Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
19.066 exploits
Exploit-DB✓ VexDay Proof
piSignage 2.6.4 - Directory Traversal
The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user)
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
nostromo 1.9.6 - Remote Code Execution
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft UPnP - Local Privilege Elevation (Metasploit)
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft W
91RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD - Dynamic Loader chpass Privilege Escalation (Metasploit)
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft UPnP - Local Privilege Elevation (Metasploit)
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD-SA-19:02.fd - Privilege Escalation
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Django < 3.0 < 2.2 < 1.11 - Account Hijack
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenMRS - Java Deserialization RCE (Metasploit)
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD 6.x - Dynamic Loader Privilege Escalation
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux 5.3 - Privilege Escalation via io_uring Offload of sendmsg() onto Kernel Thread with Kernel Creds
In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabili
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC - Heap-Based Memory Corruption due to Malformed TTF Font
Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Deep Security Agent 11 - Arbitrary File Overwrite
Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, w
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Internet Explorer - Use-After-Free in JScript Arguments During toJSON Callback
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FusionPBX - Operator Panel exec.php Command Execution (Metasploit)
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerabili
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pulse Secure VPN - Arbitrary Command Execution (Metasploit)
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
Reference count underflow in shiftfs
41RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
Mishandling of file-system uid/gid with namespaces in shiftfs
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bludit - Directory Traversal Image File Upload (Metasploit)
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ubuntu 19.10 - ubuntu-aufs-modified mmap_region() Breaks Refcounting in overlayfs/shiftfs Error Path
Reference counting error in overlayfs/shiftfs error path when used in conjuction with aufs
41RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Xorg X11 Server - Local Privilege Escalation (Metasploit)
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
Type confusion in shiftfs
41RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
An out-of-bounds read was addressed with improved input validation.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed OTF Font (CFF Table)
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Android Janus - APK Signature Bypass (Metasploit)
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
rConfig - install Command Execution (Metasploit)
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
JavaScriptCore - Type Confusion During Bailout when Reconstructing Arguments Objects
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPad
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.