Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.475 exploits
Exploit-DB✓ VexDay Proof
WordPress Plugin Site Editor 1.1.1 - Local File Inclusion
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISCO
abrir ↗Exploit-DB
Android Bluetooth - BNEP BNEP_SETUP_CONNECTION_REQUEST_MSG Out-of-Bounds Read
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RISCO
abrir ↗Exploit-DB
Android Bluetooth - BNEP BNEP_SETUP_CONNECTION_REQUEST_MSG Out-of-Bounds Read
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RISCO
abrir ↗Exploit-DB
Android Bluetooth - BNEP BNEP_SETUP_CONNECTION_REQUEST_MSG Out-of-Bounds Read
In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. T
23RISCO
abrir ↗Exploit-DB
Android Bluetooth - BNEP BNEP_SETUP_CONNECTION_REQUEST_MSG Out-of-Bounds Read
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. Th
23RISCO
abrir ↗Exploit-DB
Android Bluetooth - BNEP bnep_data_ind() Remote Heap Disclosure
In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. T
23RISCO
abrir ↗Exploit-DB
Android Bluetooth - BNEP bnep_data_ind() Remote Heap Disclosure
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Dell EMC NetWorker - Denial of Service
In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the '
28RISCO
abrir ↗Exploit-DB
Android Bluetooth - BNEP bnep_data_ind() Remote Heap Disclosure
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. Th
23RISCO
abrir ↗Exploit-DB
Android Bluetooth - BNEP bnep_data_ind() Remote Heap Disclosure
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RISCO
abrir ↗Exploit-DB
Linux Kernel < 4.15.4 - 'show_floppy' KASLR Address Leak
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi
23RISCO
abrir ↗Exploit-DB
Intelbras Telefone IP TIP200 LITE - Local File Disclosure
Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via t
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Desktop Bridge Virtual Registry NtLoadKey Arbitrary File Read/Write Privilege Escalation
The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an el
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Desktop Bridge VFS Privilege Escalation
The Desktop Bridge Virtual File System (VFS) in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server,
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'NtQueryVirtualMemory(MemoryMappedFilenameInformation)' 64-bit Pool Memory Disclosure
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Internet Explorer - 'RegExp.lastMatch' Memory Disclosure
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Desktop Bridge Virtual Registry Arbitrary File Read/Write Privilege Escalation
The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an el
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'nt!NtWaitForDebugEvent' 64-bit Stack Memory Disclosure
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RISCO
abrir ↗Exploit-DB
Coship RT3052 Wireless Router - Persistent Cross-Site Scripting
Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'NtQueryInformationThread(ThreadBasicInformation)' 64-bit Stack Memory Disclosure
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RISCO
abrir ↗Exploit-DB
Vehicle Sales Management System - Multiple Vulnerabilities
Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/veh
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'nt!KiDispatchException' 64-bit Stack Memory Disclosure
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google Software Updater macOS - Unsafe use of Distributed Objects Privilege Escalation
Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local
23RISCO
abrir ↗Exploit-DB
Cisco node-jos < 0.11.0 - Re-sign Tokens
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Firefox 46.0.1 - ASM.JS JIT-Spray Remote Code Execution
Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to ex
28RISCO
abrir ↗Exploit-DB
Unitrends UEB 10.0 - Root Remote Code Execution
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, w
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Firefox 44.0.2 - ASM.JS JIT-Spray Remote Code Execution
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox
35RISCO
abrir ↗Exploit-DB
Linux Kernel < 4.4.0-116 (Ubuntu 16.04.4) - Local Privilege Escalation
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Firefox 44.0.2 - ASM.JS JIT-Spray Remote Code Execution
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. T
35RISCO
abrir ↗Exploit-DB
Unitrends UEB 10.0 - Root Remote Code Execution
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL i
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.