Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.324exploits catalogados
36.054CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.477VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
78.258 exploits
Exploit-DB
DMA Radius Manager 4.4.0 - Cross-Site Request Forgery (CSRF)
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
23RISCO
abrir ↗GitHub PoC
Buffer Overflow in Seattle Lab Mail (SLmail) 5.5 - POP3
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISCO
abrir ↗Exploit-DB
Composr 10.0.36 - Remote Code Execution
Composr 10.0.36 allows upload and execution of PHP files.
28RISCO
abrir ↗Exploit-DB
Composr CMS 10.0.36 - Cross Site Scripting
Composr 10.0.36 allows XSS in an XML script.
23RISCO
abrir ↗GitHub PoC
CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISCO
abrir ↗Metasploit600
Cisco Small Business RV Series Authentication Bypass and Command Injection
Cisco Small Business RV Series Routers Vulnerabilities
40RISCO
abrir ↗Exploit-DB
Dell OpenManage Server Administrator 9.4.0.0 - Arbitrary File Read
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
60RISCO
abrir ↗Metasploit600
Cisco Small Business RV Series Authentication Bypass and Command Injection
Cisco Small Business RV Series Routers Vulnerabilities
50RISCO
abrir ↗Exploit-DB
Atlassian Jira Service Desk 4.9.1 - Unrestricted File Upload to XSS
The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remo
23RISCO
abrir ↗Metasploit600
Microsoft Exchange ProxyShell RCE
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir ↗VulnCheck XDB
infoleak
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗VulnCheck XDB
initial-access
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir ↗VulnCheck XDB
initial-access
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir ↗Metasploit600
Microsoft Exchange ProxyShell RCE
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC
Exploit for CVE-2012-2982
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir ↗Metasploit600
Microsoft Exchange ProxyShell RCE
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISCO
abrir ↗GitHub PoC★ 6
[CVE-2021-21972] VMware vSphere Client Unauthorized File Upload to Remote Code Execution (RCE)
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir ↗Exploit-DB
Google Chrome 81.0.4044 V8 - Remote Code Execution
Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap
28RISCO
abrir ↗GitHub PoC
pwn3z/CVE-2019-19781-Citrix
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗GitHub PoC★ 37
vRealize RCE + Privesc (CVE-2021-21975, CVE-2021-21983, CVE-0DAY-?????)
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir ↗Exploit-DB
Google Chrome 86.0.4240 V8 - Remote Code Execution
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RISCO
abrir ↗GitHub PoC★ 1
Exploit Code for CVE-2020-1472 aka Zerologon
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC
capturingcats/CVE-2021-3156
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗VulnCheck XDB
local
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗GitHub PoC★ 3
Exploiting CVE-2014-7205 by injecting arbitrary JavaScript resulting in Remote Code Execution.
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t
60RISCO
abrir ↗GitHub PoC
delina1/CVE-2018-8174
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir ↗GitHub PoC
delina1/CVE-2018-8174_EXP
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir ↗GitHub PoC★ 1
CVE-2017-9805-Exploit
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2017-9805-Exploit
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.