Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8.829Nuclei 4.357Metasploit 3.489✓ só verificadosrecentespopularesrisco
24.460 exploits
Exploit-DB✓ VexDay Proof
Movable Type 7 r.5002 - XMLRPC API OS Command Injection (Metasploit)
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISCO
abrir ↗Exploit-DB
Hikvision Web Server Build 210702 - Command Injection
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 4.8.1 - Remote Code Execution (RCE)
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir ↗Exploit-DB
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2)
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗Exploit-DB
WordPress Plugin TaxoPress 3.0.7.1 - Stored Cross-Site Scripting (XSS) (Authenticated)
TaxoPress < 3.0.7.2 - Authenticated Stored Cross-Site Scripting (XSS)
23RISCO
abrir ↗Exploit-DB
Jetty 9.4.37.v20210219 - Information Disclosure
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai
70RISCO
abrir ↗Exploit-DB
SonicWall SMA 10.2.1.0-17sv - Password Reset
An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal
45RISCO
abrir ↗Exploit-DB
WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS)
Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS)
23RISCO
abrir ↗Exploit-DB
myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
myfactory.FMS before 7.1-912 allows XSS via the Error parameter.
38RISCO
abrir ↗Exploit-DB
myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
myfactory.FMS before 7.1-912 allows XSS via the UID parameter.
38RISCO
abrir ↗Exploit-DB
Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
23RISCO
abrir ↗Exploit-DB
Plastic SCM 10.0.16.5622 - WebAdmin Server Access
Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
23RISCO
abrir ↗Exploit-DB
Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure
Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listi
28RISCO
abrir ↗Exploit-DB
Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traver
100RISCO
abrir ↗Exploit-DB
i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS)
A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enable
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE)
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗Exploit-DB
Sonicwall SonicOS 7.0 - Host Header Injection
A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management
43RISCO
abrir ↗Exploit-DB
Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RISCO
abrir ↗Exploit-DB
Maian-Cart 3.8 - Remote Code Execution (RCE) (Unauthenticated)
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the
50RISCO
abrir ↗Exploit-DB
django-unicorn 0.35.3 - Stored Cross-Site Scripting (XSS)
The Unicorn framework through 0.35.3 for Django allows XSS via component.name.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google SLO-Generator 2.0.0 - Code Execution
Code execution in SLO Generator via YAML Payload
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache HTTP Server 2.4.49 - Path Traversal & Remote Code Execution (RCE)
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗Exploit-DB
Atlassian Jira Server Data Center 8.16.0 - Arbitrary File Read
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RISCO
abrir ↗Exploit-DB
Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Read
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RISCO
abrir ↗Exploit-DB
WhatsUpGold 21.0.3 - Stored Cross-Site Scripting (XSS)
In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input.
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Select All Categories and Taxonomies 1.3.1 - Reflected Cross-Site Scripting (XSS)
Select All Categories and Taxonomies < 1.3.2 - Reflected Cross-Site Scripting (XSS)
43RISCO
abrir ↗Exploit-DB
WordPress Plugin Redirect 404 to Parent 1.3.0 - Reflected Cross-Site Scripting
Redirect 404 to Parent < 1.3.1 - Reflected Cross-Site Scripting (XSS)
43RISCO
abrir ↗Exploit-DB
WordPress Plugin TranslatePress 2.0.8 - Stored Cross-Site Scripting (XSS) (Authenticated)
TranslatePress < 2.0.9 - Authenticated Stored Cross-Site Scripting
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Popup 1.10.4 - Reflected Cross-Site Scripting (XSS)
Popup by Supsystic < 1.10.5 - Reflected Cross-Site scripting (XSS)
43RISCO
abrir ↗Exploit-DB
WordPress Plugin Ultimate Maps 1.2.4 - Reflected Cross-Site Scripting (XSS)
Ultimate Maps by Supsystic < 1.2.5 - Reflected Cross-Site scripting (XSS)
43RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.