Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
24.459 exploits
Exploit-DB
Employee Management System 1.0 - 'admin_id' SQLi
SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the ad
48RISCO
abrir ↗Exploit-DB
Blood Bank 1.0 - 'bid' SQLi
SQL Injection vulnerability in delete.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands
23RISCO
abrir ↗Exploit-DB
HNAS SMU 14.8.7825 - Information Disclosure
System Management Unit (SMU) versions prior to 14.8.7825.01, used to manage Hitachi Vantara NAS products is susceptible to unintended information disclosure via unprivileged access to SMU configuration backup data.
41RISCO
abrir ↗Exploit-DB
Teacher Subject Allocation Management System 1.0 - 'searchdata' SQLi
SQL Injection vulnerability in index.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers
23RISCO
abrir ↗Exploit-DB
JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE)
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir ↗Exploit-DB
Honeywell PM43 < P10.19.050004 - Remote Code Execution (RCE)
Printer web page invalid command execution
75RISCO
abrir ↗Exploit-DB
KiTTY 0.76.1.13 - 'Start Duplicated Session Username' Buffer Overflow
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insuf
41RISCO
abrir ↗Exploit-DB
KiTTY 0.76.1.13 - Command Injection
KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insuffic
41RISCO
abrir ↗Exploit-DB
KiTTY 0.76.1.13 - 'Start Duplicated Session Hostname' Buffer Overflow
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insuf
41RISCO
abrir ↗Exploit-DB
SolarView Compact 6.00 - Command Injection
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISCO
abrir ↗Exploit-DB
Viessmann Vitogate 300 2.1.3.0 - Remote Code Execution (RCE)
Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
70RISCO
abrir ↗Exploit-DB
Viessmann Vitogate 300 2.1.3.0 - Remote Code Execution (RCE)
Viessmann Vitogate 300 direct request
38RISCO
abrir ↗Exploit-DB
GitLab CE/EE < 16.7.2 - Password Reset
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISCO
abrir ↗Exploit-DB
Numbas < v7.3 - Remote Code Execution
Numbas editor before 7.3 mishandles editing of themes and extensions.
38RISCO
abrir ↗Exploit-DB
Hide My WP < 6.2.9 - Unauthenticated SQLi
Hide My WP < 6.2.9 - Unauthenticated SQLi
48RISCO
abrir ↗Exploit-DB
DataCube3 v1.0 - Unrestricted file upload 'RCE'
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An una
53RISCO
abrir ↗Exploit-DB
Ladder v0.0.21 - Server-side request forgery (SSRF)
An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request
41RISCO
abrir ↗Exploit-DB
Akaunting < 3.1.3 - RCE
An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company loc
60RISCO
abrir ↗Exploit-DB
DataCube3 v1.0 - Unrestricted file upload 'RCE'
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to
46RISCO
abrir ↗Exploit-DB
Petrol Pump Management Software v1.0 - Remote Code Execution via File Upload
File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a cra
53RISCO
abrir ↗Exploit-DB
Petrol Pump Management Software v1.0 - 'Address' Stored Cross Site Scripting
Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code
33RISCO
abrir ↗Exploit-DB
Petrol Pump Management Software v.1.0 - Stored Cross Site Scripting via SVG file
Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code
33RISCO
abrir ↗Exploit-DB
Petrol Pump Management Software v.1.0 - SQL Injection
SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a c
53RISCO
abrir ↗Exploit-DB
Wyrestorm Apollo VX20 < 1.3.58 - Incorrect Access Control 'Credentials Disclosure'
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext password
75RISCO
abrir ↗Exploit-DB
Wyrestorm Apollo VX20 < 1.3.58 - Account Enumeration
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only a
41RISCO
abrir ↗Exploit-DB
IBM i Access Client Solutions v1.1.2 - 1.1.4_ v1.1.4.3 - 1.1.9.4 - Remote Credential Theft
IBM i Access Client Solutions information disclosure
33RISCO
abrir ↗Exploit-DB
Wyrestorm Apollo VX20 < 1.3.58 - Incorrect Access Control 'DoS'
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /d
41RISCO
abrir ↗Exploit-DB
SureMDM On-premise < 6.31 - CAPTCHA Bypass User Enumeration
Bypassing CAPTCHA & Enumerating Usernames via Password Reset Page
33RISCO
abrir ↗Exploit-DB
Minio 2022-07-29T19-40-48Z - Path traversal
Authenticated requests for server update admin API allows path traversal in minio
53RISCO
abrir ↗Exploit-DB
Splunk 9.0.5 - admin account take over
‘edit_user’ Capability Privilege Escalation
78RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.