Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.899GitHub PoC 13.937VulnCheck XDB 8.510Nuclei 4.239Metasploit 3.468✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB✓ VexDay Proof
Altap Salamander 2.5 PE Viewer - Local Buffer Overflow (Metasploit)
Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (Englis
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe PDF - Escape EXE Social Engineering (No JavaScript) (Metasploit)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
gitWeb 1.7.3.3 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web s
23RISCO
abrir ↗Exploit-DB
Pointter PHP Micro-Blogging Social Network - Unauthorized Privilege Escalation
Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrativ
23RISCO
abrir ↗Exploit-DB
Mantis Bug Tracker 1.2.3 - 'db_type' Cross-Site Scripting / Full Path Disclosure
admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to obtain sensitive information via an inv
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'search.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.1.3712 allows remote attack
23RISCO
abrir ↗Exploit-DB
Blog:CMS 4.2.1e - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 8 - CSS Parser
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in msh
60RISCO
abrir ↗Exploit-DB
Mantis Bug Tracker 1.2.3 - 'db_type' Local File Inclusion
Directory traversal vulnerability in admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to in
23RISCO
abrir ↗Exploit-DB
Mantis Bug Tracker 1.2.3 - 'db_type' Cross-Site Scripting / Full Path Disclosure
Cross-site scripting (XSS) vulnerability in admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attacker
23RISCO
abrir ↗Exploit-DB
Blog:CMS 4.2.1e - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in admin/libs/ADMIN.php in BLOG:CMS 4.2.1.e, and possibly earlier, allow
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Tivoli Storage Manager (TSM) - Local Privilege Escalation
Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Java - 'Statement.invoke()' Trusted Method Chain (Metasploit)
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18,
100RISCO
abrir ↗Exploit-DB
BEdita 3.0.1.2550 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in BEdita before 3.1 allow remote attackers to hijack the aut
23RISCO
abrir ↗Exploit-DB
Pointter PHP Content Management System - Unauthorized Privilege Escalation
Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative pr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to exe
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Crystal Reports Viewer 12.0.0.549 - 'PrintControl.dll' ActiveX
Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Axis2 / SAP BusinessObjects - (Authenticated) Code Execution (via SOAP) (Metasploit)
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Axis2 - (Authenticated) Code Execution (via REST) (Metasploit)
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which all
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RISCO
abrir ↗Exploit-DB
FontForge - '.BDF' Font File Stack Buffer Overflow (PoC)
Stack-based buffer overflow in FontForge 20100501 allows remote attackers to cause a denial of service (application cras
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - DHTML Behaviour Use-After-Free (MS10-018) (Metasploit)
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, an
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Clear iSpot/Clearspot 2.0.0.0 - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Exim 4.63 - Remote Command Execution
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to exe
100RISCO
abrir ↗Exploit-DB
PHP 5.3.3 - NumberFormatter::getSymbol Integer Overflow
Integer overflow in the NumberFormatter::getSymbol (aka numfmt_get_symbol) function in PHP 5.3.3 and earlier allows cont
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox/Thunderbird/SeaMonkey - Multiple HTML Injection Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox before 3.5.16 and 3.6.x b
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.