Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.334VulnCheck XDB 8.195Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
22.786 exploits
Exploit-DB
D-Link DIR-816L Wireless Router - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2
23RISCO
abrir ↗Exploit-DB
Microsoft Windows Kernel - 'win32k.sys' Malformed OS/2 Table TTF Font Processing Pool-Based Buffer Overflow (MS15-115)
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISCO
abrir ↗Exploit-DB
Microsoft Windows Kernel - 'win32k.sys' Malformed TrueType Program TTF Font Processing Pool-Based Buffer Overflow (MS15-115)
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISCO
abrir ↗Exploit-DB
Arris TG1682G Modem - Persistent Cross-Site Scripting
Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via
23RISCO
abrir ↗Exploit-DB
JSSE - SKIP-TLS
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.
50RISCO
abrir ↗Exploit-DB
vBulletin 5.1.x - Remote Code Execution
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RISCO
abrir ↗Exploit-DB
OpenSSL - Alternative Chains Certificate Forgery
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly
50RISCO
abrir ↗Exploit-DB
Samsung - libQjpeg Image Decoding Memory Corruption
The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allow
23RISCO
abrir ↗Exploit-DB
Samsung Galaxy S6 Samsung Gallery - Bitmap Decoding Crash
Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
23RISCO
abrir ↗Exploit-DB
Samsung Galaxy S6 - android.media.process Face Recognition Memory Corruption
The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge befo
23RISCO
abrir ↗Exploit-DB
Samsung Galaxy S6 - libQjpeg DoIntegralUpsample Crash
LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memor
23RISCO
abrir ↗Exploit-DB
Symantec pcAnywhere 12.5.0 (Windows x86) - Remote Code Execution
The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.
35RISCO
abrir ↗Exploit-DB
Microsoft Windows - NtCreateLowBoxToken Handle Capture Local Denial of Service / Privilege Escalation (MS15-111)
The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10
23RISCO
abrir ↗Exploit-DB
Oxwall 1.7.4 - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall before 1.8 allow remote attackers to hijack the aut
23RISCO
abrir ↗Exploit-DB
eBay Magento 1.9.2.1 - PHP FPM XML eXternal Entity Injection
The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x befor
23RISCO
abrir ↗Exploit-DB
NetUSB - Kernel Stack Buffer Overflow
Stack-based buffer overflow in the run_init_sbus function in the KCodes NetUSB module for the Linux kernel, as used in c
28RISCO
abrir ↗Exploit-DB
Samsung - 'seiren' Kernel Driver Buffer Overflow
Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung
23RISCO
abrir ↗Exploit-DB
Samsung - SecEmailComposer QUICK_REPLY_BACKGROUND Permissions
The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions f
23RISCO
abrir ↗Exploit-DB
Samsung SecEmailUI - Script Injection
SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaS
23RISCO
abrir ↗Exploit-DB
JIRA and HipChat for JIRA Plugin - Velocity Template Injection
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java
50RISCO
abrir ↗Exploit-DB
Samsung - 'm2m1shot' Kernel Driver Buffer Overflow
Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in
23RISCO
abrir ↗Exploit-DB
Apple Mac OSX 10.9.5/10.10.5 - 'rsh/libmalloc' Local Privilege Escalation (Metasploit)
rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors inv
38RISCO
abrir ↗Exploit-DB
Apple Safari - User-Assisted Applescript Exec Attack (Metasploit)
Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement f
50RISCO
abrir ↗Exploit-DB
Joomla! Component Realtyna RPL 8.9.2 - Persistent Cross-Site Scripting / Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows
23RISCO
abrir ↗Exploit-DB
Joomla! Component Realtyna RPL 8.9.2 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote adm
23RISCO
abrir ↗Exploit-DB
The World Browser 3.0 Final - Remote Code Execution
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISCO
abrir ↗Exploit-DB
Zpanel - Remote Code Execution (Metasploit)
ZPanel through 10.1.0 has Remote Command Execution
43RISCO
abrir ↗Exploit-DB
HTML Compiler - Remote Code Execution
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISCO
abrir ↗Exploit-DB
Adobe Flash - 'IExternalizable.writeExternal' Type Confusion
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535
83RISCO
abrir ↗Exploit-DB
Belkin N150 Router 1.00.08/1.00.09 - Directory Traversal
Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware befor
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.