Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
19.066 exploits
Exploit-DB✓ VexDay Proof
Qualcomm Android - Kernel Use-After-Free via Incorrect set_page_dirty() in KGSL
Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Spidermonkey - IonMonkey Unexpected ObjectGroup in ObjectGroupDispatch Operation
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, al
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Shopware - createInstanceFromNamedArguments PHP Object Instantiation Remote Code Execution (Metasploit)
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of t
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OS X - Feedback Assistant Race Condition (Metasploit)
A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A mali
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 1809 - 'CmKeyBodyRemapToVirtualForEnum' Arbitrary Key Enumeration Privilege Escalation
An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumeration, aka 'Windows
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Visual Voicemail for iPhone - IMAP NAMESPACE Processing Use-After-Free
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchO
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 XNU - 'in6_pcbdetach' Stale Pointer Use-After-Free
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Brocade Network Advisor 14.4.1 - Unauthenticated Remote Code Execution
A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 DFG JIT Compiler - 'HasIndexedProperty' Use-After-Free
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS M
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 XNU - Wild-read due to bad cast in stf_ioctl
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 JavaScriptCore - Loop-Invariant Code Motion (LICM) in DFG JIT Leaves Stack Variable Uninitialized
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS M
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 JavaScriptCore - AIR Optimization Incorrectly Removes Assignment to Register
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS M
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GetSimpleCMS - Unauthenticated Remote Code Execution (Metasploit)
An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Prime Infrastructure Health Monitor HA TarArchive - Directory Traversal / Remote Code Execution
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
78RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VMware Workstation 15.1.0 - DLL Hijacking
VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by t
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenProject 5.0.0 - 8.3.1 - SQL Injection
A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbi
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cortex Unshortenlink Analyzer < 1.1 - Server-Side Request Forgery
TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PostgreSQL 9.3 - COPY FROM PROGRAM Command Execution (Metasploit)
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Weblogic Server - 'AsyncResponseService' Deserialization Remote Code Execution (Metasploit)
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome 72.0.3626.119 - 'FileReader' Use-After-Free (Metasploit)
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ruby On Rails - DoubleTap Development Mode secret_key_base Remote Code Execution (Metasploit)
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AIS logistics ESEL-Server - Unauthenticated SQL Injection Remote Code Execution (Metasploit)
SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app)
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pimcore < 5.71 - Unserialize Remote Code Execution (Metasploit)
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/c
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Domoticz 4.10577 - Unauthenticated Remote Command Execution
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux - Missing Locking Between ELF coredump code and userfaultfd VMA Modification
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Domoticz 4.10577 - Unauthenticated Remote Command Execution
Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
systemd - DynamicUser can Create setuid Binaries when Assisted by Another Process
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allo
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
systemd - DynamicUser can Create setuid Binaries when Assisted by Another Process
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RARLAB WinRAR 5.61 - ACE Format Input Validation Remote Code Execution (Metasploit)
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VirtualBox 6.0.4 r128413 - COM RPC Interface Code Injection Host Privilege Escalation
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.