Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DB
SugarCRM 3.5.1 - Cross-Site Scripting
CVE-2018-5715webappsphp17 jan 2018
phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).
38RISCO
abrir
Exploit-DB
Master IP CAM 01 - Multiple Vulnerabilities
CVE-2018-5724remotehardware17 jan 2018
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore
28RISCO
abrir
Exploit-DB
Master IP CAM 01 - Multiple Vulnerabilities
CVE-2018-5725remotehardware17 jan 2018
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of t
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JavascriptGeneratorFunction::GetPropertyBuiltIns' Type Confusion
CVE-2017-11914doswindows17 jan 2018
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain t
35RISCO
abrir
Exploit-DB
Reservo Image Hosting Script 1.5 - Cross-Site Scripting
CVE-2018-5705webappsphp17 jan 2018
Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to t
23RISCO
abrir
Exploit-DB
Master IP CAM 01 - Multiple Vulnerabilities
CVE-2018-5723remotehardware17 jan 2018
MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.
23RISCO
abrir
Exploit-DBVexDay Proof
glibc < 2.26 - 'getcwd()' Local Privilege Escalation
CVE-2018-1000001locallinux16 jan 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir
Exploit-DBVexDay Proof
ILIAS < 5.2.4 - Cross-Site Scripting
CVE-2018-5688webappsphp15 jan 2018
ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in
23RISCO
abrir
Exploit-DB
GitStack - Remote Code Execution
CVE-2018-5955webappsphp15 jan 2018
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RISCO
abrir
Exploit-DB
Oracle PeopleSoft 8.5x - Remote Code Execution
CVE-2017-10366webappsjava15 jan 2018
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Perform
35RISCO
abrir
Exploit-DB
PerfexCRM 1.9.7 - Arbitrary File Upload
CVE-2017-17976webappsphp15 jan 2018
In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.
28RISCO
abrir
Exploit-DB
Disk Pulse Enterprise 10.1.18 - Remote Buffer Overflow
CVE-2017-15663remotewindows15 jan 2018
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The att
28RISCO
abrir
Exploit-DB
pfSense < 2.1.4 - 'status_rrd_graph_img.php' Command Injection
CVE-2014-4688webappsphp15 jan 2018
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle E-Business Suite 12.1.3/12.2.x - Open Redirect
CVE-2017-3528webappsjsp15 jan 2018
Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (li
43RISCO
abrir
Exploit-DB
ImgHosting 1.5 - Cross-Site Scripting
CVE-2018-5479webappsphp15 jan 2018
FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its sear
23RISCO
abrir
Exploit-DB
RISE 1.9 - 'search' SQL Injection
CVE-2017-17999webappsphp15 jan 2018
SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir
Exploit-DB
SysGauge Server 3.6.18 - Remote Buffer Overflow
CVE-2018-5359remotewindows15 jan 2018
The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system
23RISCO
abrir
Exploit-DB
Xnami 1.0 - Cross-Site Scripting
CVE-2018-5370webappsphp12 jan 2018
BizLogic xnami 1.0 has XSS via the comment parameter in an addComment action to the /media/ajax URI.
23RISCO
abrir
Exploit-DB
Kentico CMS 11.0 - Buffer Overflow
CVE-2018-5282doswindows12 jan 2018
Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password fie
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NtImpersonateAnonymousToken LPAC to Non-LPAC Privilege Escalation
CVE-2018-0752doswindows11 jan 2018
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'AppendLeftOverItemsFromEndSegment' Out-of-Bounds Read
CVE-2018-0767doswindows11 jan 2018
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain info
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NTFS Owner/Mandatory Label Privilege Bypass
CVE-2018-0748doswindows11 jan 2018
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and
23RISCO
abrir
Exploit-DBVexDay Proof
phpCollab 2.5.1 - File Upload (Metasploit)
CVE-2017-6090remotephp11 jan 2018
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RISCO
abrir
Exploit-DB
ALLMediaServer 0.95 - Remote Buffer Overflow
CVE-2017-17932remotewindows11 jan 2018
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows SMB Server (v1/v2) - Mount Point Arbitrary Device Open Privilege Escalation
CVE-2018-0749doswindows11 jan 2018
The Microsoft Server Message Block (SMB) Server in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NtImpersonateAnonymousToken AC to Non-AC Privilege Escalation
CVE-2018-0751doswindows11 jan 2018
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RISCO
abrir
Exploit-DBVexDay Proof
Android - Hardware Service Manager Arbitrary Service Replacement due to getpidcon
CVE-2017-13209dosandroid11 jan 2018
In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the
23RISCO
abrir
Exploit-DBVexDay Proof
macOS - 'process_policy' Stack Leak Through Uninitialized Field
CVE-2017-7154dosmacos11 jan 2018
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISCO
abrir
Exploit-DBVexDay Proof
Transmission - RPC DNS Rebinding
CVE-2018-5702remotemultiple11 jan 2018
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access con
28RISCO
abrir
Exploit-DB
Seagate Personal Cloud - Multiple Vulnerabilities
CVE-2018-5347remotehardware11 jan 2018
Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs
35RISCO
abrir
anteriorpágina 114 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.