Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
19.066 exploits
Exploit-DB✓ VexDay Proof
vsftpd 2.3.4 - Backdoor Command Execution
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Codiad 2.8.4 - Remote Code Execution (Authenticated)
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SonLogger 4.2.3.3 - Unauthenticated Arbitrary File Upload (Metasploit)
SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Con
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Golden FTP Server 4.70 - 'PASS' Buffer Overflow (2)
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AnyDesk 5.5.2 - Remote Code Execution
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execut
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zen Cart 1.5.7b - Remote Code Execution (Authenticated)
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FortiLogger 4.4.2.2 - Unauthenticated Arbitrary File Upload (Metasploit)
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Klog Server 2.4.1 - Unauthenticated Command Injection (Metasploit)
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Wordpress Plugin Simple Job Board 2.9.3 - Authenticated File Read (Metasploit)
Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Flink 1.11.0 - Unauthenticated Arbitrary File Read (Metasploit)
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Gitea 1.7.5 - Remote Code Execution
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to rem
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PaperStream IP (TWAIN) 1.42.0.5685 - Local Privilege Escalation
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes u
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sonatype Nexus 3.21.1 - Remote Code Execution (Authenticated)
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Klog Server 2.4.1 - Command Injection (Unauthenticated)
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Razer Chroma SDK Server 3.16.02 - Race Condition Remote File Execution
Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a ra
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ZeroShell 3.9.0 - 'cgi-bin/kerbynet' Remote Root Command Injection (Metasploit)
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bludit 3.9.2 - Auth Bruteforce Bypass
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CuteNews 2.1.2 - Remote Code Execution
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bludit 3.9.2 - Authentication Bruteforce Mitigation Bypass
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pi-hole 4.4.0 - Remote Code Execution (Authenticated)
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Synology DiskStation Manager - smart.cgi Remote Command Execution (Metasploit)
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authe
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Plesk/myLittleAdmin - ViewState .NET Deserialization (Metasploit)
The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcod
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebLogic Server - Deserialization RCE - BadAttributeValueExpException (Metasploit)
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Druva inSync Windows Client 6.6.3 - Local Privilege Escalation
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pi-Hole - heisenbergCompensator Blocklist OS Command Execution (Metasploit)
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Druva inSync Windows Client 6.5.2 - Local Privilege Escalation
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, u
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Docker-Credential-Wincred.exe - Privilege Escalation (Metasploit)
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-c
98RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
Unraid 6.8.0 allows authentication bypass.
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.