
abrir ↗Exploit-DB
Inteno’s IOPSYS - (Authenticated) Local Privilege Escalation
read_tmp and write_tmp in Inteno IOPSYS allow attackers to gain privileges after writing to /tmp/etc/smb.conf because /v
23RISCO
abrir ↗Exploit-DB
MSVOD 10 - 'cid' SQL Injection
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
23RISCO
abrir ↗Exploit-DB
Touchpad / Trivum WebTouch Setup 2.53 build 13163 - Authentication Bypass
Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attacker
35RISCO
abrir ↗Exploit-DB
TP-Link TL-WR840N - Denial of Service
TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets w
23RISCO
abrir ↗Exploit-DB
Linux - BPF Sign Extension Local Privilege Escalation (Metasploit)
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir ↗Exploit-DB
MyBB New Threads Plugin 1.1 - Cross-Site Scripting
The New Threads plugin before 1.2 for MyBB has XSS.
35RISCO
abrir ↗Exploit-DB
WordPress Plugin All In One Favicon 4.6 - (Authenticated) Cross-Site Scripting
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plu
23RISCO
abrir ↗Exploit-DB
Open-AudIT Community 2.1.1 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows
23RISCO
abrir ↗Exploit-DB
QNAP Q'Center - 'change_passwd' Command Execution (Metasploit)
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
50RISCO
abrir ↗Exploit-DB
QNAP Q'Center - 'change_passwd' Command Execution (Metasploit)
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate
50RISCO
abrir ↗Exploit-DB
Nanopool Claymore Dual Miner - APIs Remote Code Execution (Metasploit)
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
60RISCO
abrir ↗Exploit-DB
PrestaShop < 1.6.1.19 - 'BlowFish ECD' Privilege Escalation
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RISCO
abrir ↗Exploit-DB
PrestaShop < 1.6.1.19 - 'AES CBC' Privilege Escalation
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RISCO
abrir ↗Exploit-DB
Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injection
MFSBGN03811 rev.1 - Fortify Software Security Center (SSC), Multiple vulnerabilities
46RISCO
abrir ↗Exploit-DB
VelotiSmart WiFi B-380 Camera - Directory Traversal
The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../..
50RISCO
abrir ↗Exploit-DB
Linux (Ubuntu) - Other Users coredumps Can Be Read via setgid Directory and killpriv Bypass
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.