Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8.883Nuclei 4.361Metasploit 3.493✓ só verificadosrecentespopularesrisco
79.305 exploits
VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗GitHub PoC★ 255
FileReader Exploit
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISCO
abrir ↗Exploit-DB
PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Request Forgery
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpag
23RISCO
abrir ↗GitHub PoC★ 6
CVE-2018-11686 - FlexPaper PHP Publish Service RCE <= 2.3.6
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_c
50RISCO
abrir ↗Metasploit600
PostgreSQL COPY FROM PROGRAM Command Execution
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir ↗GitHub PoC★ 14
GUI版 EXP
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome < M73 - FileSystemOperationRunner Use-After-Free
An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft VBScript - VbsErase Memory Corruption
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - Flash click2play Bypass with CObjectElement::FinalCreateObject
A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash obj
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome < M73 - MidiManagerWin Use-After-Free
An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 11 - VBScript Execution Policy Bypass in MSHTML
A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restri
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome < M73 - Data Race in ExtensionsGuestViewMessageFilter
Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially explo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RISCO
abrir ↗GitHub PoC★ 36
A multi-threaded Golang scanner to identify Ruby endpoints vulnerable to CVE-2019-5418
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome < M73 - Double-Destruction Race in StoragePartitionService
Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap c
41RISCO
abrir ↗Exploit-DB
MyBB Upcoming Events Plugin 1.32 - Cross-Site Scripting
An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name
23RISCO
abrir ↗GitHub PoC
Herramienta para revisar si es que un payload tiene componente malicioso de acuerdo a CVE-2018-20250
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir ↗Metasploit300
IBM BigFix Relay Server Sites and Package Enum
IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the upd
33RISCO
abrir ↗GitHub PoC★ 5
File Content Disclosure on Rails Test Case - CVE-2019-5418
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir ↗GitHub PoC★ 7
xConsoIe/CVE-2019-0193
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BMC Patrol Agent - Privilege Escalation Code Execution Execution (Metasploit)
An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for l
38RISCO
abrir ↗GitHub PoC★ 6
thinkphp5.*Rce CVE-2018-20062
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISCO
abrir ↗VulnCheck XDB
initial-access
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISCO
abrir ↗VulnCheck XDB
infoleak
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir ↗GitHub PoC★ 201
CVE-2019-5418 - File Content Disclosure on Ruby on Rails
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir ↗GitHub PoC
cve-2018-16283
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
50RISCO
abrir ↗GitHub PoC★ 10
Noodle [Moodle RCE] (v3.4.1) - CVE-2018-1133
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code exec
35RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.