Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8.182Nuclei 4.217Metasploit 3.462✓ só verificadosrecentespopularesrisco
22.786 exploits
Exploit-DB
libao 1.2.0 - Denial of Service
The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of servic
23RISCO
abrir ↗Exploit-DB
Sound eXchange (SoX) 14.4.2 - Multiple Vulnerabilities
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (d
23RISCO
abrir ↗Exploit-DB
libvorbis 1.3.5 - Multiple Vulnerabilities
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial
23RISCO
abrir ↗Exploit-DB
Vorbis Tools oggenc 1.4.0 - '.wav' Denial of Service
The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of serv
23RISCO
abrir ↗Exploit-DB
Jenkins < 1.650 - Java Deserialization
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex
60RISCO
abrir ↗Exploit-DB
McAfee Security Scan Plus - Remote Command Execution
A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior
28RISCO
abrir ↗Exploit-DB
SoundTouch 1.9.2 - Multiple Vulnerabilities
The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attack
23RISCO
abrir ↗Exploit-DB
libjpeg-turbo 1.5.1 - Denial of Service
The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service
23RISCO
abrir ↗Exploit-DB
SoundTouch 1.9.2 - Multiple Vulnerabilities
The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to
23RISCO
abrir ↗Exploit-DB
LAME 3.99.5 - Multiple Vulnerabilities
The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of ser
23RISCO
abrir ↗Exploit-DB
SoundTouch 1.9.2 - Multiple Vulnerabilities
The TDStretch::acceptNewOverlapLength function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote atta
23RISCO
abrir ↗Exploit-DB
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthor
38RISCO
abrir ↗Exploit-DB
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthor
43RISCO
abrir ↗Exploit-DB
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to exec
38RISCO
abrir ↗Exploit-DB
GNU libiberty - Buffer Overflow
Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB
AudioCoder 0.8.46 - Local Buffer Overflow (SEH)
Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RISCO
abrir ↗Exploit-DB
Microsoft Windows - '.LNK' Shortcut File Code Execution (Metasploit)
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISCO
abrir ↗Exploit-DB
WebKit JSC - 'ArgumentsEliminationPhase::transform' Incorrect LoadVarargs Handling
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB
WebKit JSC - 'JSArray::appendMemcpy' Uninitialized Memory Copy
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB
WebKit JSC - 'JSObject::putInlineSlow' / 'JSValue::putToPrimitive' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB
WebKit JSC - 'DFG::ByteCodeParser::flush(InlineStackEntry* inlineStackEntry)' Incorrect Scope Register Handling
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB
WebKit - 'WebCore::RenderObject' with Accessibility Enabled Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB
WebKit - 'WebCore::AccessibilityNodeObject::textUnderElement' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB
WebKit - 'WebCore::Node::getFlag' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB
Razer Synapse 2.20.15.1104 - rzpnk.sys ZwOpenProcess (Metasploit)
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpe
60RISCO
abrir ↗Exploit-DB
Microsoft Internet Explorer - 'mshtml.dll' Remote Code Execution (MS17-007)
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilde
93RISCO
abrir ↗Exploit-DB
WebKit - 'WebCore::AccessibilityRenderObject::handleAriaExpandedChanged' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB
WebKit - 'WebCore::Node::nextSibling' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB
WebKit - 'WebCore::getCachedWrapper' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB
WebKit - 'WebCore::InputType::element' Use-After-Free (1)
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.