Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8.156Nuclei 4.201Metasploit 3.462✓ só verificadosrecentespopularesrisco
22.786 exploits
Exploit-DB
QEMU Guest Agent 2.12.50 - Denial of Service
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 h
28RISCO
abrir ↗Exploit-DB
GreenCMS 2.3.0603 - Information Disclosure
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_d
28RISCO
abrir ↗Exploit-DB
phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (2)
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir ↗Exploit-DB
phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (1)
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir ↗Exploit-DB
LFCMS 3.7.0 - Cross-Site Request Forgery (Add User)
A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.
23RISCO
abrir ↗Exploit-DB
LFCMS 3.7.0 - Cross-Site Request Forgery (Add Admin)
Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authen
23RISCO
abrir ↗Exploit-DB
Dell EMC RecoverPoint < 5.1.2 - Local Root Command Execution
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command inje
35RISCO
abrir ↗Exploit-DB
MaDDash 2.0.2 - Directory Listing
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provi
23RISCO
abrir ↗Exploit-DB
MaDDash 2.0.2 - Directory Listing
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ pro
23RISCO
abrir ↗Exploit-DB
MaDDash 2.0.2 - Directory Listing
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ pr
23RISCO
abrir ↗Exploit-DB
MaDDash 2.0.2 - Directory Listing
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provi
23RISCO
abrir ↗Exploit-DB
Microsoft Windows 10 - Desktop Bridge Virtual Registry CVE-2018-0880 Incomplete Fix Privilege Escalation
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RISCO
abrir ↗Exploit-DB
Microsoft Windows 10 - Desktop Bridge Activation Arbitrary Directory Creation Privilege Escalation
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RISCO
abrir ↗Exploit-DB
ntp 4.2.8p11 - Local Buffer Overflow (PoC)
Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or es
28RISCO
abrir ↗Exploit-DB
Redis 5.0 - Denial of Service
Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers t
28RISCO
abrir ↗Exploit-DB
IPConfigure Orchid VMS 2.0.5 - Directory Traversal / Information Disclosure (Metasploit)
IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.
50RISCO
abrir ↗Exploit-DB
Apache CouchDB < 2.1.0 - Remote Code Execution
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISCO
abrir ↗Exploit-DB
Pale Moon Browser < 27.9.3 - Use After Free (PoC)
A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.
23RISCO
abrir ↗Exploit-DB
Nikto 2.1.6 - CSV Injection
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the S
28RISCO
abrir ↗Exploit-DB
Microsoft COM for Windows - Privilege Escalation
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized
100RISCO
abrir ↗Exploit-DB
Redis-cli < 5.0 - Buffer Overflow (PoC)
Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution
23RISCO
abrir ↗Exploit-DB
OEcms 3.1 - Cross-Site Scripting
A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerabil
38RISCO
abrir ↗Exploit-DB
Dimofinf CMS 3.0.0 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arb
23RISCO
abrir ↗Exploit-DB
Joomla! Component Ek Rishta 2.10 - SQL Injection
router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to
23RISCO
abrir ↗Exploit-DB
RSLinx Classic and FactoryTalk Linx Gateway - Privilege Escalation
An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.
23RISCO
abrir ↗Exploit-DB
Microsoft Windows 10 - Child Process Restriction Mitigation Bypass
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows
23RISCO
abrir ↗Exploit-DB
DHCP Client - Command Injection 'DynoRoot' (Metasploit)
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISCO
abrir ↗Exploit-DB
MACCMS 10 - Cross-Site Request Forgery (Add User)
Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.
23RISCO
abrir ↗Exploit-DB
glibc - 'realpath()' Privilege Escalation (Metasploit)
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir ↗Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.