Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.104GitHub PoC 15.075VulnCheck XDB 8.883Nuclei 4.365Metasploit 3.493✓ só verificadosrecentespopularesrisco
79.386 exploits
Exploit-DB✓ VexDay Proof
Netatalk 3.1.12 - Authentication Bypass
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VBScript - VbsErase Reference Leak Use-After-Free
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
35RISCO
abrir ↗VulnCheck XDB
client-side
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗GitHub PoC
Weblogic(CVE-2017-10271)
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗VulnCheck XDB
client-side
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed wi
28RISCO
abrir ↗GitHub PoC★ 5
Flash 2018-15982 UAF
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VBScript - MSXML Execution Policy Bypass
A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly rest
35RISCO
abrir ↗GitHub PoC
https://github.com/milo2012/CVE-2018-0296.git
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISCO
abrir ↗Metasploit600
Mailcleaner Remote Code Execution
www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitra
30RISCO
abrir ↗GitHub PoC★ 6
LibSSH Authentication Bypass CVE-2018-10933
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir ↗GitHub PoC
qiantu88/CVE-2017-12617
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISCO
abrir ↗GitHub PoC
CVE-2003-0264 - SLMail 5.5 POP3 'PASS' Remote Buffer Overflow Vulnerability. Tested on Windows XP Professional SP3.
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISCO
abrir ↗VulnCheck XDB
initial-access
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISCO
abrir ↗VulnCheck XDB
initial-access
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISCO
abrir ↗GitHub PoC
CVE-2012-5106 - Freefloat FTP Server Buffer Overflow Vulnerability. Tested on Windows XP Professional SP3.
Stack-based buffer overflow in FreeFloat FTP Server 1.0 allows remote authenticated users to execute arbitrary code via
28RISCO
abrir ↗GitHub PoC
CVE-2004-2271 - Minishare 1.4.1 HTTP Server Remote Buffer Overflow Vulnerability. Tested on Windows XP Professional SP3.
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RISCO
abrir ↗Exploit-DB
Linux Kernel 4.4 - 'rtnetlink' Stack Memory Disclosure
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain
23RISCO
abrir ↗Exploit-DB
Yeswiki Cercopitheque - 'id' SQL Injection
SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to ex
23RISCO
abrir ↗Exploit-DB
Integria IMS 5.0.83 - 'search_string' Cross-Site Scripting
Artica Integria IMS 5.0.83 has XSS via the search_string parameter.
23RISCO
abrir ↗Exploit-DB
Bolt CMS < 3.6.2 - Cross-Site Scripting
Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and Ne
23RISCO
abrir ↗GitHub PoC
qiantu88/CVE-2018-8120
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Operational Decision Manager 8.x - XML External Entity Injection
IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) a
46RISCO
abrir ↗GitHub PoC
CVE-2007-1567 - WarFTP 1.65 'USER' Remote Buffer Overflow Vulnerability. Tested on Windows XP Professional SP3.
Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of s
35RISCO
abrir ↗GitHub PoC
Yable/CVE-2018-4878
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir ↗Exploit-DB
Integria IMS 5.0.83 - Cross-Site Request Forgery
Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary
23RISCO
abrir ↗Exploit-DB
MiniShare 1.4.1 - 'HEAD/POST' Remote Buffer Overflow
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD re
28RISCO
abrir ↗Exploit-DB
MiniShare 1.4.1 - 'HEAD/POST' Remote Buffer Overflow
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST re
28RISCO
abrir ↗Exploit-DB
SDL Web Content Manager 8.5.0 - XML External Entity Injection
The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive
23RISCO
abrir ↗GitHub PoC★ 85
An implementation of CVE-2009-0689 for the Nintendo Wii.
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'jscript!JsArrayFunctionHeapSort' Out-of-Bounds Write
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet
35RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.