Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
Zoom Linux Client 2.0.106600.0904 - Command Injection
CVE-2017-1504918 dez 2017
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when c
28RISCO
abrir
Exploit-DB
GoAhead Web Server 2.5 < 3.6.5 - HTTPd 'LD_PRELOAD' Remote Code Execution
CVE-2017-17562HIGHsob ataque18 dez 2017
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISCO
abrir
Exploit-DB
Zoom Linux Client 2.0.106600.0904 - Stack-Based Buffer Overflow (PoC)
CVE-2017-1504818 dez 2017
Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote
28RISCO
abrir
Exploit-DB
Linux kernel < 4.10.15 - Race Condition Privilege Escalation
CVE-2017-1066115 dez 2017
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denia
28RISCO
abrir
Exploit-DB
Sync Breeze 10.2.12 - Denial of Service
CVE-2017-1708815 dez 2017
The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The we
23RISCO
abrir
Exploit-DB
Bus Booking Script 1.0 - 'txtname' SQL Injection
CVE-2017-1764514 dez 2017
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
23RISCO
abrir
Exploit-DB
FS Lynda Clone 1.0 - SQL Injection
CVE-2017-1764314 dez 2017
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
23RISCO
abrir
Exploit-DB
Paid To Read Script 2.0.5 - 'uid' / 'fnum' / 'fn' SQL Injection
CVE-2017-1765114 dez 2017
Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum para
23RISCO
abrir
Exploit-DB
Palo Alto Networks Firewalls - Root Remote Code Execution
CVE-2017-15944CRITICALsob ataque14 dez 2017
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISCO
abrir
Exploit-DB
Readymade Video Sharing Script 3.2 - HTML Injection
CVE-2017-1764914 dez 2017
Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.
23RISCO
abrir
Exploit-DB
Advantech WebAccess 8.2-2017.03.31 - Webvrpcs Service Opcode 80061 Stack Buffer Overflow (Metasploit)
CVE-2017-1401614 dez 2017
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The applicati
43RISCO
abrir
Exploit-DB
Linksys WVBR0 - 'User-Agent' Remote Command Injection
CVE-2017-1741114 dez 2017
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authe
60RISCO
abrir
Exploit-DB
Piwigo 2.9.1 - 'cat_true' / 'cat_false' SQL Injection
CVE-2017-1068214 dez 2017
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitra
23RISCO
abrir
Exploit-DB
vBulletin 5.x - 'cacheTemplates' Remote Arbitrary File Deletion
CVE-2017-1767213 dez 2017
In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file delet
28RISCO
abrir
Exploit-DB
Joomla! Component JEXTN Question And Answer 3.1.0 - SQL Injection
CVE-2017-1787113 dez 2017
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action
23RISCO
abrir
Exploit-DB
Joomla! Component JEXTN Video Gallery 3.0.5 - 'id' SQL Injection
CVE-2017-1787213 dez 2017
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
23RISCO
abrir
Exploit-DB
Meinberg LANTIME Web Configuration Utility 6.16.008 - Arbitrary File Read
CVE-2017-1678713 dez 2017
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read
23RISCO
abrir
Exploit-DB
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
CVE-2017-100040813 dez 2017
A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environme
23RISCO
abrir
Exploit-DB
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
CVE-2017-100040913 dez 2017
A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environ
23RISCO
abrir
Exploit-DB
Accesspress Anonymous Post Pro < 3.2.0 - Arbitrary File Upload
CVE-2017-1694912 dez 2017
An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper in
28RISCO
abrir
Exploit-DB
Joomla! Component JBuildozer 1.4.1 - 'appid' SQL Injection
CVE-2017-1787012 dez 2017
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
23RISCO
abrir
Exploit-DB
Apple macOS - Kernel Code Execution due to Lack of Bounds Checking in AppleIntelCapriController::GetLinkConfig
CVE-2017-1387512 dez 2017
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graph
23RISCO
abrir
Exploit-DB
Apple macOS/iOS - Kernel Double Free due to Incorrect API Usage in Flow Divert Socket Option Handling
CVE-2017-1386712 dez 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISCO
abrir
Exploit-DB
Apple XNU Kernel - Memory Corruption due to Integer Overflow in __offsetof Usage in posix_spawn on 32-bit Platforms
CVE-2017-1387612 dez 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISCO
abrir
Exploit-DB
Apple macOS/iOS - Multiple Kernel Use-After-Frees due to Incorrect IOKit Object Lifetime Management in IOTimeSyncClockManagerUserClient
CVE-2017-1384712 dez 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The is
23RISCO
abrir
Exploit-DB
Food Order Script 1.0 - 'list?city' SQL Injection
CVE-2017-1761411 dez 2017
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir
Exploit-DB
Linux Kernel - 'The Huge Dirty Cow' Overwriting The Huge Zero Page (2)
CVE-2017-100040511 dez 2017
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside
23RISCO
abrir
Exploit-DB
Freelance Website Script 2.0.6 - 'pr_id' / 'catid' SQL Injection
CVE-2017-1761311 dez 2017
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RISCO
abrir
Exploit-DB
Hot Scripts Clone 3.1 - 'subctid' / 'mctid' SQL Injection
CVE-2017-1761211 dez 2017
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
23RISCO
abrir
Exploit-DB
Vanguard 1.4 - Arbitrary File Upload
CVE-2017-1787411 dez 2017
Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product
23RISCO
abrir
anteriorpágina 112 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.