Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8.970Nuclei 4.394Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.476 exploits
Exploit-DB
Microsoft Windows Kernel - 'win32k.sys NtSetWindowLongPtr' Local Privilege Escalation (MS16-135) (2)
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISCO
abrir ↗Exploit-DB
Splunk 6.1.1 - 'Referer' Header Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML
23RISCO
abrir ↗Exploit-DB
Microsoft Edge (Windows 10) - 'chakra.dll' Information Leak / Type Confusion Remote Code Execution
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISCO
abrir ↗Exploit-DB
Microsoft Edge (Windows 10) - 'chakra.dll' Information Leak / Type Confusion Remote Code Execution
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISCO
abrir ↗Exploit-DB
Firejail < 0.9.44.4 / < 0.9.38.8 LTS - Local Sandbox Escape
Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Atlassian Confluence < 5.10.6 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitra
23RISCO
abrir ↗Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail comman
60RISCO
abrir ↗Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass
35RISCO
abrir ↗Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.
35RISCO
abrir ↗Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir ↗Exploit-DB
Zend Framework / zend-mail < 2.4.11 - Remote Code Execution
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.
35RISCO
abrir ↗Exploit-DB
PHPMailer < 5.2.18 - Remote Code Execution
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google Android - get_user/put_user (Metasploit)
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RISCO
abrir ↗Exploit-DB
SapLPD 7.40 - Denial of Service
SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long
23RISCO
abrir ↗Exploit-DB
SwiftMailer < 5.4.5-DEV - Remote Code Execution
The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass
35RISCO
abrir ↗Exploit-DB
PHPMailer < 5.2.20 - Remote Code Execution
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail comman
60RISCO
abrir ↗Exploit-DB
PHPMailer < 5.2.20 - Remote Code Execution
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHPMailer < 5.2.18 - Remote Code Execution
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Wampserver 3.0.6 - Insecure File Permissions Privilege Escalation
WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYS
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Shutter 0.93.1 - Code Execution
/usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a cra
23RISCO
abrir ↗Exploit-DB
Sonicwall 8.1.0.2-14sv - 'extensionsettings.cgi' Remote Command Injection (Metasploit)
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerabili
28RISCO
abrir ↗Exploit-DB
PHPMailer < 5.2.18 - Remote Code Execution
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir ↗Exploit-DB
Sonicwall 8.1.0.2-14sv - 'viewcert.cgi' Remote Command Injection (Metasploit)
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerabili
23RISCO
abrir ↗Exploit-DB
Apache mod_session_crypto - Padding Oracle
In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured c
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSH < 7.4 - agent Protocol Arbitrary Library Loading
Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute
53RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSH < 7.4 - 'UsePrivilegeSeparation Disabled' Forwarded Unix Domain Sockets Privilege Escalation
sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which
41RISCO
abrir ↗Exploit-DB
Freepbx < 2.11.1.5 - Remote Code Execution
htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9,
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.12 - Double vm_deallocate in Userspace MIG Code Use-After-Free
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Directory S
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.