Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.475 exploits
Exploit-DB✓ VexDay Proof
HongCMS 3.0.0 - (Authenticated) SQL Injection
An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Quest KACE Systems Management - Command Injection (Metasploit)
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by
100RISCO
abrir ↗Exploit-DB
PoDoFo 0.9.5 - Buffer Overflow (PoC)
In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.
23RISCO
abrir ↗Exploit-DB
WordPress Plugin iThemes Security < 7.0.3 - SQL Injection
The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admi
28RISCO
abrir ↗Exploit-DB
WordPress Plugin Advanced Order Export For WooCommerce < 1.5.4 - CSV Injection
The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.
23RISCO
abrir ↗Exploit-DB
DIGISOL DG-BR4000NG - Cross-Site Scripting
DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
KVM (Nested Virtualization) - L1 Guest Privilege Escalation
In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Foxit Reader 9.0.1.1049 - Remote Code Execution
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RISCO
abrir ↗Exploit-DB
Ecessa ShieldLink SL175EHQ < 10.7.4 - Cross-Site Request Forgery (Add Superuser)
ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogi
23RISCO
abrir ↗Exploit-DB
DIGISOL DG-BR4000NG - Buffer Overflow (PoC)
DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Foxit Reader 9.0.1.1049 - Remote Code Execution
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RISCO
abrir ↗Exploit-DB
WordPress Plugin Comments Import & Export < 2.0.4 - CSV Injection
The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
23RISCO
abrir ↗Exploit-DB
GreenCMS 2.3.0603 - Information Disclosure
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_d
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (2)
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir ↗Exploit-DB
QEMU Guest Agent 2.12.50 - Denial of Service
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 h
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (1)
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir ↗Exploit-DB
LFCMS 3.7.0 - Cross-Site Request Forgery (Add User)
A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.
23RISCO
abrir ↗Exploit-DB
LFCMS 3.7.0 - Cross-Site Request Forgery (Add Admin)
Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authen
23RISCO
abrir ↗Exploit-DB
Dell EMC RecoverPoint < 5.1.2 - Local Root Command Execution
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command inje
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache CouchDB < 2.1.0 - Remote Code Execution
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISCO
abrir ↗Exploit-DB
MaDDash 2.0.2 - Directory Listing
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provi
23RISCO
abrir ↗Exploit-DB
MaDDash 2.0.2 - Directory Listing
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provi
23RISCO
abrir ↗Exploit-DB
MaDDash 2.0.2 - Directory Listing
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ pr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 - Desktop Bridge Virtual Registry CVE-2018-0880 Incomplete Fix Privilege Escalation
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 - Desktop Bridge Activation Arbitrary Directory Creation Privilege Escalation
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RISCO
abrir ↗Exploit-DB
IPConfigure Orchid VMS 2.0.5 - Directory Traversal / Information Disclosure (Metasploit)
IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.
50RISCO
abrir ↗Exploit-DB
MaDDash 2.0.2 - Directory Listing
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ pro
23RISCO
abrir ↗Exploit-DB
ntp 4.2.8p11 - Local Buffer Overflow (PoC)
Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or es
28RISCO
abrir ↗Exploit-DB
Redis 5.0 - Denial of Service
Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers t
28RISCO
abrir ↗Exploit-DB
Pale Moon Browser < 27.9.3 - Use After Free (PoC)
A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.