Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8.843Nuclei 4.358Metasploit 3.489✓ só verificadosrecentespopularesrisco
19.066 exploits
Exploit-DB✓ VexDay Proof
Microsoft Office PowerPoint 2010 - Invalid Pointer Reference
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 20
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec RAR Decomposer Engine (Multiple Products) - Out-of-Bounds Read / Out-of-Bounds Write
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP);
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VMware Workstation - 'vprintproxy.exe' JPEG2000 Images Multiple Memory Corruptions
tpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, whe
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VMware Workstation - 'vprintproxy.exe' TrueType NAME Tables Heap Buffer Overflow (PoC)
VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado Thin
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NetBSD - 'mail.local(8)' Local Privilege Escalation (Metasploit)
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cherry Music 0.35.1 - Arbitrary File Disclosure
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary file
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Method Calls Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Transform.colorTranform Getter Infomation Leak
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google Android - libutils UTF16 to UTF8 Conversion Heap Buffer Overflow
LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe ColdFusion < 11 Update 10 - XML External Entity Injection
The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attack
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Use-After-Free When Returning Rectangle
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Stage.align Setter Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Selection.setFocus Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - BitmapData.copyPixels Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - MovieClip Transform Getter Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Eye of Gnome 3.10.2 - GMarkup Out of Bounds Write
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib befor
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Core 4.5.3 - Directory Traversal / Denial of Service
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ocomon 2.0 - SQL Injection
SQL injection vulnerability in OcoMon 1.21, and possibly other versions, when magic_quotes_gpc is disabled, allows remot
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Core 4.5.3 - Directory Traversal / Denial of Service
Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPre
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - GDI+ EMR_EXTTEXTOUTA / EMR_POLYTEXTOUTA Heap Buffer Overflow (MS16-097)
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - GDI+ ValidateBitmapInfo Invalid Pointer Arithmetic Out-of-Bounds Reads (MS16-097)
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - GDI+ DecodeCompressedRLEBitmap Invalid Pointer Arithmetic Out-of-Bounds Write (MS16-097)
The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1;
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WSO2 Identity Server 5.1.0 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote at
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - MSHTML!CMultiReadStreamLifetimeManager::ReleaseThreadStateInternal Read AV
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet E
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Word 2013/2016 - sprmSdyaTop Denial of Service (MS16-099)
Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a craf
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WSO2 Carbon 4.4.5 - Denial of Service / Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authenticatio
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WSO2 Carbon 4.4.5 - Local File Inclusion
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated admini
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WSO2 Identity Server 5.1.0 - Multiple Vulnerabilities
XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WSO2 Carbon 4.4.5 - Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SAP SAPCAR - Multiple Vulnerabilities
SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard l
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.