Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.475 exploits
Exploit-DB
WUZHI CMS 4.1.0 - 'form[qq_10]' Cross-Site Scripting
WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 2003 SP2 - 'RRAS' SMB Remote Code Execution
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold,
35RISCO
abrir ↗Exploit-DB
Open-AudIT Community 2.2.0 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web s
23RISCO
abrir ↗Exploit-DB
2345 Security Guard 3.7 - '2345BdPcSafe.sys' Denial of Service
In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv
23RISCO
abrir ↗Exploit-DB
Open-AudIT Professional - 2.1.1 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary we
23RISCO
abrir ↗Exploit-DB
EMC RecoverPoint 4.3 - 'Admin CLI' Command Injection
An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0
23RISCO
abrir ↗Exploit-DB
MyBB Latest Posts on Profile Plugin 1.1 - Cross-Site Scripting
The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displ
23RISCO
abrir ↗Exploit-DB
Dell Touchpad - 'ApMsgFwd.exe' Denial of Service
An issue was discovered in Alps Pointing-device Driver 10.1.101.207. ApMsgFwd.exe allows the current user to map and wri
23RISCO
abrir ↗Exploit-DB
ModbusPal 1.6b - XML External Entity Injection
ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations c
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mantis Bug Tracker 1.1.3 - 'manage_proj_page' PHP Code Execution (Metasploit)
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISCO
abrir ↗Exploit-DB
Fastweb FASTGate 0.00.47 - Cross-Site Request Forgery
Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi act
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PlaySMS 1.4 - 'sendfromfile.php?Filename' (Authenticated) 'Code Execution (Metasploit)
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FTPShell Client 6.7 - Buffer Overflow
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with t
50RISCO
abrir ↗Exploit-DB
2345 Security Guard 3.7 - '2345NetFirewall.sys' Denial of Service
In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD)
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PlaySMS - 'import.php' (Authenticated) CSV File Upload Code Execution (Metasploit)
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Palo Alto Networks - 'readSessionVarsFromFile()' Session Corruption (Metasploit)
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISCO
abrir ↗Exploit-DB
CSP MySQL User Manager 2.3.1 - Authentication Bypass
CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a
23RISCO
abrir ↗Exploit-DB
DeviceLock Plug and Play Auditor 5.72 - Unicode Buffer Overflow (SEH)
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
28RISCO
abrir ↗Exploit-DB
GNU wget - Cookie Injection
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequen
28RISCO
abrir ↗Exploit-DB
IceWarp Mail Server < 11.1.1 - Directory Traversal
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary
50RISCO
abrir ↗Exploit-DB
WordPress Plugin WF Cookie Consent 1.1.3 - Cross-Site Scripting
An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scriptin
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome V8 - Object Allocation Size Integer Overflow
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows WMI - Recieve Notification Exploit (Metasploit)
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RISCO
abrir ↗Exploit-DB
GPON Routers - Authentication Bypass / Command Injection
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RISCO
abrir ↗Exploit-DB
JasperReports - (Authenticated) File Read
TIBCO JasperReports Server Information Disclosure Vulnerability
83RISCO
abrir ↗Exploit-DB
GPON Routers - Authentication Bypass / Command Injection
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images
100RISCO
abrir ↗Exploit-DB
TBK DVR4104 / DVR4216 - Credentials Leak
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir ↗Exploit-DB
LibreOffice/Open Office - '.odt' Information Disclosure
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
60RISCO
abrir ↗Exploit-DB
Norton Core Secure WiFi Router - 'BLE' Command Injection (PoC)
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::jsElementScrollHeightGetter' Use-After-Free
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.