Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
24.695 exploits
Exploit-DB✓ VexDay Proof
Translatepress Multilinugal WordPress plugin < 2.3.3 - Authenticated SQL Injection
Translatepress Multilinugal < 2.3.3 - Admin+ SQLi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
NEX-Forms < 7.9.7 - Authenticated SQLi
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Composr-CMS Version <=10.0.39 - Authenticated Remote Code Execution
Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Abantecart v1.3.2 - Authenticated Remote Code Execution
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Wordpress Plugin Zephyr Project Manager 3.2.42 - Multiple SQLi
Zephyr Project Manager < 3.2.5 - Multiple Unauthenticated SQLi
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Wordpress Plugin WP-UserOnline 2.88.0 - Stored Cross Site Scripting (XSS)
WP-UserOnline <= 2.88.0 - Authenticated (Admin+) Stored Cross-Site Scripting
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bookwyrm v0.4.3 - Authentication Bypass
Authentication Bypass by Primary Weakness in bookwyrm-social/bookwyrm
53RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Gitea 1.16.6 - Remote Code Execution (RCE) (Metasploit)
Gitea before 1.16.7 does not escape git fetch remote.
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Duplicator 1.4.7 - Information Disclosure
Duplicator < 1.4.7.1 - Unauthenticated System Information Disclosure
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
qdPM 9.1 - Remote Code Execution (RCE) (Authenticated) (v2)
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Wondershare Dr.Fone 12.0.7 - Privilege Escalation (ElevationService)
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send m
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SuiteCRM 7.11.18 - Remote Code Execution (RCE) (Authenticated) (Metasploit)
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumsta
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Movable Type 7 r.5002 - XMLRPC API OS Command Injection (Metasploit)
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 4.8.1 - Remote Code Execution (RCE)
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE)
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google SLO-Generator 2.0.0 - Code Execution
Code execution in SLO Generator via YAML Payload
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache HTTP Server 2.4.49 - Path Traversal & Remote Code Execution (RCE)
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
qdPM 9.1 - Remote Code Execution (Authenticated)
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.19 < 5.9 - 'Netfilter Local Privilege Escalation
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated) (2)
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Websvn 2.6.0 - Remote Code Execution (Unauthenticated)
WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search paramet
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Polkit 0.105-26 0.117-2 - Local Privilege Escalation
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Rocket.Chat 3.12.1 - NoSQL Injection (Unauthenticated)
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHPFusion 9.03.50 - Remote Code Execution
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pluck CMS 4.7.13 - File Upload Remote Code Execution (Authenticated)
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution (2)
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Chamilo LMS 1.11.14 - Remote Code Execution (Authenticated)
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a paramete
46RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GravCMS 1.10.7 - Unauthenticated Arbitrary File Write (Metasploit)
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.