Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
OTRS 5.0.x/6.0.x - Remote Command Execution (1)
CVE-2017-1692121 jan 2018
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.2
28RISCO
abrir
Exploit-DB
macOS 10.13 (17A365) - Kernel Memory Disclosure due to Lack of Bounds Checking in 'AppleIntelCapriController::getDisplayPipeCapability'
CVE-2017-1387819 jan 2018
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graph
23RISCO
abrir
Exploit-DB
Primefaces 5.x - Remote Code Execution (Metasploit)
CVE-2017-1000486CRITICALsob ataque18 jan 2018
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISCO
abrir
Exploit-DB
Smiths Medical Medfusion 4000 - 'DHCP' Denial of Service
CVE-2017-1271818 jan 2018
A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version
28RISCO
abrir
Exploit-DB
Microsoft Edge Chakra - Incorrect Scope Handling
CVE-2018-077417 jan 2018
Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due t
35RISCO
abrir
Exploit-DB
Master IP CAM 01 - Multiple Vulnerabilities
CVE-2018-572417 jan 2018
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore
28RISCO
abrir
Exploit-DB
Master IP CAM 01 - Multiple Vulnerabilities
CVE-2018-572617 jan 2018
MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to obtain sensitive information via a crafted HTTP request,
28RISCO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - Stack-to-Heap Copy
CVE-2018-077617 jan 2018
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RISCO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - Incorrect Bounds Calculation
CVE-2018-076917 jan 2018
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RISCO
abrir
Exploit-DB
Microsoft Edge Chakra - 'AsmJSByteCodeGenerator::EmitCall' Out-of-Bounds Read
CVE-2018-078017 jan 2018
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtai
35RISCO
abrir
Exploit-DB
SugarCRM 3.5.1 - Cross-Site Scripting
CVE-2018-571517 jan 2018
phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).
38RISCO
abrir
Exploit-DB
Master IP CAM 01 - Multiple Vulnerabilities
CVE-2018-572517 jan 2018
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of t
23RISCO
abrir
Exploit-DB
Microsoft Edge Chakra - 'JavascriptGeneratorFunction::GetPropertyBuiltIns' Type Confusion
CVE-2017-1191417 jan 2018
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain t
35RISCO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - Out-of-Bounds Write
CVE-2018-077717 jan 2018
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RISCO
abrir
Exploit-DB
Reservo Image Hosting Script 1.5 - Cross-Site Scripting
CVE-2018-570517 jan 2018
Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to t
23RISCO
abrir
Exploit-DB
Microsoft Edge Chakra - Deferred Parsing Makes Wrong Scopes (2)
CVE-2018-077517 jan 2018
Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due t
35RISCO
abrir
Exploit-DB
Master IP CAM 01 - Multiple Vulnerabilities
CVE-2018-572317 jan 2018
MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.
23RISCO
abrir
Exploit-DB
glibc < 2.26 - 'getcwd()' Local Privilege Escalation
CVE-2018-100000116 jan 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir
Exploit-DB
Disk Pulse Enterprise 10.1.18 - Remote Buffer Overflow
CVE-2017-1566315 jan 2018
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The att
28RISCO
abrir
Exploit-DB
PerfexCRM 1.9.7 - Arbitrary File Upload
CVE-2017-1797615 jan 2018
In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.
28RISCO
abrir
Exploit-DB
pfSense < 2.1.4 - 'status_rrd_graph_img.php' Command Injection
CVE-2014-468815 jan 2018
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RISCO
abrir
Exploit-DB
Oracle PeopleSoft 8.5x - Remote Code Execution
CVE-2017-1036615 jan 2018
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Perform
35RISCO
abrir
Exploit-DB
RISE 1.9 - 'search' SQL Injection
CVE-2017-1799915 jan 2018
SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir
Exploit-DB
SysGauge Server 3.6.18 - Remote Buffer Overflow
CVE-2018-535915 jan 2018
The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system
23RISCO
abrir
Exploit-DB
ILIAS < 5.2.4 - Cross-Site Scripting
CVE-2018-568815 jan 2018
ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in
23RISCO
abrir
Exploit-DB
GitStack - Remote Code Execution
CVE-2018-595515 jan 2018
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RISCO
abrir
Exploit-DB
Oracle E-Business Suite 12.1.3/12.2.x - Open Redirect
CVE-2017-352815 jan 2018
Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (li
43RISCO
abrir
Exploit-DB
ImgHosting 1.5 - Cross-Site Scripting
CVE-2018-547915 jan 2018
FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its sear
23RISCO
abrir
Exploit-DB
Xnami 1.0 - Cross-Site Scripting
CVE-2018-537012 jan 2018
BizLogic xnami 1.0 has XSS via the comment parameter in an addComment action to the /media/ajax URI.
23RISCO
abrir
Exploit-DB
Kentico CMS 11.0 - Buffer Overflow
CVE-2018-528212 jan 2018
Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password fie
23RISCO
abrir
anteriorpágina 108 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.