Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.442exploits catalogados
34.431CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.497GitHub PoC 13.624VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB✓ VexDay Proof
Google Android - 'gpsOneXtra' Data Files Denial of Service
The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 be
23RISCO
abrir ↗Exploit-DB
Linux Kernel 4.6.2 (Ubuntu 16.04.1) - 'IP6T_SO_SET_REPLACE' Local Privilege Escalation
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux
38RISCO
abrir ↗Exploit-DB
Apache Tomcat 8/7/6 (RedHat Based Distros) - Local Privilege Escalation
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distribu
38RISCO
abrir ↗Exploit-DB
HP Client 9.1/9.0/8.1/7.9 - Command Injection
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Firepower Threat Management Console 6.0.1 - Remote Command Execution
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users
60RISCO
abrir ↗Exploit-DB
Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusion
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via
50RISCO
abrir ↗Exploit-DB
Cisco Firepower Threat Management Console 6.0.1 - Hard-Coded MySQL Credentials
Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive
23RISCO
abrir ↗Exploit-DB
ISC BIND 9 - Denial of Service
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 8/7/6 (Debian-Based Distros) - Local Privilege Escalation
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debia
38RISCO
abrir ↗Exploit-DB
Grandsteam GXV3611_HD - SQL Injection
SQL injection vulnerability on the Grandstream GXV3611_HD camera with firmware before 1.0.3.9 beta allows remote attacke
23RISCO
abrir ↗Exploit-DB
Symantec Messaging Gateway 10.6.1 - Directory Traversal
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote au
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google Android 5.0 < 5.1.1 - 'Stagefright' .MP4 tx3g Integer Overflow (Metasploit)
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 4.6.3 (x86) - 'Netfilter' Local Privilege Escalation (Metasploit)
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - RegLoadAppKey Hive Enumeration Privilege Escalation (MS16-111)
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 8.1 Update 2 / 10 10586 (x86/x64) - NtLoadKeyEx User Hive Attachment Point Privilege Escalation (MS16-111)
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Crash When Freeing Memory After AVC decoding
Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635
28RISCO
abrir ↗Exploit-DB
Exponent CMS 2.3.9 - Blind SQL Injection
Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
JCraft/JSch Java Secure Channel 0.1.53 - Recursive sftp-get Directory Traversal
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allow
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kerberos - Security Feature Bypass (MS16-101)
Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec RAR Decomposer Engine (Multiple Products) - Out-of-Bounds Read / Out-of-Bounds Write
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP);
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office PowerPoint 2010 - Invalid Pointer Reference
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 20
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec RAR Decomposer Engine (Multiple Products) - Out-of-Bounds Read / Out-of-Bounds Write
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP);
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VMware Workstation - 'vprintproxy.exe' TrueType NAME Tables Heap Buffer Overflow (PoC)
VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado Thin
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VMware Workstation - 'vprintproxy.exe' JPEG2000 Images Multiple Memory Corruptions
tpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, whe
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NetBSD - 'mail.local(8)' Local Privilege Escalation (Metasploit)
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
38RISCO
abrir ↗Exploit-DB
Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can
23RISCO
abrir ↗Exploit-DB
Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX G
23RISCO
abrir ↗Exploit-DB
Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline
23RISCO
abrir ↗Exploit-DB
Open-Xchange App Suite 7.8.2 - Cross-Site Scripting
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical atta
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cherry Music 0.35.1 - Arbitrary File Disclosure
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary file
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.