Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.953exploits catalogados
36.205CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.986VulnCheck XDB 8.829Nuclei 4.357Metasploit 3.489✓ só verificadosrecentespopularesrisco
19.066 exploits
Exploit-DB✓ VexDay Proof
Zahir Enterprise Plus 6 - Stack Buffer Overflow (Metasploit)
Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute a
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Unitrends UEB - HTTP API Remote Code Execution (Metasploit)
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Navigate CMS - (Unauthenticated) Remote Code Execution (Metasploit)
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs N
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Navigate CMS - (Unauthenticated) Remote Code Execution (Metasploit)
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigat
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerabili
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves b
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateS
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PCProtect 4.8.35 - Privilege Escalation
PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - Sandbox Escape
An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privil
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - Sandbox Escape
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - Sandbox Escape
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel - VMA Use-After-Free via Buggy vmacache_flush_all() Fastpath Local Privilege Escalation
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Penny Auction Factory 2.0.4 - SQL Injection
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order p
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Raffle Factory 3.5.2 - SQL Injection
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order paramete
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris - 'EXTREMEPARR' dtappgather Privilege Escalation (Metasploit)
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (C
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::RenderTreeBuilder::removeAnonymousWrappersForInlineChildrenIfNeeded' Use-After-Free
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::InlineTextBox::paint' Out-of-Bounds Read
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Super Cms Blog Pro 1.0 - SQL Injection
SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Article Factory Manager 4.3.9 - SQL Injection
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_e
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Jobs Factory 2.0.4 - SQL Injection
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Swap Factory 2.2.1 - SQL Injection
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Social Factory 3.8.3 - SQL Injection
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radiu
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Music Collection 3.0.3 - SQL Injection
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Reverse Auction Factory 4.3.8 - SQL Injection
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::RenderMultiColumnSet::updateMinimumColumnHeight' Use-After-Free
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::SVGTRefElement::updateReferencedText' Use-After-Free
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::AXObjectCache::handleMenuItemSelected' Use-After-Free
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::Node::ensureRareData' Use-After-Free
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::SVGTextLayoutAttributes::context' Use-After-Free
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.