Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8.846Nuclei 4.361Metasploit 3.490✓ só verificadosrecentespopularesrisco
24.695 exploits
Exploit-DB✓ VexDay Proof
WordPress Plugin Paid Memberships Pro 1.7.14.2 - Directory Traversal
Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mantis Bug Tracker 1.2.0a3 < 1.2.17 XmlImportExport Plugin - PHP Code Injection (Metasploit) (2)
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a cr
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mantis Bug Tracker 1.2.0a3 < 1.2.17 XmlImportExport Plugin - PHP Code Injection (Metasploit) (1)
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a cr
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mantis Bug Tracker 1.2.0a3 < 1.2.17 XmlImportExport Plugin - PHP Code Injection (Metasploit) (1)
The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arb
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 8 - Fixed Col Span ID (Full ASLR + DEP + EMET 5.1 Bypass) (MS12-037)
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allo
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-064) (Metasploit)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (via Python) (MS14-064) (Metasploit)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (via Python) (MS14-064) (Metasploit)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OSSEC 2.8 - 'hosts.deny' Local Privilege Escalation
host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, whi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-064) (Metasploit)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Digi Online Examination System 2.0 - Unrestricted Arbitrary File Upload
Unrestricted file upload vulnerability in the Photo functionality in DigitalVidhya Digi Online Examination System 2.0 al
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 11 - OLE Automation Array Remote Code Execution (1)
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
vldPersonals 2.7 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1 allows remote attackers to inject arbitrary web sc
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
vldPersonals 2.7 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in vldPersonals before 2.7.1 allow remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Visual Mining NetCharts Server - Remote Code Execution (Metasploit)
Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary co
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpSound Music Sharing Platform 1.0.5 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in phpSound 1.0.5 allow remote attackers to inject arbitrary web scr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Citrix Netscaler SOAP Handler - Remote Code Execution (Metasploit)
Unspecified vulnerability in the management interface in Citrix NetScaler Application Delivery Controller (ADC) and NetS
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Belkin N750 - 'jump?login' Remote Buffer Overflow
Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote a
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
X7 Chat 2.0.5 - 'message.php' PHP Code Execution (Metasploit)
lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a c
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Remote Code Execution)
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
20RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
20RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
20RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
20RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
20RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MAARCH 1.4 - Arbitrary File Upload
Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earl
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Enalean Tuleap 7.2 - XML External Entity File Disclosure
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.