Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.056exploits catalogados
35.925CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.392VulnCheck XDB 8.755Nuclei 4.333Metasploit 3.478✓ só verificadosrecentespopularesrisco
22.640 exploits
Referência
CVE-2017-14143
The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, wh
60RISCO
abrir ↗Referência✓ VexDay Proof
MOG-WebShop - 'index.php?group' SQL Injection
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência
CVE-2015-3302
The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1
28RISCO
abrir ↗Referência
CVE-2020-24186
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISCO
abrir ↗Referência
CVE-2009-1330
Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long fil
28RISCO
abrir ↗Referência
CVE-2009-4437
Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL comma
23RISCO
abrir ↗Referência✓ VexDay Proof
Icarus 2.0 - '.pgn' Local Stack Overflow (SEH)
Stack-based buffer overflow in Icarus 2.0 allows remote attackers to cause a denial of service (application crash) or ex
23RISCO
abrir ↗Referência
CVE-2016-6272
XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing s
28RISCO
abrir ↗Referência
CVE-2018-20525
Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
28RISCO
abrir ↗Referência✓ VexDay Proof
PPLive 1.9.21 - '/LoadModule' URI Handlers Argument Injection
Multiple argument injection vulnerabilities in PPLive.exe in PPLive 1.9.21 and earlier allow remote attackers to execute
23RISCO
abrir ↗Referência
CVE-2018-20525
Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
28RISCO
abrir ↗Referência
CVE-2013-4341
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, an
43RISCO
abrir ↗Referência
CVE-2005-0116
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacte
60RISCO
abrir ↗Referência
CVE-2021-40379
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 doe
28RISCO
abrir ↗Referência
CVE-2009-2339
SQL injection vulnerability in index.php in Rentventory allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permis
23RISCO
abrir ↗Referência
CVE-2010-3143
Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to
28RISCO
abrir ↗Referência
CVE-2010-3227
Stack-based buffer overflow in the UpdateFrameTitleForDocument method in the CFrameWnd class in mfc42.dll in the Microso
28RISCO
abrir ↗Referência
CVE-2005-2842
Buffer overflow in dwrcs.exe in DameWare Mini Remote Control before 4.9.0 allows remote attackers to execute arbitrary c
28RISCO
abrir ↗Referência✓ VexDay Proof
Wireshark 1.0.6 - PN-DCP Format String (PoC)
Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attacker
28RISCO
abrir ↗Referência✓ VexDay Proof
PrecisionID Datamatrix - ActiveX Arbitrary File Overwrite
Multiple insecure method vulnerabilities in PRECIS~2.DLL in the PrecisionID Datamatrix ActiveX control (DMATRIXLib.Datam
23RISCO
abrir ↗Referência
CVE-2016-0015
DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
35RISCO
abrir ↗Referência
CVE-2019-14348
The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via
28RISCO
abrir ↗Referência
CVE-2016-3223
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold an
28RISCO
abrir ↗Referência
CVE-2021-46387
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads t
43RISCO
abrir ↗Referência
CVE-2019-19368
A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker ca
43RISCO
abrir ↗Referência
CVE-2021-44595
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send m
28RISCO
abrir ↗Referência
CVE-2014-2908
Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x
43RISCO
abrir ↗Referência
CVE-2019-9955
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, U
43RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.