Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.334VulnCheck XDB 8.195Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
20.003 exploits
Referência
CVE-2018-6383
Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but
28RISCO
abrir ↗Referência
CVE-2018-7739
antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and
35RISCO
abrir ↗Referência
CVE-2015-6589
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before
28RISCO
abrir ↗Referência
CVE-2015-6589
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before
28RISCO
abrir ↗Referência
CVE-2014-5465
Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress
28RISCO
abrir ↗Referência
eXtremail 2.1.1 - 'memmove()' Remote Denial of Service
Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execu
28RISCO
abrir ↗Referência
GuildFTPd 0.999.8.11/0.999.14 - Heap Corruption (PoC) / Denial of Service
GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possib
50RISCO
abrir ↗Referência
CVE-2011-0421
The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a Z
28RISCO
abrir ↗Referência
Sun Solaris 10 - snoop(1M) Utility Remote Command Execution
Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o op
28RISCO
abrir ↗Referência
CVE-2019-3010
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RISCO
abrir ↗Referência
CVE-2017-6444
The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast netw
28RISCO
abrir ↗Referência
CVE-2017-6444
The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast netw
28RISCO
abrir ↗Referência
CVE-2021-25159
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in v
28RISCO
abrir ↗Referência
CVE-2009-4491
thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers
53RISCO
abrir ↗Referência
Windows 10.0.17763.7009 - spoofing vulnerability
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir ↗Referência
iPrimal Forums - '/admin/index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in (1) index.php and (2) admin/index.php in IPrimal Forums as of 20061105 allows
23RISCO
abrir ↗Referência
VideoLAN VLC Media Player 0.8.6i - '.tta' File Parsing Heap Overflow (PoC)
Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause
28RISCO
abrir ↗Referência
CVE-2019-17424
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows re
28RISCO
abrir ↗Referência
windows 10/11 - NTLM Hash Disclosure Spoofing
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir ↗Referência
CVE-2016-2278
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows
28RISCO
abrir ↗Referência
CVE-2018-8056
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/ma
28RISCO
abrir ↗Referência
CVE-2015-1365
Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows rem
28RISCO
abrir ↗Referência
CVE-2018-7739
antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and
35RISCO
abrir ↗Referência
CVE-2015-1365
Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows rem
28RISCO
abrir ↗Referência
CVE-2021-25681
AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. T
28RISCO
abrir ↗Referência
CVE-2019-10863
A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows on
28RISCO
abrir ↗Referência
TeemIp IPAM < 2.4.0 - 'new_config' Command Injection (Metasploit)
A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows on
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.