Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8.182Nuclei 4.217Metasploit 3.462✓ só verificadosrecentespopularesrisco
22.786 exploits
Exploit-DB
OpenSSH 6.8 < 6.9 - 'PTY' Local Privilege Escalation
sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial
23RISCO
abrir ↗Exploit-DB
Apple macOS 10.12.1 / iOS Kernel - 'IOService::matchPassive' Use-After-Free
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth"
23RISCO
abrir ↗Exploit-DB
OpenSSL 1.1.0 - Remote Client Denial of Service
Bad (EC)DHE parameters cause a client crash
35RISCO
abrir ↗Exploit-DB
Apple macOS 10.12.1 / iOS 10.2 - Kernel Userspace Pointer Memory Corruption
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RISCO
abrir ↗Exploit-DB
Systemd 228 (SUSE 12 SP2 / Ubuntu Touch 15.04) - Local Privilege Escalation
A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd tim
23RISCO
abrir ↗Exploit-DB
Geutebrueck GCore 1.3.8.42/1.4.2.37 - Remote Code Execution (Metasploit)
Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote at
43RISCO
abrir ↗Exploit-DB
Mozilla Firefox < 50.0.2 - 'nsSMILTimeContainer::NotifyTimeChange()' Remote Code Execution (Metasploit)
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RISCO
abrir ↗Exploit-DB
Oracle OpenJDK Runtime Environment 1.8.0_112-b15 - Java Serialization Denial Of Service
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versi
35RISCO
abrir ↗Exploit-DB
NTOPNG 2.4 Web Interface - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authenticati
23RISCO
abrir ↗Exploit-DB
PageKit 1.0.10 - Password Reset
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the reg
23RISCO
abrir ↗Exploit-DB
Joomla! < 2.5.2 - Admin Creation
Joomla! before 2.5.3 allows Admin Account Creation.
23RISCO
abrir ↗Exploit-DB
Joomla! < 3.6.4 - Admin Takeover
An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of
28RISCO
abrir ↗Exploit-DB
Apple macOS Sierra 10.12.1 - 'physmem' Local Privilege Escalation
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth"
23RISCO
abrir ↗Exploit-DB
Apple macOS Sierra 10.12.1 - 'physmem' Local Privilege Escalation
IOHIDFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a d
23RISCO
abrir ↗Exploit-DB
Cisco Firepower Management Console 6.0 - Post Authentication UserAdd (Metasploit)
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users
60RISCO
abrir ↗Exploit-DB
Mozilla Firefox < 50.1.0 - Use-After-Free
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption.
28RISCO
abrir ↗Exploit-DB
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow
23RISCO
abrir ↗Exploit-DB
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate d
23RISCO
abrir ↗Exploit-DB
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/repor
23RISCO
abrir ↗Exploit-DB
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (1)
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurre
28RISCO
abrir ↗Exploit-DB
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (2)
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurre
28RISCO
abrir ↗Exploit-DB
Apple OS X Yosemite - 'flow_divert-heap-overflow' Kernel Panic
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISCO
abrir ↗Exploit-DB
Ansible 2.1.4/2.2.1 - Command Execution
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent fr
38RISCO
abrir ↗Exploit-DB
Microsoft Windows Kernel - 'win32k.sys NtSetWindowLongPtr' Local Privilege Escalation (MS16-135) (2)
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISCO
abrir ↗Exploit-DB
Splunk 6.1.1 - 'Referer' Header Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML
23RISCO
abrir ↗Exploit-DB
Microsoft Edge (Windows 10) - 'chakra.dll' Information Leak / Type Confusion Remote Code Execution
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISCO
abrir ↗Exploit-DB
Microsoft Edge (Windows 10) - 'chakra.dll' Information Leak / Type Confusion Remote Code Execution
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISCO
abrir ↗Exploit-DB
Atlassian Confluence < 5.10.6 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitra
23RISCO
abrir ↗Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.
35RISCO
abrir ↗Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail comman
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.