Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DBVexDay Proof
Android - 'getpidcon' Permission Bypass in KeyStore Service
CVE-2017-13236dosandroid07 fev 2018
In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to loc
23RISCO
abrir
Exploit-DB
MalwareFox AntiMalware 2.74.0.150 - Privilege Escalation
CVE-2018-6606localwindows07 fev 2018
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows
23RISCO
abrir
Exploit-DBVexDay Proof
Asterisk 13.17.2 - 'chan_skinny' Remote Memory Corruption
CVE-2017-17090dosmultiple07 fev 2018
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and old
45RISCO
abrir
Exploit-DB
Wonder CMS 2.3.1 - 'Host' Header Injection
CVE-2017-14523webappsphp05 fev 2018
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NO
23RISCO
abrir
Exploit-DB
Joomla! Component Zh YandexMap 6.2.1.0 - 'id' SQL Injection
CVE-2018-6604webappsphp05 fev 2018
SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetail
23RISCO
abrir
Exploit-DB
HPE iLO 4 < 2.53 - Add New Administrator User
CVE-2017-12542remotemultiple05 fev 2018
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'EternalRomance'/'EternalSynergy'/'EternalChampion' SMB Remote Code Execution (Metasploit) (MS17-010)
CVE-2017-0147HIGHsob ataqueransomwareremotewindows05 fev 2018
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DB
Netis WF2419 Router - Cross-Site Scripting
CVE-2018-6190webappshardware05 fev 2018
Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page.
23RISCO
abrir
Exploit-DB
Claymore Dual GPU Miner 10.5 - Format String
CVE-2018-6317dosmultiple05 fev 2018
The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format strin
50RISCO
abrir
Exploit-DB
Joomla! Component Zh BaiduMap 3.0.0.1 - SQL Injection
CVE-2018-6605webappsphp05 fev 2018
SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, get
50RISCO
abrir
Exploit-DBVexDay Proof
Apport/ABRT - 'chroot' Local Privilege Escalation (Metasploit)
CVE-2015-1318locallinux05 fev 2018
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a craf
38RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'EternalRomance'/'EternalSynergy'/'EternalChampion' SMB Remote Code Execution (Metasploit) (MS17-010)
CVE-2017-0146HIGHsob ataqueransomwareremotewindows05 fev 2018
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DB
MalwareFox AntiMalware 2.74.0.150 - Local Privilege Escalation
CVE-2018-6593localwindows05 fev 2018
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows
23RISCO
abrir
Exploit-DBVexDay Proof
Wonder CMS 2.3.1 - Unrestricted File Upload
CVE-2017-14521webappsphp05 fev 2018
In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'EternalRomance'/'EternalSynergy'/'EternalChampion' SMB Remote Code Execution (Metasploit) (MS17-010)
CVE-2017-0143HIGHsob ataqueransomwareremotewindows05 fev 2018
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DB
Online Voting System - Authentication Bypass
CVE-2018-6180webappsphp05 fev 2018
A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password fo
23RISCO
abrir
Exploit-DB
WordPress Core - 'load-scripts.php' Denial of Service
CVE-2018-6389dosphp05 fev 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
Exploit-DB
Joomla! Component Zh GoogleMap 8.4.0.0 - SQL Injection
CVE-2018-6582webappsphp05 fev 2018
SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, ge
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Subsystem for Linux - 'execve()' Local Privilege Escalation
CVE-2018-0743localwindows02 fev 2018
Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle Hospitality Simphony (MICROS) 2.7 < 2.9 - Directory Traversal
CVE-2018-2636webappsmultiple02 fev 2018
Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security).
28RISCO
abrir
Exploit-DBVexDay Proof
BMC Server Automation RSCD Agent - NSH Remote Command Execution (Metasploit)
CVE-2016-1543remotemultiple01 fev 2018
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux a
60RISCO
abrir
Exploit-DBVexDay Proof
BMC Server Automation RSCD Agent - NSH Remote Command Execution (Metasploit)
CVE-2016-1542remotemultiple01 fev 2018
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U
60RISCO
abrir
Exploit-DBVexDay Proof
WebKit - 'detachWrapper' Use-After-Free
CVE-2018-4089dosmultiple01 fev 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safa
23RISCO
abrir
Exploit-DB
BMC BladeLogic RSCD Agent 8.3.00.64 - Windows Users Disclosure
CVE-2016-5063webappswindows30 jan 2018
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote atta
23RISCO
abrir
Exploit-DB
Joomla! Component Visual Calendar 3.1.3 - 'id' SQL Injection
CVE-2018-6395webappsphp30 jan 2018
SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action.
23RISCO
abrir
Exploit-DB
Joomla! Component CP Event Calendar 3.0.1 - 'id' SQL Injection
CVE-2018-6398webappsphp30 jan 2018
SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action.
23RISCO
abrir
Exploit-DB
Hotspot Shield - Information Disclosure
CVE-2018-6460localwindows30 jan 2018
Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sen
28RISCO
abrir
Exploit-DB
HPE iMC 7.3 - RMI Java Deserialization
CVE-2017-5792remotewindows30 jan 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
35RISCO
abrir
Exploit-DB
Advantech WebAccess < 8.3 - SQL Injection
CVE-2017-16716webappswindows30 jan 2018
A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs
23RISCO
abrir
Exploit-DB
Joomla! Component Picture Calendar for Joomla! 3.1.4 - Directory Traversal
CVE-2018-6397webappsphp30 jan 2018
Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! via the list.php folder parameter.
28RISCO
abrir
anteriorpágina 111 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.