Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8.829Nuclei 4.357Metasploit 3.489✓ só verificadosrecentespopularesrisco
24.695 exploits
Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQuerySystemInformation (information class 138_ QueryMemoryTopologyInformation)' Kernel Pool Memory Disclosure
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Android - Inter-Process munmap due to Race Condition in ashmem
In ashmem_ioctl of ashmem.c, there is an out-of-bounds write due to insufficient locking when accessing asma. This could
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Vanilla < 2.1.5 - Cross-Site Request Forgery
Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VX Search Enterprise 10.1.12 - Denial of Service
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The atta
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows win32k - Using SetClassLong to Switch Between CS_CLASSDC and CS_OWNDC Corrupts DC Cache
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wi
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ayukov NFTP FTP Client 2.0 - Remote Buffer Overflow (Metasploit)
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Xplico - Remote Code Execution (Metasploit)
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass / SQL Injection
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthentica
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle WebLogic < 10.3.6 - 'wls-wsat' Component Deserialisation Remote Command Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass / SQL Injection
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cambium ePMP1000 - 'get_chart' Shell via Command Injection (Metasploit)
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP Mercury LoadRunner Agent magentproc.exe - Remote Command Execution (Metasploit)
Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SysGauge Server 3.6.18 - Denial of Service
In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafte
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Tuleap 9.6 - Second-Order PHP Object Injection (Metasploit)
An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentEl
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Intel Content Protection HECI Service - Type Confusion Privilege Escalation
Type Confusion in Content Protection HECI Service in Intel Graphics Driver allows unprivileged user to elevate privilege
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 11 - 'jscript!JSONStringifyObject' Use-After-Free
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Window
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'jscript!JsArraySlice' Uninitialized Variable
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Window
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'jscript!NameTbl::GetValDef' Use-After-Free
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jenkins - XStream Groovy classpath Deserialization (Metasploit)
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - jscript.dll 'Array.sort' Heap Overflow
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'jscript!RegExpComp::Compile' Heap Overflow Through IE or Local Network via WPAD
Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Win
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'jscript!RegExpFncObj::LastParen' Out-of-Bounds Read
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Western Digital MyCloud - 'multi_uploadify' File Upload (Metasploit)
An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquer
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zoom Linux Client 2.0.106600.0904 - Command Injection
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when c
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GoAhead Web Server 2.5 < 3.6.5 - HTTPd 'LD_PRELOAD' Remote Code Execution
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zoom Linux Client 2.0.106600.0904 - Stack-Based Buffer Overflow (PoC)
Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FS Lynda Clone 1.0 - SQL Injection
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bus Booking Script 1.0 - 'txtname' SQL Injection
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Paid To Read Script 2.0.5 - 'uid' / 'fnum' / 'fn' SQL Injection
Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum para
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Palo Alto Networks Firewalls - Root Remote Code Execution
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.