Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8.970Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.476 exploits
Exploit-DB✓ VexDay Proof
Apple macOS 10.13.1 (High Sierra) - 'Blank Root' Local Privilege Escalation (Metasploit)
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RISCO
abrir ↗Exploit-DB
Linux Kernel - 'The Huge Dirty Cow' Overwriting The Huge Zero Page (1)
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
QEMU - NBD Server Long Export Name Stack Buffer Overflow
A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client
46RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP iMC Plat 7.2 - Remote Code Execution (2)
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP iMC Plat 7.2 - Remote Code Execution
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.13.1 (High Sierra) - 'Blank Root' Local Privilege Escalation
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RISCO
abrir ↗Exploit-DB
WordPress Plugin WooCommerce 2.0/3.0 - Directory Traversal
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/wooco
46RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - 'GlobOpt::OptTagChecks' Must Consider IsLoopPrePass Properly
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, versio
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - 'BailOutOnTaggedValue' Bailouts Type Confusion
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows a
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Incorrect Function Declaration Scope
ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the
35RISCO
abrir ↗Exploit-DB
Diving Log 6.0 - XML External Entity Injection
XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled d
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Exim 4.89 - 'BDAT' Denial of Service
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - 'Inline::InlineCallApplyTarget_Shared' does not Return the return Instruction
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, versio
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ZTE ZXDSL 831CII - Improper Access Restrictions
connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to mo
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel - 'mincore()' Uninitialized Kernel Heap Page Disclosure
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RISCO
abrir ↗Exploit-DB
Linux Kernel (Ubuntu 17.04) - 'XFRM' Local Privilege Escalation
The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gai
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::DocumentLoader::frameLoader' Use-After-Free
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::RenderObject::previousSibling' Use-After-Free
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISCO
abrir ↗Exploit-DB
KMPlayer 4.2.2.4 - Denial of Service
KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::PositionIterator::decrement' Use-After-Free
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::RenderText::localCaretRect' Out-of-Bounds Read
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::SimpleLineLayout::RunResolver::runForPoint' Out-of-Bounds Read
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::FormSubmission::create' Use-After-Free
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::InputType::element' Use-After-Free (2)
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISCO
abrir ↗Exploit-DB
Winamp Pro 5.66.Build.3512 - Denial of Service
Winamp Pro 5.66 Build 3512 allows remote attackers to cause a denial of service via a crafted WAV, WMV, AU, ASF, AIFF, o
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::TreeScope::documentScope' Use-After-Free
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::SVGPatternElement::collectPatternAttributes' Out-of-Bounds Read
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::Style::TreeResolver::styleForElement' Use-After-Free
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::AXObjectCache::performDeferredCacheUpdate' Use-After-Free
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 - 'nt!NtQueryDirectoryFile (luafv!LuafvCopyDirectoryEntry)' Pool Memory Disclosure
Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2,
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.