Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8.843Nuclei 4.358Metasploit 3.489✓ só verificadosrecentespopularesrisco
19.066 exploits
Exploit-DB✓ VexDay Proof
Microsoft Edge Scripting Engine - Memory Corruption (MS16-129)
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute a
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NTP 4.2.8p8 - Denial of Service
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a craf
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Nagios 4.2.2 - Local Privilege Escalation
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary fil
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Palo Alto Networks PanOS - 'root_trace' Local Privilege Escalation
Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Palo Alto Networks PanOS - 'root_reboot' Local Privilege Escalation
Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - 'Array.filter' Information Leak
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - 'Array.reverse' Overflow
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute a
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - 'FillFromPrototypes' Type Confusion
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Palo Alto Networks PanOS - appweb3 Stack Buffer Overflow
Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x b
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - 'Array.splice' Heap Overflow
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - 'eval' Type Confusion
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Registry Hive Loading 'nt!RtlEqualSid' Out-of-Bounds Read (MS16-138)
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandles permissi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - VHDMP Arbitrary Physical Disk Cloning Privilege Escalation (MS16-138)
Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 151
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - VHDMP ZwDeleteFile Arbitrary File Deletion Privilege Escalation (MS16-138)
Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - VHDMP Arbitrary File Creation Privilege Escalation (MS16-138)
Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 11 - MSHTML CMapElement::Notify Use-After-Free (MS15-009)
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 4.4 (Ubuntu 16.04) - 'BPF' Local Privilege Escalation (Metasploit)
The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly mai
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft WININET.dll - 'CHttpHeaderParser::ParseStatusLine' Out-of-Bounds Read (MS16-104/MS16-105)
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted w
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 11/10/9 - MSHTML 'PROPERTYDESC::HandleStyleComponentProperty' Out-of-Bounds Read (MS16-104)
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - LSASS SMB NTLM Exchange Null-Pointer Dereference (MS16-137)
Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, W
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Connect 9.5.7 - Cross-Site Scripting
Adobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulne
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 8/9/10/11 / IIS / CScript.exe/WScript.exe VBScript - CRegExp..Execute Use of Uninitialized Memory (MS14-080/MS14-084)
vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allo
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM AIX 6.1/7.1/7.2.0.2 - 'lsmcode' Local Privilege Escalation
IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privile
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM AIX 5.3/6.1/7.1/7.2 - 'lquerylv' Local Privilege Escalation
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to ob
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bassmaster 1.5.1 - Batch Arbitrary JavaScript Injection Remote Code Execution (Metasploit)
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel (Ubuntu / Fedora / RedHat) - 'Overlayfs' Local Privilege Escalation (Metasploit)
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Alienvault OSSIM/USM 5.3.1 - Persistent Cross-Site Scripting
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Alienvault OSSIM/USM 5.3.1 - SQL Injection
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbit
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Alienvault OSSIM/USM 5.3.1 - PHP Object Injection
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vuln
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel (Ubuntu / Fedora / RedHat) - 'Overlayfs' Local Privilege Escalation (Metasploit)
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.