Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8.829Nuclei 4.357Metasploit 3.489✓ só verificadosrecentespopularesrisco
24.460 exploits
Exploit-DB
Chamilo LMS 1.11.14 - Account Takeover
A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Product Slider for WooCommerce 1.13.21 - Cross Site Scripting (XSS)
PickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)
43RISCO
abrir ↗Exploit-DB
Mozilla Firefox 67 - Array.pop JIT Type Confusion
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RISCO
abrir ↗Exploit-DB
PHP Unit 4.8.28 - Remote Code Execution (RCE) (Unauthenticated)
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir ↗Exploit-DB
Moodle 3.11.4 - SQL Injection
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web serv
35RISCO
abrir ↗Exploit-DB
Wordpress Plugin Download Monitor WordPress V 4.4.4 - SQL Injection (Authenticated)
Download Monitor < 4.4.5 - Admin+ SQL Injection
61RISCO
abrir ↗Exploit-DB
Wordpress Plugin 404 to 301 2.0.2 - SQL-Injection (Authenticated)
The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.
50RISCO
abrir ↗Exploit-DB
WordPress Plugin Learnpress 4.1.4.1 - Arbitrary Image Renaming
LearnPress < 4.1.5 - Arbitrary Image Renaming
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Contact Form Check Tester 1.0.2 - Broken Access Control
Contact Form Check Tester <= 1.0.2 - Broken Access Control to Cross-Site Scripting (XSS)
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Domain Check 1.0.16 - Reflected Cross-Site Scripting (XSS) (Authenticated)
Domain Check < 1.0.17 - Reflected Cross-Site Scripting
43RISCO
abrir ↗Exploit-DB
WordPress Plugin Post Grid 2.1.1 - Cross Site Scripting (XSS)
Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)
43RISCO
abrir ↗Exploit-DB
WordPress Plugin Modern Events Calendar V 6.1 - SQL Injection (Unauthenticated)
Modern Events Calendar < 6.1.5 - Unauthenticated Blind SQL Injection
60RISCO
abrir ↗Exploit-DB
PolicyKit-1 0.105-31 - Privilege Escalation
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗Exploit-DB
WordPress Plugin Mortgage Calculators WP 1.52 - Stored Cross-Site Scripting (XSS) (Authenticated)
Mortgage Calculators WP < 1.56 - Admin+ Stored Cross-Site Scripting
23RISCO
abrir ↗Exploit-DB
WordPress Plugin RegistrationMagic V 5.0.1.5 - SQL Injection (Authenticated)
RegistrationMagic < 5.0.1.6 - Admin+ SQL Injection
60RISCO
abrir ↗Exploit-DB
Oracle WebLogic Server 14.1.1.0.0 - Local File Inclusion
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISCO
abrir ↗Exploit-DB
PHPIPAM 1.4.4 - SQLi (Authenticated)
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISCO
abrir ↗Exploit-DB
Creston Web Interface 1.0.0.2159 - Credential Disclosure
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI
60RISCO
abrir ↗Exploit-DB
WordPress Plugin Frontend Uploader 1.3.2 - Stored Cross Site Scripting (XSS) (Unauthenticated)
Frontend Uploader <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting
28RISCO
abrir ↗Exploit-DB
VUPlayer 2.49 - '.wax' Local Buffer Overflow (DEP Bypass)
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RISCO
abrir ↗Exploit-DB
Open-AudIT Community 4.2.0 - Cross-Site Scripting (XSS) (Authenticated)
Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad
23RISCO
abrir ↗Exploit-DB
CoreFTP Server build 725 - Directory Traversal (Authenticated)
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP
23RISCO
abrir ↗Exploit-DB
Nettmp NNT 5.1 - SQLi Authentication Bypass
Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel
23RISCO
abrir ↗Exploit-DB
SAFARI Montage 8.5 - Reflected Cross Site Scripting (XSS)
Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScrip
23RISCO
abrir ↗Exploit-DB
WordPress Plugin WP Visitor Statistics 4.7 - SQL Injection
WP Visitor Statistics (Real Time Traffic) < 4.8 - Subscriber+ SQL Injection
50RISCO
abrir ↗Exploit-DB
ConnectWise Control 19.2.24707 - Username Enumeration
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumer
28RISCO
abrir ↗Exploit-DB
WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read (Unauthenticated)
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISCO
abrir ↗Exploit-DB
Gerapy 0.9.7 - Remote Code Execution (RCE) (Authenticated)
Gerapy may contain remote code execution vulnerability
60RISCO
abrir ↗Exploit-DB
Automox Agent 32 - Local Privilege Escalation
Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.