Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.961exploits catalogados
36.896CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.400GitHub PoC 15.245VulnCheck XDB 8.946Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.475 exploits
Exploit-DB
Roundcube rcfilters plugin 2.1.6 - Cross-Site Scripting
In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters sec
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Double Dereference in NtEnumerateKey Elevation of Privilege
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'CiSetFileCache' WDAC Security Feature Bypass TOCTOU
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Wechat Broadcast 1.2.0 - Local File Inclusion
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
50RISCO
abrir ↗Exploit-DB
WordPress Plugin Localize My Post 1.0 - Local File Inclusion
The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter.
50RISCO
abrir ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:4
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'PathTypeHandlerBase::SetAttributesHelper' Type Confusion
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - 'localeCompare' Type Confusion
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
35RISCO
abrir ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require ad
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris - libnspr NSPR_LOG_FILE Privilege Escalation (Metasploit)
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment v
38RISCO
abrir ↗Exploit-DB
CA Release Automation NiMi 6.5 - Remote Command Execution
Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows atta
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component JCK Editor 6.4.4 - 'parent' SQL Injection
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
60RISCO
abrir ↗Exploit-DB
Watchguard AP100 AP102 AP200 1.2.9.15 - Remote Code Execution (Metasploit)
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentia
23RISCO
abrir ↗Exploit-DB
Watchguard AP100 AP102 AP200 1.2.9.15 - Remote Code Execution (Metasploit)
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentica
23RISCO
abrir ↗Exploit-DB
Watchguard AP100 AP102 AP200 1.2.9.15 - Remote Code Execution (Metasploit)
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices w
23RISCO
abrir ↗Exploit-DB
Apache Portals Pluto 3.0.0 - Remote Code Execution
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote a
35RISCO
abrir ↗Exploit-DB
Apache Syncope 2.0.7 - Remote Code Execution
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupporte
28RISCO
abrir ↗Exploit-DB
Apache Syncope 2.0.7 - Remote Code Execution
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and un
28RISCO
abrir ↗Exploit-DB
SynaMan 4.0 build 1488 - (Authenticated) Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Identity Governance and Intelligence 5.2.3.2 / 5.2.4 - SQL Injection
IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker co
46RISCO
abrir ↗Exploit-DB
CirCarLife SCADA 4.3.0 - Credential Disclosure
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/lo
50RISCO
abrir ↗Exploit-DB
Rubedo CMS 3.4.0 - Directory Traversal
Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attac
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.