Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8.829Nuclei 4.357Metasploit 3.489✓ só verificadosrecentespopularesrisco
24.460 exploits
Exploit-DB
htmly 2.8.0 - 'description' Stored Cross-Site Scripting (XSS)
htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.
23RISCO
abrir ↗Exploit-DB
Horde Groupware Webmail 5.2.22 - Stored XSS
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library befor
23RISCO
abrir ↗Exploit-DB
Tileserver-gl 3.0.0 - 'key' Reflected Cross-Site Scripting (XSS)
An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected u
43RISCO
abrir ↗Exploit-DB
MariaDB 10.2 - 'wsrep_provider' OS Command Execution
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
35RISCO
abrir ↗Exploit-DB
jQuery 1.2 - Cross-Site Scripting (XSS)
jQuery has a potential XSS vulnerability
55RISCO
abrir ↗Exploit-DB
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 - RCE
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacter
35RISCO
abrir ↗Exploit-DB
CITSmart ITSM 9.1.2.27 - 'query' Time-based Blind SQL Injection (Authenticated)
CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."
23RISCO
abrir ↗Exploit-DB
CITSmart ITSM 9.1.2.22 - LDAP Injection
CITSmart before 9.1.2.23 allows LDAP Injection.
28RISCO
abrir ↗Exploit-DB
jQuery 1.0.3 - Cross-Site Scripting (XSS)
Potential XSS vulnerability in jQuery
85RISCO
abrir ↗Exploit-DB
ExpressVPN VPN Router 1.0 - Router Login Panel's Integer Overflow
An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensi
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
vsftpd 2.3.4 - Backdoor Command Execution
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗Exploit-DB
PrestaShop 1.7.6.7 - 'location' Blind Sql Injection
Blind SQL Injection in PrestaShop
28RISCO
abrir ↗Exploit-DB
DMA Radius Manager 4.4.0 - Cross-Site Request Forgery (CSRF)
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
23RISCO
abrir ↗Exploit-DB
Composr 10.0.36 - Remote Code Execution
Composr 10.0.36 allows upload and execution of PHP files.
28RISCO
abrir ↗Exploit-DB
Linux Kernel 5.4 - 'BleedingTooth' Bluetooth Zero-Click Remote Code Execution
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adja
23RISCO
abrir ↗Exploit-DB
Linux Kernel 5.4 - 'BleedingTooth' Bluetooth Zero-Click Remote Code Execution
Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via a
23RISCO
abrir ↗Exploit-DB
Atlassian Jira Service Desk 4.9.1 - Unrestricted File Upload to XSS
The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remo
23RISCO
abrir ↗Exploit-DB
Dell OpenManage Server Administrator 9.4.0.0 - Arbitrary File Read
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
60RISCO
abrir ↗Exploit-DB
Composr CMS 10.0.36 - Cross Site Scripting
Composr 10.0.36 allows XSS in an XML script.
23RISCO
abrir ↗Exploit-DB
Google Chrome 86.0.4240 V8 - Remote Code Execution
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RISCO
abrir ↗Exploit-DB
Google Chrome 81.0.4044 V8 - Remote Code Execution
Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap
28RISCO
abrir ↗Exploit-DB
F5 BIG-IP 16.0.x - iControl REST Remote Code Execution (Unauthenticated)
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir ↗Exploit-DB
Concrete5 8.5.4 - 'name' Stored XSS
The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.p
23RISCO
abrir ↗Exploit-DB
SyncBreeze 10.1.16 - XML Parsing Stack-based Buffer Overflow
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary co
23RISCO
abrir ↗Exploit-DB
Dolibarr ERP 11.0.4 - File Upload Restrictions Bypass (Authenticated RCE)
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code executio
28RISCO
abrir ↗Exploit-DB
Linksys EA7500 2.0.8.194281 - Cross-Site Scripting
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differen
23RISCO
abrir ↗Exploit-DB
MyBB 1.8.25 - Poll Vote Count SQL Injection
SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Codiad 2.8.4 - Remote Code Execution (Authenticated)
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.
35RISCO
abrir ↗Exploit-DB
WordPress Plugin Delightful Downloads Jquery File Tree 1.6.6 - Path Traversal
jqueryFileTree 2.1.5 and older Directory Traversal
50RISCO
abrir ↗Exploit-DB
MyBB 1.8.25 - Chained Remote Command Execution
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.