Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
Microsoft Windows Subsystem for Linux - 'execve()' Local Privilege Escalation
CVE-2018-074302 fev 2018
Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows
23RISCO
abrir
Exploit-DB
Oracle Hospitality Simphony (MICROS) 2.7 < 2.9 - Directory Traversal
CVE-2018-263602 fev 2018
Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security).
28RISCO
abrir
Exploit-DB
BMC Server Automation RSCD Agent - NSH Remote Command Execution (Metasploit)
CVE-2016-154301 fev 2018
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux a
60RISCO
abrir
Exploit-DB
BMC Server Automation RSCD Agent - NSH Remote Command Execution (Metasploit)
CVE-2016-154201 fev 2018
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U
60RISCO
abrir
Exploit-DB
WebKit - 'detachWrapper' Use-After-Free
CVE-2018-408901 fev 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safa
23RISCO
abrir
Exploit-DB
Joomla! Component CP Event Calendar 3.0.1 - 'id' SQL Injection
CVE-2018-639830 jan 2018
SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action.
23RISCO
abrir
Exploit-DB
HPE iMC 7.3 - RMI Java Deserialization
CVE-2017-579230 jan 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
35RISCO
abrir
Exploit-DB
BMC BladeLogic RSCD Agent 8.3.00.64 - Windows Users Disclosure
CVE-2016-506330 jan 2018
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote atta
23RISCO
abrir
Exploit-DB
Hotspot Shield - Information Disclosure
CVE-2018-646030 jan 2018
Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sen
28RISCO
abrir
Exploit-DB
System Shield 5.0.0.136 - Privilege Escalation
CVE-2018-570130 jan 2018
In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerabi
28RISCO
abrir
Exploit-DB
Joomla! Component Visual Calendar 3.1.3 - 'id' SQL Injection
CVE-2018-639530 jan 2018
SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action.
23RISCO
abrir
Exploit-DB
Joomla! Component Picture Calendar for Joomla! 3.1.4 - Directory Traversal
CVE-2018-639730 jan 2018
Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! via the list.php folder parameter.
28RISCO
abrir
Exploit-DB
Advantech WebAccess < 8.3 - SQL Injection
CVE-2017-1671630 jan 2018
A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs
23RISCO
abrir
Exploit-DB
iBall WRA150N - Multiple Vulnerabilities
CVE-2018-638829 jan 2018
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands
23RISCO
abrir
Exploit-DB
systemd (systemd-tmpfiles) < 236 - 'fs.protected_hardlinks=0' Local Privilege Escalation
CVE-2017-1807829 jan 2018
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the
23RISCO
abrir
Exploit-DB
Arq 5.10 - Local Privilege Escalation (2)
CVE-2017-1694529 jan 2018
The standardrestorer binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequen
23RISCO
abrir
Exploit-DB
Oracle WebLogic - wls-wsat Component Deserialization Remote Code Execution (Metasploit)
CVE-2017-10271HIGHsob ataqueransomware29 jan 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
Exploit-DB
Arq 5.10 - Local Privilege Escalation (1)
CVE-2017-1692829 jan 2018
The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently g
23RISCO
abrir
Exploit-DB
macOS - 'sysctl_vfs_generic_conf' Stack Leak Through Struct Padding
CVE-2018-409029 jan 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS
23RISCO
abrir
Exploit-DB
Multilanguage Real Estate MLM Script 3.0 - 'srch' SQL Injection
CVE-2018-636428 jan 2018
SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.
23RISCO
abrir
Exploit-DB
Joomla! Component Jtag Members Directory 5.3.7 - Arbitrary File Download
CVE-2018-600828 jan 2018
Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter
50RISCO
abrir
Exploit-DB
TSiteBuilder 1.0 - SQL Injection
CVE-2018-636528 jan 2018
SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php.
23RISCO
abrir
Exploit-DB
Buddy Zone 2.9.9 - SQL Injection
CVE-2018-636728 jan 2018
SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parame
23RISCO
abrir
Exploit-DB
Nexpose < 6.4.66 - Cross-Site Request Forgery
CVE-2017-526428 jan 2018
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated A
23RISCO
abrir
Exploit-DB
Artifex MuJS 1.0.2 - Denial of Service
CVE-2018-619128 jan 2018
The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent v
23RISCO
abrir
Exploit-DB
Hot Scripts Clone - 'subctid' SQL Injection
CVE-2017-1761228 jan 2018
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
23RISCO
abrir
Exploit-DB
Artifex MuJS 1.0.2 - Integer Overflow
CVE-2018-575928 jan 2018
jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows re
23RISCO
abrir
Exploit-DB
Joomla! Component JS Support Ticket 1.1.0 - Cross-Site Request Forgery
CVE-2018-600728 jan 2018
CSRF exists in the JS Support Ticket 1.1.0 component for Joomla! and allows attackers to inject HTML or edit a ticket.
23RISCO
abrir
Exploit-DB
Task Rabbit Clone 1.0 - 'id' SQL Injection
CVE-2018-636328 jan 2018
SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter.
23RISCO
abrir
Exploit-DB
KeystoneJS < 4.0.0-beta.7 - Cross-Site Request Forgery
CVE-2017-1657028 jan 2018
KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureL
23RISCO
abrir
anteriorpágina 106 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.