Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.978exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.248VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
3.502 exploits
Metasploit600
osCommerce 2.2 Arbitrary PHP Code Execution
osCommerce <= 2.2 Admin File Manager Arbitrary PHP Code Execution
63RISCO
abrir ↗Metasploit500
MS09-053 Microsoft IIS FTP Server NLST Response Overflow
Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authen
60RISCO
abrir ↗Metasploit300
Oracle Document Capture 10g ActiveX Control Buffer Overflow
Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used
50RISCO
abrir ↗Metasploit300
ProFTP 2.9 Banner Remote Buffer Overflow
Buffer overflow in Labtam ProFTP 2.9 allows remote FTP servers to cause a denial of service (application crash) or execu
43RISCO
abrir ↗Metasploit500
ProShow Gold v4.0.2549 (PSH File) Stack Buffer Overflow
Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code
50RISCO
abrir ↗Metasploit500
Xenorate 2.50 (.xpl) Universal Local Buffer Overflow (SEH)
Xenorate <= 2.50 .xpl File Stack-Based Buffer Overflow
36RISCO
abrir ↗Metasploit300
Oracle Secure Backup Authentication Bypass/Command Injection Vulnerability
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers
50RISCO
abrir ↗Metasploit400
VUPlayer M3U Buffer Overflow
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long st
50RISCO
abrir ↗Metasploit400
VUPlayer CUE Buffer Overflow
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RISCO
abrir ↗Metasploit300
Oracle Secure Backup Authentication Bypass/Command Injection Vulnerability
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers
60RISCO
abrir ↗Metasploit500
Linux Kernel Sendpage Local Privilege Escalation
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socke
43RISCO
abrir ↗Metasploit300
Microsoft OWC Spreadsheet HTMLURL Buffer Overflow
Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3,
50RISCO
abrir ↗Metasploit400
BlazeDVD 6.1 PLF Buffer Overflow
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote at
50RISCO
abrir ↗Metasploit500
SAP Business One License Manager 2005 Buffer Overflow
Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote atta
50RISCO
abrir ↗Metasploit500
Millenium MP3 Studio 2.0 (PLS File) Stack Buffer Overflow
Millenium MP3 Studio <= 2.0 .pls File Stack-Based Buffer Overflow
36RISCO
abrir ↗Metasploit600
Joomla 1.5.12 TinyBrowser File Upload Code Execution
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
50RISCO
abrir ↗Metasploit600
DD-WRT HTTP Daemon Arbitrary Command Execution
httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers
60RISCO
abrir ↗Metasploit300
Microsoft OWC Spreadsheet msDataSourceObject Memory Corruption
The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 an
50RISCO
abrir ↗Metasploit300
Firefox 3.5 escape() Return Value Memory Corruption
js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1
50RISCO
abrir ↗Metasploit600
Wyse Rapport Hagent Fake Hserver Command Execution
hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attacker
50RISCO
abrir ↗Metasploit200
AwingSoft Winds3D Player SceneURL Buffer Overflow
Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlie
50RISCO
abrir ↗Metasploit300
Microsoft DirectShow (msvidctl.dll) MPEG-2 Memory Corruption
Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in
100RISCO
abrir ↗Metasploit600
ColdFusion 8.0.1 Arbitrary File Upload and Execute
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISCO
abrir ↗Metasploit300
Media Jukebox 8.0.400 Buffer Overflow (SEH)
Heap-based buffer overflow in Sorcerer Software MultiMedia Jukebox 4.0 Build 020124 allows remote attackers to cause a d
50RISCO
abrir ↗Metasploit400
HT-MP3Player 1.0 HT3 File Parsing Buffer Overflow
Stack-based buffer overflow in HT-MP3Player 1.0 allows remote attackers to execute arbitrary code via a long string in a
50RISCO
abrir ↗Metasploit500
Timbuktu PlughNTCommand Named Pipe Buffer Overflow
Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code
50RISCO
abrir ↗Metasploit500
VideoLAN Client (VLC) Win32 smb:// URI Buffer Overflow
Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.
50RISCO
abrir ↗Metasploit600
Nagios3 statuswml.cgi Ping Command Execution
statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in t
60RISCO
abrir ↗Metasploit400
Bopup Communications Server Buffer Overflow
Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrar
50RISCO
abrir ↗Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
Radware Alteon devices with a firmware version between 31.0.0.0-31.0.3.0 are vulnerable to an adaptive-chosen ciphertext
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.