Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.475 exploits
Exploit-DB
XiongMai uc-httpd 1.0.0 - Buffer Overflow
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE
50RISCO
abrir ↗Exploit-DB
Splunk < 7.0.1 - Information Disclosure
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - WebAssembly Compilation Info Leak
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
28RISCO
abrir ↗Exploit-DB
Monstra CMS < 3.0.4 - Cross-Site Scripting (1)
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
XNU Kernel - Heap Overflow Due to Bad Bounds Checking in MPTCP
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS Kernel - Use-After-Free Due to Lack of Locking in nvidia GeForce Driver
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "NVIDIA Grap
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS Kernel - Heap Overflow Due to Lack of Lower Size Check in getvolattrlist
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 7.2.2 - 'php_stream_url_wrap_http_ex' Buffer Overflow
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denia
91RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RISCO
abrir ↗Exploit-DB
Linux Kernel < 4.16.11 - 'ext4_read_inline_data()' Memory Corruption
In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untruste
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISCO
abrir ↗Exploit-DB
WebKitGTK+ < 2.21.3 - Crash (PoC)
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon
50RISCO
abrir ↗Exploit-DB
Jenkins Mailer Plugin < 1.20 - Cross-Site Request Forgery (Send Email)
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated
23RISCO
abrir ↗Exploit-DB
Pagekit < 1.0.13 - Cross-Site Scripting Code Generator
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MyBB Recent Threads Plugin 1.0 - Cross-Site Scripting
The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject.
23RISCO
abrir ↗Exploit-DB
CyberArk < 10 - Memory Disclosure
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay
28RISCO
abrir ↗Exploit-DB
EMS Master Calendar < 8.0.0.20180520 - Cross-Site Scripting
Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malici
23RISCO
abrir ↗Exploit-DB
Brother HL Series Printers 1.15 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability on Brother HL series printers allows remote attackers to inject arbitrary web s
23RISCO
abrir ↗Exploit-DB
SearchBlox 8.6.7 - XML External Entity Injection
XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to re
28RISCO
abrir ↗Exploit-DB
Zip-n-Go 4.9 - Buffer Overflow (SEH)
MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file.
23RISCO
abrir ↗Exploit-DB
GreenCMS 2.3.0603 - Cross-Site Request Forgery (Add Admin)
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php
23RISCO
abrir ↗Exploit-DB
GreenCMS 2.3.0603 - Cross-Site Request Forgery / Remote Code Execution
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - EntrySimpleObjectSlotGetter Type Confusion
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISCO
abrir ↗Exploit-DB
Procps-ng - Multiple Vulnerabilities
procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset
41RISCO
abrir ↗Exploit-DB
Procps-ng - Multiple Vulnerabilities
A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory
28RISCO
abrir ↗Exploit-DB
Procps-ng - Multiple Vulnerabilities
procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection
28RISCO
abrir ↗Exploit-DB
Procps-ng - Multiple Vulnerabilities
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec
41RISCO
abrir ↗Exploit-DB
Siemens SIMATIC S7-300 CPU - Remote Denial of Service
Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode transition) via craf
53RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.