Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8.156Nuclei 4.201Metasploit 3.462✓ só verificadosrecentespopularesrisco
22.786 exploits
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev4
23RISCO
abrir ↗Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.
23RISCO
abrir ↗Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RISCO
abrir ↗Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and
23RISCO
abrir ↗Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RISCO
abrir ↗Exploit-DB
Canon PrintMe EFI - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitra
23RISCO
abrir ↗Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Pie Register < 3.0.9 - Blind SQL Injection
SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute ar
23RISCO
abrir ↗Exploit-DB
Schools Alert Management Script - Arbitrary File Deletion
Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.p
28RISCO
abrir ↗Exploit-DB
Schools Alert Management Script - SQL Injection
Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.ph
23RISCO
abrir ↗Exploit-DB
Schools Alert Management Script - 'get_sec.php' SQL Injection
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
23RISCO
abrir ↗Exploit-DB
WebKitGTK+ < 2.21.3 - 'WebKitFaviconDatabase' Denial of Service (Metasploit)
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon
50RISCO
abrir ↗Exploit-DB
Schools Alert Management Script - Arbitrary File Read
Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absol
50RISCO
abrir ↗Exploit-DB
WebKit - WebAssembly Compilation Info Leak
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
28RISCO
abrir ↗Exploit-DB
Splunk < 7.0.1 - Information Disclosure
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json
60RISCO
abrir ↗Exploit-DB
TrendMicro OfficeScan XG 11.0 - Change Prevention Bypass
A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or
23RISCO
abrir ↗Exploit-DB
Google Chrome - Integer Overflow when Processing WebAssembly Locals
An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker t
23RISCO
abrir ↗Exploit-DB
WebRTC - VP9 Frame Processing Out-of-Bounds Memory Access
Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to pot
23RISCO
abrir ↗Exploit-DB
XiongMai uc-httpd 1.0.0 - Buffer Overflow
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE
50RISCO
abrir ↗Exploit-DB
WebKit - Use-After-Free when Resuming Generator
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
23RISCO
abrir ↗Exploit-DB
WebRTC - VP9 Missing Frame Processing Out-of-Bounds Memory Access
Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially per
23RISCO
abrir ↗Exploit-DB
Monstra CMS < 3.0.4 - Cross-Site Scripting (1)
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI
23RISCO
abrir ↗Exploit-DB
Apple macOS/iOS Kernel - Heap Overflow Due to Lack of Lower Size Check in getvolattrlist
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
28RISCO
abrir ↗Exploit-DB
Apple macOS Kernel - Use-After-Free Due to Lack of Locking in nvidia GeForce Driver
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "NVIDIA Grap
23RISCO
abrir ↗Exploit-DB
XNU Kernel - Heap Overflow Due to Bad Bounds Checking in MPTCP
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RISCO
abrir ↗Exploit-DB
PHP 7.2.2 - 'php_stream_url_wrap_http_ex' Buffer Overflow
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer
45RISCO
abrir ↗Exploit-DB
WebKitGTK+ < 2.21.3 - Crash (PoC)
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon
50RISCO
abrir ↗Exploit-DB
WebKit - not_number defineProperties UAF (Metasploit)
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISCO
abrir ↗Exploit-DB
Jenkins Mailer Plugin < 1.20 - Cross-Site Request Forgery (Send Email)
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated
23RISCO
abrir ↗Exploit-DB
WebKit - not_number defineProperties UAF (Metasploit)
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.