Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8.860Nuclei 4.361Metasploit 3.491✓ só verificadosrecentespopularesrisco
79.230 exploits
GitHub PoC★ 4
Interactive-Like Command-Line Console for CVE-2019-16759
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - win32k.sys TTF Font Processing Pool Corruption in win32k!ulClearTypeFilter
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in CI!CipFixImageType While Parsing Malformed PE File
An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - NULL Pointer Dereference in nt!MiOffsetToProtos While Parsing Malformed PE File
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in nt!MiParseImageLoadConfig While Parsing Malformed PE File
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
23RISCO
abrir ↗Exploit-DB
SMA Solar Technology AG Sunny WebBox device - 1.6 - Cross-Site Request Forgery
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action
41RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in nt!MiRelocateImage While Parsing Malformed PE File
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in CI!HashKComputeFirstPageHash While Parsing Malformed PE File
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RISCO
abrir ↗GitHub PoC★ 1
CVE-2018-7600 and CVE-2018-7602 Mass Exploiter
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗VulnCheck XDB
initial-access
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir ↗VulnCheck XDB
initial-access
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗GitHub PoC★ 10
PoC materials to exploit CVE-2018-6789
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir ↗VulnCheck XDB
initial-access
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir ↗GitHub PoC★ 16
Critical Remote Code Execution Vulnerability (CVE-2018-11776) Found in Apache Struts.
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir ↗Exploit-DB
TP-Link TL-WR1043ND 2 - Authentication Bypass
An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packe
28RISCO
abrir ↗GitHub PoC★ 2
The study of vulnerability CVE-2017-3066. Java deserialization
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RISCO
abrir ↗VulnCheck XDB
initial-access
Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.
35RISCO
abrir ↗VulnCheck XDB
initial-access
From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the su
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
XNU - Remote Double-Free via Data Race in IPComp Input Path
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15, tvOS
23RISCO
abrir ↗GitHub PoC★ 2
KRAMER VIAware 2.5.0719.1034 - Remote Code Execution
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
28RISCO
abrir ↗GitHub PoC
Investigation of CVE-2018-11776 vulnerability that allows attackers to remotely execute code and gain control over Apache Struts-based applications.
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir ↗Exploit-DB
IBM Bigfix Platform 9.5.9.62 - Arbitrary File Upload
IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root pr
53RISCO
abrir ↗Exploit-DB
Subrion 4.2.1 - 'Email' Persistant Cross-Site Scripting
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" i
23RISCO
abrir ↗Exploit-DB
vBulletin 5.0 < 5.5.4 - 'updateAvatar' Authenticated Remote Code Execution
vBulletin through 5.5.4 mishandles custom avatars.
28RISCO
abrir ↗Exploit-DB
CheckPoint Endpoint Security Client/ZoneAlarm 15.4.062.17802 - Privilege Escalation
A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security clien
23RISCO
abrir ↗GitHub PoC★ 4
infiniteLoopers/CVE-2019-11932
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir ↗GitHub PoC★ 4
Double-Free BUG in WhatsApp exploit poc.
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir ↗GitHub PoC★ 79
timwr/CVE-2019-2215
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Android - Binder Driver Use-After-Free
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir ↗VulnCheck XDB
local
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.