Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.497GitHub PoC 13.627VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB✓ VexDay Proof
Adobe Flash - LMZA Property Decoding Heap Corruption
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - ATF Processing Overflow
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RISCO
abrir ↗Exploit-DB
IPS Community Suite 4.1.12.3 - PHP Code Injection
applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Bo
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ruby on Rails ActionPack Inline ERB - Code Execution (Metasploit)
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GNU Wget < 1.18 - Arbitrary File Upload / Remote Code Execution
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RISCO
abrir ↗Exploit-DB
Python smtplib 2.7.11 / 3.4.4 / 3.5.1 - Man In The Middle StartTLS Stripping
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an e
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ktools Photostore 4.7.5 - Blind SQL Injection
SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to e
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - PowerPoint Misaligned Stream-cache Remote Stack Buffer Overflow (PoC)
Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - TNEF Decoder Integer Overflow
Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); S
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager 12.1 - Multiple Vulnerabilities
Open redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - 'dec2lha Library' Remote Stack Buffer Overflow (PoC)
Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager 12.1 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in management scripts in Symantec Endpoint Protection Manager
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - Heap Overflow Modifying MIME Messages
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager 12.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM)
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - Missing Bounds Checks in dec2zip ALPkOldFormatDecompressor::UnShrink
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - Unpacking RAR Multiple Remote Memory Corruptions
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RISCO
abrir ↗Exploit-DB
Microsoft Windows 7 SP1 (x86) - Local Privilege Escalation (MS16-014)
CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0
23RISCO
abrir ↗Exploit-DB
Wolf CMS 0.8.2 - Arbitrary File Upload (Metasploit)
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/
28RISCO
abrir ↗Exploit-DB
Microsoft Internet Explorer 11 (Windows 10) - VBScript Memory Corruption (MS16-051)
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RISCO
abrir ↗Exploit-DB
Wolf CMS 0.8.2 - Arbitrary File Upload (Metasploit)
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/
28RISCO
abrir ↗Exploit-DB
SAP NetWeaver AS JAVA 7.1 < 7.5 - Directory Traversal
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary fil
83RISCO
abrir ↗Exploit-DB
SAP NetWeaver AS JAVA 7.1 < 7.5 - 'ctcprotocol Servlet' XML External Entity
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remo
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Custom Font Disable Policy Bypass
The kernel-mode driver in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted applica
23RISCO
abrir ↗Exploit-DB
Microsoft Internet Explorer 11 - Garbage Collector Attribute Type Confusion (MS16-063)
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'ATMFD.dll' NamedEscape 0x250C Pool Corruption (MS16-074)
atmfd.dll in the Adobe Type Manager Font Driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Wind
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel - 'ecryptfs' '/proc/$pid/environ' Local Privilege Escalation
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to ga
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'gdi32.dll' Multiple DIB-Related EMF Record Handlers Heap Out-of-Bounds Reads/Memory Disclosure (MS16-074)
GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, W
28RISCO
abrir ↗Exploit-DB
Symphony CMS 2.6.7 - Session Fixation
Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers
23RISCO
abrir ↗Exploit-DB
SolarWinds Virtualization Manager - Local Privilege Escalation
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguratio
71RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 7 - win32k Bitmap Use-After-Free (MS16-062) (2)
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.