Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8.829Nuclei 4.357Metasploit 3.489✓ só verificadosrecentespopularesrisco
24.695 exploits
Exploit-DB✓ VexDay Proof
Oracle JDeveloper 11.1.x/12.x - Directory Traversal
Vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware (subcomponent: Deployment). Supported versi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
macOS 10.13 (17A365) - Kernel Memory Disclosure due to Lack of Bounds Checking in 'AppleIntelCapriController::getDisplayPipeCapability'
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graph
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - Incorrect Scope Handling
Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due t
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'AsmJSByteCodeGenerator::EmitCall' Out-of-Bounds Read
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtai
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Incorrect Bounds Calculation
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Stack-to-Heap Copy
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - Deferred Parsing Makes Wrong Scopes (2)
Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due t
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Out-of-Bounds Write
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'JavascriptGeneratorFunction::GetPropertyBuiltIns' Type Confusion
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain t
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
glibc < 2.26 - 'getcwd()' Local Privilege Escalation
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ILIAS < 5.2.4 - Cross-Site Scripting
ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle E-Business Suite 12.1.3/12.2.x - Open Redirect
Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (li
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'AppendLeftOverItemsFromEndSegment' Out-of-Bounds Read
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain info
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpCollab 2.5.1 - File Upload (Metasploit)
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows SMB Server (v1/v2) - Mount Point Arbitrary Device Open Privilege Escalation
The Microsoft Server Message Block (SMB) Server in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - NTFS Owner/Mandatory Label Privilege Bypass
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Android - Hardware Service Manager Arbitrary Service Replacement due to getpidcon
In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - NtImpersonateAnonymousToken AC to Non-AC Privilege Escalation
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - NtImpersonateAnonymousToken LPAC to Non-LPAC Privilege Escalation
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
macOS - 'process_policy' Stack Leak Through Uninitialized Field
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Transmission - RPC DNS Rebinding
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access con
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Easydiscuss < 4.0.21 - Cross-Site Scripting
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - 'Lowerer::LowerSetConcatStrMultiItem' Missing Integer Overflow Check
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HPE iMC - dbman 'RestoreDBase' Remote Command Execution (Metasploit)
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HPE iMC - dbman 'RestartDB' Remote Command Execution (Metasploit)
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'asm.js' Out-of-Bounds Read
ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Op_MaxInAnArray and Op_MinInAnArray can Explicitly call User-Defined JavaScript Functions
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execut
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Escape Analysis Bug
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQuerySystemInformation (information class 138_ QueryMemoryTopologyInformation)' Kernel Pool Memory Disclosure
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - BackwardPass::RemoveEmptyLoopAfterMemOp Does not Insert Branches
ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i
35RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.