Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8.970Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.476 exploits
Exploit-DB
Sound eXchange (SoX) 14.4.2 - Multiple Vulnerabilities
The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (div
23RISCO
abrir ↗Exploit-DB
libvorbis 1.3.5 - Multiple Vulnerabilities
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial
23RISCO
abrir ↗Exploit-DB
Sound eXchange (SoX) 14.4.2 - Multiple Vulnerabilities
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (d
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jenkins < 1.650 - Java Deserialization
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex
60RISCO
abrir ↗Exploit-DB
McAfee Security Scan Plus - Remote Command Execution
A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthor
38RISCO
abrir ↗Exploit-DB
SoundTouch 1.9.2 - Multiple Vulnerabilities
The TDStretch::acceptNewOverlapLength function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote atta
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to exec
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthor
43RISCO
abrir ↗Exploit-DB
SoundTouch 1.9.2 - Multiple Vulnerabilities
The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attack
23RISCO
abrir ↗Exploit-DB
LAME 3.99.5 - Multiple Vulnerabilities
The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of ser
23RISCO
abrir ↗Exploit-DB
SoundTouch 1.9.2 - Multiple Vulnerabilities
The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to
23RISCO
abrir ↗Exploit-DB
libjpeg-turbo 1.5.1 - Denial of Service
The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GNU libiberty - Buffer Overflow
Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB
Microsoft Windows - '.LNK' Shortcut File Code Execution (Metasploit)
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AudioCoder 0.8.46 - Local Buffer Overflow (SEH)
Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit JSC - 'JSArray::appendMemcpy' Uninitialized Memory Copy
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit JSC - 'JSObject::putInlineSlow' / 'JSValue::putToPrimitive' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit JSC - 'DFG::ByteCodeParser::flush(InlineStackEntry* inlineStackEntry)' Incorrect Scope Register Handling
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit JSC - 'ArgumentsEliminationPhase::transform' Incorrect LoadVarargs Handling
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::AccessibilityNodeObject::textUnderElement' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::RenderObject' with Accessibility Enabled Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::getCachedWrapper' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB
vBulletin 5.1.2 < 5.1.9 - Unserialize Code Execution (Metasploit)
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::RenderSearchField::addSearchResult' Heap Buffer Overflow
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Exploit-DB
Nitro Pro PDF - Multiple Vulnerabilities
Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX
23RISCO
abrir ↗Exploit-DB
ManageEngine Desktop Central 10 Build 100087 - Remote Code Execution (Metasploit)
Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors invo
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::Node::nextSibling' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.