Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
3.502 exploits
Metasploit400
Oracle Secure Backup NDMP_CONNECT_CLIENT_AUTH Buffer Overflow
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers
50RISCO
abrir ↗Metasploit300
Oracle Secure Backup exec_qr() Command Injection Vulnerability
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers
30RISCO
abrir ↗Metasploit400
BEA WebLogic JSESSIONID Cookie Value Overflow
Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA
50RISCO
abrir ↗Metasploit300
Oracle DB SQL Injection in MDSYS.SDO_TOPO_DROP_FTBL Trigger
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authent
50RISCO
abrir ↗Metasploit300
TrendMicro Data Loss Prevention 5.5 Directory Traversal
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16,
60RISCO
abrir ↗Metasploit300
Tomcat UTF-8 Directory Traversal Vulnerability
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16,
60RISCO
abrir ↗Metasploit500
HP OpenView Network Node Manager Toolbar.exe CGI Buffer Overflow
Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote att
50RISCO
abrir ↗Metasploit400
Destiny Media Player 1.61 PLS M3U Buffer Overflow
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RISCO
abrir ↗Metasploit100
SasCam Webcam Server v.2.6.5 Get() Method Buffer Overflow
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote
50RISCO
abrir ↗Metasploit400
Adobe Flash Player ActionScript Launch Command Execution Vulnerability
Unspecified vulnerability in Adobe Flash Player for Linux 10.0.12.36, and 9.0.151.0 and earlier, allows remote attackers
60RISCO
abrir ↗Metasploit500
Realtek Media Player Playlist Buffer Overflow
Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows
50RISCO
abrir ↗Metasploit400
MS09-004 Microsoft SQL Server sp_replwritetovarbin Memory Corruption
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RISCO
abrir ↗Metasploit600
MS09-004 Microsoft SQL Server sp_replwritetovarbin Memory Corruption via SQL Injection
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RISCO
abrir ↗Metasploit300
MS08-078 Microsoft Internet Explorer Data Binding Memory Corruption
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet
50RISCO
abrir ↗Metasploit600
Sun Java Calendar Deserialization Privilege Escalation
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; a
60RISCO
abrir ↗Metasploit400
Cain and Abel RDP Buffer Overflow
Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier,
50RISCO
abrir ↗Metasploit100
Microsoft Works 7 WkImgSrv.dll WKsPictureInterface() ActiveX Code Execution
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RISCO
abrir ↗Metasploit300
Avahi Source Port 0 DoS
The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 al
50RISCO
abrir ↗Metasploit300
Pi3Web ISAPI DoS
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi
43RISCO
abrir ↗Metasploit600
Openfire Admin Console Authentication Bypass
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows rem
60RISCO
abrir ↗Metasploit400
VLC Media Player RealText Subtitle Overflow
Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execu
50RISCO
abrir ↗Metasploit600
Chilkat Crypt ActiveX WriteFile Unsafe Method
Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilka
50RISCO
abrir ↗Metasploit100
DjVu DjVu_ActiveX_MSOffice.dll ActiveX ComponentBuffer Overflow
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers
50RISCO
abrir ↗Metasploit300
PacketTrap TFTP Server 2.2.5459.0 DoS
The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.0 and earlier allows remote attackers to cause a denial of s
50RISCO
abrir ↗Metasploit400
TugZip 3.5 Zip File Parsing Buffer Overflow Vulnerability
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary
50RISCO
abrir ↗Metasploit500
MS08-067 Microsoft Server Service Relative Path Stack Corruption
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISCO
abrir ↗Metasploit300
Victory FTP Server 5.0 LIST DoS
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a crafted LIST command, which triggers a NU
50RISCO
abrir ↗Metasploit300
Victory FTP Server 5.0 LIST DoS
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (fo
50RISCO
abrir ↗Metasploit600
Opera historysearch XSS
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary w
50RISCO
abrir ↗Metasploit300
Oracle DB SQL Injection via SYS.DBMS_CDC_IPUBLISH.ALTER_HOTLOG_INTERNAL_CSOURCE
Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allow
18RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.