Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8.182Nuclei 4.217Metasploit 3.462✓ só verificadosrecentespopularesrisco
22.786 exploits
Exploit-DB
dotCMS 3.6.1 - Blind Boolean SQL Injection
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessib
23RISCO
abrir ↗Exploit-DB
NVIDIA Driver 375.70 - DxgkDdiEscape 0x100008b Out-of-Bounds Read/Write
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handle
23RISCO
abrir ↗Exploit-DB
OpenText Documentum D2 - Remote Code Execution
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a craf
28RISCO
abrir ↗Exploit-DB
Geutebruck 5.02024 G-Cam/EFD-2250 - 'testaction.cgi' Remote Command Execution (Metasploit)
An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD
28RISCO
abrir ↗Exploit-DB
Microsoft Windows - 'gdi32.dll' EMR_SETDIBITSTODEVICE Heap Out-of-Bounds Reads / Memory Disclosure
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
45RISCO
abrir ↗Exploit-DB
NVIDIA Driver 375.70 - Buffer Overflow in Command Buffer Submission
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implem
23RISCO
abrir ↗Exploit-DB
Geutebruck 5.02024 G-Cam/EFD-2250 - 'testaction.cgi' Remote Command Execution (Metasploit)
An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authenticatio
35RISCO
abrir ↗Exploit-DB
GOM Player 2.3.10.5266 - '.fpx' Denial of Service
GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspeci
23RISCO
abrir ↗Exploit-DB
Cisco ASA - WebVPN CIFS Handling Buffer Overflow
A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software,
28RISCO
abrir ↗Exploit-DB
Google Android - Inter-process munmap in android.util.MemoryIntArray
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RISCO
abrir ↗Exploit-DB
Google Android - android.util.MemoryIntArray Ashmem Race Conditions
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RISCO
abrir ↗Exploit-DB
F5 BIG-IP 11.6 SSL Virtual Server - 'Ticketbleed' Memory Disclosure
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RISCO
abrir ↗Exploit-DB
Microsoft Edge - TypedArray.sort Use-After-Free (MS16-145)
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (m
45RISCO
abrir ↗Exploit-DB
ntfs-3g - Unsanitized modprobe Environment Privilege Escalation
ntfs-3g: Modprobe influence vulnerability via environment variables
56RISCO
abrir ↗Exploit-DB
Linux Kernel 3.10.0 (CentOS 7) - Denial of Service
The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fa
28RISCO
abrir ↗Exploit-DB
HP Smart Storage Administrator 2.30.6.0 - Remote Command Injection (Metasploit)
A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found.
28RISCO
abrir ↗Exploit-DB
F5 BIG-IP SSL Virtual Server - 'Ticketbleed' Memory Disclosure
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RISCO
abrir ↗Exploit-DB
Node.JS - 'node-serialize' Remote Code Execution
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISCO
abrir ↗Exploit-DB
OpenBSD HTTPd < 6.0 - Memory Exhaustion Denial of Service
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for
28RISCO
abrir ↗Exploit-DB
CUPS < 2.0.3 - Remote Command Execution
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-va
28RISCO
abrir ↗Exploit-DB
ntfs-3g (Debian 9) - Local Privilege Escalation
ntfs-3g: Modprobe influence vulnerability via environment variables
56RISCO
abrir ↗Exploit-DB
Apple WebKit - Type Confusion in RenderBox with Accessibility Enabled
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISCO
abrir ↗Exploit-DB
Apple WebKit - 'HTMLFormElement::reset()' Use-After Free
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISCO
abrir ↗Exploit-DB
Apple WebKit - 'HTMLKeygenElement' Type Confusion
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISCO
abrir ↗Exploit-DB
AlienVault OSSIM/USM < 5.3.1 - Remote Code Execution (Metasploit)
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vuln
23RISCO
abrir ↗Exploit-DB
PHP PEAR 1.10.1 - Arbitrary File Download
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenam
28RISCO
abrir ↗Exploit-DB
Netgear Routers - Password Disclosure
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R
100RISCO
abrir ↗Exploit-DB
Oracle VM VirtualBox < 5.0.32 / < 5.1.14 - Local Privilege Escalation
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions tha
23RISCO
abrir ↗Exploit-DB
Radisys MRF - Command Injection
An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was dis
23RISCO
abrir ↗Exploit-DB
Apple macOS 10.12.1 / iOS Kernel - 'IOService::matchPassive' Use-After-Free
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth"
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.