Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8.883Nuclei 4.361Metasploit 3.493✓ só verificadosrecentespopularesrisco
79.305 exploits
GitHub PoC★ 5
Exploiting CVE-2016-10277 for Secure Boot and Device Locking bypass
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute
23RISCO
abrir ↗GitHub PoC
cve-2018-3811
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthentica
35RISCO
abrir ↗GitHub PoC
cve-2018-3810
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RISCO
abrir ↗Exploit-DB
SureMDM < 2018-11 Patch - Local / Remote File Inclusion
An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
macOS XNU - Copy-on-Write Behaviour Bypass via Partial-Page Truncation of File
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Moja
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Kernel Heap Overflow in PF_KEY due to Lack of Bounds Checking when Retrieving Statistics
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3,
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Arbitrary mach Port Name Deallocation in XPC Services due to Invalid mach Message Parsing in _xpc_serializer_unpack
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 XNU - 'vm_map_copy' Optimization which Requires Atomicity isn't Atomic
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Moja
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Sandbox Escapes due to Type Confusions and Memory Safety Issues in iohideventsystem
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.1
23RISCO
abrir ↗GitHub PoC★ 16
iOS 12.0 -> 12.1.2 Incomplete Osiris Jailbreak with CVE-2019-6225 by GeoSn0w (FCE365)
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
28RISCO
abrir ↗VulnCheck XDB
initial-access
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iOS/macOS 10.13.6 - 'if_ports_used_update_wakeuuid()' 16-byte Uninitialized Kernel Stack Disclosure
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input
23RISCO
abrir ↗GitHub PoC★ 1
NSE script to scan for Cisco routers vulnerable to CVE-2019-1653
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir ↗GitHub PoC★ 1
Python 3 implementation of an existing CVE-2011-3556 proof of concept (PoC).
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RISCO
abrir ↗GitHub PoC
Exploit script for Crossfire 1.9.0
Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrar
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Firepower Management Center 6.2.2.2 / 6.2.3 - Cross-Site Scripting
Cisco Firepower Management Center Cross-Site Scripting Vulnerability
33RISCO
abrir ↗Exploit-DB
Rundeck Community Edition < 3.0.13 - Persistent Cross-Site Scripting
An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascrip
23RISCO
abrir ↗Exploit-DB
CloudMe Sync 1.11.2 Buffer Overflow - WoW64 (DEP Bypass)
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RISCO
abrir ↗Exploit-DB
AirTies Air5341 Modem 1.0.0.12 - Cross-Site Request Forgery
AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.
28RISCO
abrir ↗GitHub PoC★ 2
DVR username password recovery.
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir ↗Exploit-DB
MyBB IP History Logs Plugin 1.0.2 - Cross-Site Scripting
An issue was discovered in the User IP History Logs (aka IP_History_Logs) plugin 1.0.2 for MyBB. There is XSS via the ad
23RISCO
abrir ↗VulnCheck XDB
initial-access
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir ↗Exploit-DB
Sricam gSOAP 2.8 - Denial of Service
Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server
28RISCO
abrir ↗Exploit-DB
LogonBox Limited / Hypersocket Nervepoint Access Manager - (Unauthenticated) Insecure Direct Object Reference
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 thr
23RISCO
abrir ↗Exploit-DB
Cisco RV300 / RV320 - Information Disclosure
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-in
35RISCO
abrir ↗Metasploit600
Schneider Electric Pelco Endura NET55XX Encoder
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 wh
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 - Command Injection
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iOS/macOS - 'task_swap_mach_voucher()' Use-After-Free
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
28RISCO
abrir ↗Exploit-DB
Lua 5.3.5 - 'debug.upvaluejoin' Use After Free
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attack
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.