Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8.213Nuclei 4.218Metasploit 3.464✓ só verificadosrecentespopularesrisco
24.443 exploits
Exploit-DB✓ VexDay Proof
Apple Mac OSX / iOS Kernel - iokit Registry Iterator Manipulation Double-Free
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - no-more-senders Use-After-Free
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX / iOS - Unsandboxable Kernel Use-After-Free in Mach Vouchers
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - IOAccelMemoryInfoUserClient Use-After-Free
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - IOAccelDisplayPipeUserClient2 Use-After-Free
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (1)
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RISCO
abrir ↗Exploit-DB
FreeBSD SCTP ICMPv6 - Error Processing
The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, w
28RISCO
abrir ↗Exploit-DB
Linux Kernel 3.x/4.x - prima WLAN Driver Heap Overflow
Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka W
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (2)
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (1)
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RISCO
abrir ↗Exploit-DB
Huawei Mate 7 - '/dev/hifi_misc' Privilege Escalation
Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7
23RISCO
abrir ↗Exploit-DB
NTP - Local Privilege Escalation
The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ub
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CesarFTP 0.99g - XCWD Denial of Service
Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (applicat
50RISCO
abrir ↗Exploit-DB
Linux Kernel 4.4.1 - REFCOUNT Overflow Use-After-Free in Keyrings Local Privilege Escalation (1)
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir ↗Exploit-DB
Linux Kernel 4.4.1 - REFCOUNT Overflow Use-After-Free in Keyrings Local Privilege Escalation (2)
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir ↗Exploit-DB
SeaWell Networks Spectrum - Multiple Vulnerabilities
Directory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00.
23RISCO
abrir ↗Exploit-DB
SeaWell Networks Spectrum - Multiple Vulnerabilities
SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.
23RISCO
abrir ↗Exploit-DB
SeaWell Networks Spectrum - Multiple Vulnerabilities
SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account.
23RISCO
abrir ↗Exploit-DB
mcart.xls Bitrix Module 6.5.2 - SQL Injection
Multiple SQL injection vulnerabilities in the mcart.xls module 6.5.2 and earlier for Bitrix allow remote authenticated u
23RISCO
abrir ↗Exploit-DB
Roundcube Webmail 1.1.3 - Directory Traversal
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office / COM Object - 'WMALFXGFXDSP.dll' DLL Planting (MS16-007)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RISCO
abrir ↗Exploit-DB
WhatsUp Gold 16.3 - Remote Code Execution
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - devenum.dll!DeviceMoniker::Load() Heap Corruption Buffer Underflow (MS16-007)
DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
35RISCO
abrir ↗Exploit-DB
Grassroots DICOM (GDCM) 2.6.0 and 2.6.1 - ImageRegionReader::ReadIntoBuffer Buffer Overflow
Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cx
28RISCO
abrir ↗Exploit-DB
Linux Kernel 4.3.3 - 'overlayfs' Local Privilege Escalation (2)
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro - node.js HTTP Server Listening on localhost Can Execute Commands
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url para
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash BlurFilter Processing - Out-of-Bounds Memset
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Konica Minolta FTP Utility 1.00 - CWD Command Overflow (SEH)
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Use-After-Free When Setting Stage
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash (Multiple Scripts) - Use-After-Free When Rendering Displays (1)
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.