Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
3.502 exploits
Metasploit300
Oracle DB SQL Injection via SYS.DBMS_CDC_PUBLISH.ALTER_AUTOLOG_CHANGE_SOURCE
Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allow
18RISCO
abrir ↗Metasploit400
VideoLAN VLC TiVo Buffer Overflow
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RISCO
abrir ↗Metasploit300
Oracle DB SQL Injection via SYS.LT.MERGEWORKSPACE
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RISCO
abrir ↗Metasploit600
Mantis manage_proj_page PHP Code Execution
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISCO
abrir ↗Metasploit600
Husdawg, LLC. System Requirements Lab ActiveX Unsafe Method
Husdawg, LLC Systems Requirements Lab 3, as used by Instant Expert Analysis, allows remote attackers to force the downlo
50RISCO
abrir ↗Metasploit500
Sun Solaris sadmind adm_build_path() Buffer Overflow
Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allo
50RISCO
abrir ↗Metasploit300
Titan FTP Server 6.26.630 SITE WHO DoS
Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO
50RISCO
abrir ↗Metasploit300
Microsoft Host Integration Server 2006 Command Execution Vulnerability
Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, whic
40RISCO
abrir ↗Metasploit300
XM Easy Personal FTP Server 5.6.0 NLST DoS
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument
50RISCO
abrir ↗Metasploit300
Oracle DB SQL Injection via SYS.LT.REMOVEWORKSPACE
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RISCO
abrir ↗Metasploit300
Oracle DB SQL Injection via SYS.LT.COMPRESSWORKSPACE
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
23RISCO
abrir ↗Metasploit300
Guild FTPd 0.999.8.11/0.999.14 Heap Corruption
GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possib
50RISCO
abrir ↗Metasploit200
Computer Associates ARCserve REPORTREMOTEEXECUTECML Buffer Overflow
Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve
60RISCO
abrir ↗Metasploit300
iseemedia / Roxio / MGI Software LPViewer ActiveX Control Buffer Overflow
Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and
43RISCO
abrir ↗Metasploit300
mIRC PRIVMSG Handling Stack Buffer Overflow
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIV
50RISCO
abrir ↗Metasploit600
phpScheduleIt PHP reserve.php start_date Parameter Arbitrary Code Injection
Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allo
43RISCO
abrir ↗Metasploit300
WinFTP 2.3.0 NLST Denial of Service
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of se
43RISCO
abrir ↗Metasploit500
DATAC RealWin SCADA Server Buffer Overflow
Stack-based buffer overflow in RealFlex Technologies Ltd. RealWin Server 2.0, as distributed by DATAC, allows remote att
50RISCO
abrir ↗Metasploit300
Windows Media Encoder 9 wmex.dll ActiveX Buffer Overflow
Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9
50RISCO
abrir ↗Metasploit500
BEA Weblogic Transfer-Encoding Buffer Overflow
Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 M
50RISCO
abrir ↗Metasploit400
Ultra Shareware Office Control ActiveX HttpUpload Buffer Overflow
Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware
50RISCO
abrir ↗Metasploit600
AWStats Totals multisort Remote Command Execution
awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences
50RISCO
abrir ↗Metasploit100
activePDF WebGrabber ActiveX Control Buffer Overflow
activePDF WebGrabber ActiveX Control Buffer Overflow
36RISCO
abrir ↗Metasploit300
SoftArtisans XFile FileManager ActiveX Control Buffer Overflow
Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.
43RISCO
abrir ↗Metasploit300
Microsoft Visual Studio Mdmask32.ocx ActiveX Stack Buffer Overflow
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RISCO
abrir ↗Metasploit500
Racer v0.5.3 Beta 5 Buffer Overflow
Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbit
50RISCO
abrir ↗Metasploit300
Ruby WEBrick::HTTP::DefaultFileHandler DoS
Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFile
60RISCO
abrir ↗Metasploit400
WebEx UCF atucfobj.dll ActiveX NewObject Method Buffer Overflow
Stack-based buffer overflow in the WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before
50RISCO
abrir ↗Metasploit300
DNS BailiWicked Domain Attack
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RISCO
abrir ↗Metasploit300
DNS BailiWicked Host Attack
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.