Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8.970Nuclei 4.394Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.476 exploits
Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.22 < 3.9 (x86/x64) - 'Dirty COW /proc/self/mem' Race Condition Privilege Escalation (SUID Method)
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Registry Hive Loading Relative Arbitrary Read in nt!RtlValidRelativeSecurityDescriptor (MS16-123)
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'win32k.sys' TTF Processing win32k!sbit_Embolden / win32k!ttfdCloseFontContext Use-After-Free (MS16-120)
The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; W
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - NtLoadKeyEx Read Only Hive Arbitrary File Write Privilege Escalation (MS16-124)
The kernel in Microsoft Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application
23RISCO
abrir ↗Exploit-DB
MiCasaVerde VeraLite - Remote Code Execution
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute a
28RISCO
abrir ↗Exploit-DB
MiCasaVerde VeraLite - Remote Code Execution
Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a P
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Hak5 WiFi Pineapple 2.4 - Preconfiguration Command Injection (Metasploit)
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Edge/Internet Explorer - Isolated Private Namespace Insecure DACL Privilege Escalation (MS16-118)
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which al
28RISCO
abrir ↗Exploit-DB
Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injection
Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0,
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SPIP 3.1.2 Template Compiler/Composer - PHP Code Execution
The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - 'Array.join' Infomation Leak (MS16-119)
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site,
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Registry Hive Loading Negative RtlMoveMemory Size in nt!CmpCheckValueList (MS16-124)
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serve
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SPIP 3.1.1/3.1.2 - File Enumeration / Path Traversal
Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to en
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - 'Array.map' Heap Overflow (MS16-119)
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Edge/Internet Explorer - Isolated Private Namespace Insecure Boundary Descriptor Privilege Escalation (MS16-118)
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which al
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SPIP 3.1.2 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - Spread Operator Stack Overflow (MS16-119)
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'win32k.sys' TTF Processing RCVT TrueType Instruction Handler Out-of-Bounds Read (MS16-120)
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - 'Function.apply' Information Leak (MS16-119)
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.22 < 3.9 - 'Dirty COW' /proc/self/mem Race Condition (Write Access Method)
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - DFS Client Driver Arbitrary Drive Mapping Privilege Escalation (MS16-123)
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - DeviceApi CMApi User Hive Impersonation Privilege Escalation (MS16-124)
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 160
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - DeviceApi CMApi PiCMOpenDeviceKey Arbitrary Registry Key Write Privilege Escalation (MS16-124)
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 160
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows (x86) - 'afd.sys' Local Privilege Escalation (MS11-046)
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vis
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Diagnostics Hub - DLL Load Privilege Escalation (MS16-125)
The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles librar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ruby on Rails - Dynamic Render File Upload / Remote Code Execution (Metasploit)
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.
100RISCO
abrir ↗Exploit-DB
Linux Kernel < 4.5.1 - Off-By-One (PoC)
The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buff
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player 23.0.0.162 - '.SWF' ConstantPool Critical Memory Corruption
Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637
28RISCO
abrir ↗Exploit-DB
Subversion 1.6.6/1.6.12 - Code Execution
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit perm
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Webex Player T29.10 - '.WRF' Use-After-Free Memory Corruption
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.