Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.846exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.346GitHub PoC 15.209VulnCheck XDB 8.932Nuclei 4.383Metasploit 3.501✓ só verificadosrecentespopularesrisco
24.475 exploits
Exploit-DB✓ VexDay Proof
Microsoft Font Subsetting - DLL Heap Corruption in ReadTableIntoStructure
Microsoft Graphics Remote Code Execution Vulnerability
46RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - free() of Uninitialized Pointer due to Malformed JBIG2Globals Stream
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Use-After-Free due to Malformed JP2 Stream
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow in CoolType.dll
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NSKeyedUnarchiver - Info Leak in Decoding SGBigUTF8String
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6. A remote attacker
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in GetGlyphIdx
Microsoft Graphics Component Information Disclosure Vulnerability
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Out-of-Bounds read due to Malformed JP2 Stream
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISCO
abrir ↗Exploit-DB
TortoiseSVN 1.12.1 - Remote Code Execution
An issue was discovered in in TortoiseSVN 1.12.1. The Tsvncmd: URI handler allows a customised diff operation on Excel w
28RISCO
abrir ↗Exploit-DB
D-Link DIR-600M - Authentication Bypass (Metasploit)
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without
50RISCO
abrir ↗Exploit-DB
Mitsubishi Electric smartRTU / INEA ME-RTU - Unauthenticated Configuration Download
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3
35RISCO
abrir ↗Exploit-DB
BSI Advance Hotel Booking System 2.0 - 'booking_details.php Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0
23RISCO
abrir ↗Exploit-DB
Cisco Adaptive Security Appliance - Path Traversal (Metasploit)
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISCO
abrir ↗Exploit-DB
Mitsubishi Electric smartRTU / INEA ME-RTU - Unauthenticated OS Command Injection Bind Shell
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ghidra (Linux) 9.0.4 - .gar Arbitrary Code Execution
In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive)
23RISCO
abrir ↗Exploit-DB
VxWorks 6.8 - TCP Urgent Pointer = 0 Integer Underflow
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TC
45RISCO
abrir ↗Exploit-DB
UNA 10.0.0 RC1 - 'polyglot.php' Persistent Cross-Site Scripting
studio/polyglot.php?page=etemplates in UNA 10.0.0-RC1 allows XSS via the System Name field under Emails during template
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - UXSS via XSLT and Nested Document Replacements
A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This i
23RISCO
abrir ↗Exploit-DB
Open-School 3.0 / Community Edition 2.3 - Cross-Site Scripting
Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.
43RISCO
abrir ↗Exploit-DB
Adive Framework 2.0.7 - Cross-Site Request Forgery
Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.
23RISCO
abrir ↗Exploit-DB
Aptana Jaxer 1.0.3.4547 - Local File inclusion
Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer. This v
43RISCO
abrir ↗Exploit-DB
WordPress Plugin JoomSport 3.3 - SQL Injection
The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tika 1.15 - 1.17 - Header Command Injection (Metasploit)
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
macOS iMessage - Heap Overflow when Deserializing
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.6. A rem
28RISCO
abrir ↗Exploit-DB
SilverSHielD 6.x - Local Privilege Escalation
extenua SilverSHielD 6.x fails to secure its ProgramData folder, leading to a Local Privilege Escalation to SYSTEM. The
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Hyperion Planning 11.1.2.3 - XML External Entity
Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported versi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iMessage - NSKeyedUnarchiver Deserialization Allows file Backed NSData Objects
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iMessage - NSArray Deserialization can Invoke Subclass that does not Retain References
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.4, tvOS 12.4, watchO
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
macOS / iOS JavaScriptCore - JSValue Use-After-Free in ValueProfiles
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS M
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iMessage - Memory Corruption when Decoding NSKnownKeysDictionary1
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Amcrest Cameras 2.520.AC00.18.R - Unauthenticated Audio Streaming
The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.