Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DBVexDay Proof
HPE iMC - dbman 'RestoreDBase' Remote Command Execution (Metasploit)
CVE-2017-5817remotewindows10 jan 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RISCO
abrir
Exploit-DB
Parity Browser < 1.6.10 - Bypass Same Origin Policy
CVE-2017-18016localmultiple10 jan 2018
Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
23RISCO
abrir
Exploit-DB
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
CVE-2016-2386CRITICALsob ataquewebappsmultiple10 jan 2018
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Easydiscuss < 4.0.21 - Cross-Site Scripting
CVE-2018-5263webappsphp10 jan 2018
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.
23RISCO
abrir
Exploit-DB
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
CVE-2016-2388MEDIUMsob ataquewebappsmultiple10 jan 2018
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user infor
75RISCO
abrir
Exploit-DBVexDay Proof
HPE iMC - dbman 'RestartDB' Remote Command Execution (Metasploit)
CVE-2017-5816remotewindows10 jan 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'Lowerer::LowerSetConcatStrMultiItem' Missing Integer Overflow Check
CVE-2018-0758doswindows10 jan 2018
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RISCO
abrir
Exploit-DB
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
CVE-2016-1910webappsmultiple10 jan 2018
The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors,
23RISCO
abrir
Exploit-DB
WordPress Plugin Events Calendar - 'event_id' SQL Injection
CVE-2018-5315webappsphp10 jan 2018
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
23RISCO
abrir
Exploit-DB
Muviko 1.1 - SQL Injection
CVE-2017-17970webappsphp10 jan 2018
Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1
23RISCO
abrir
Exploit-DB
Jungo Windriver 12.5.1 - Local Privilege Escalation
CVE-2018-5189localwindows10 jan 2018
Race condition in Jungo Windriver 12.5.1 allows local users to cause a denial of service (buffer overflow) or gain syste
23RISCO
abrir
Exploit-DB
DiskBoss Enterprise 8.8.16 - Remote Buffer Overflow
CVE-2018-5262remotewindows10 jan 2018
A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQuerySystemInformation (information class 138_ QueryMemoryTopologyInformation)' Kernel Pool Memory Disclosure
CVE-2018-0746doswindows09 jan 2018
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wi
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Escape Analysis Bug
CVE-2017-11918doswindows09 jan 2018
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryInformationProcess (information class 76_ QueryProcessEnergyValues)' Kernel Stack Memory Disclosure
CVE-2018-0745doswindows09 jan 2018
The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an infor
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Op_MaxInAnArray and Op_MinInAnArray can Explicitly call User-Defined JavaScript Functions
CVE-2017-11893doswindows09 jan 2018
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execut
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'asm.js' Out-of-Bounds Read
CVE-2017-11911doswindows09 jan 2018
ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - BackwardPass::RemoveEmptyLoopAfterMemOp Does not Insert Branches
CVE-2017-11909doswindows09 jan 2018
ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i
35RISCO
abrir
Exploit-DB
Microsoft Office - 'Composite Moniker Remote Code Execution
CVE-2017-8570HIGHsob ataquelocalwindows09 jan 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISCO
abrir
Exploit-DB
FiberHome LM53Q1 - Multiple Vulnerabilities
CVE-2017-16886webappshardware08 jan 2018
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact
23RISCO
abrir
Exploit-DBVexDay Proof
Vanilla < 2.1.5 - Cross-Site Request Forgery
CVE-2017-1000432webappsphp08 jan 2018
Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
23RISCO
abrir
Exploit-DB
Synology DiskStation Manager (DSM) < 6.1.3-15152 - 'forget_passwd.cgi' User Enumeration
CVE-2017-9554webappscgi08 jan 2018
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RISCO
abrir
Exploit-DBVexDay Proof
VX Search Enterprise 10.1.12 - Denial of Service
CVE-2017-15662doswindows08 jan 2018
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The atta
23RISCO
abrir
Exploit-DB
FiberHome LM53Q1 - Multiple Vulnerabilities
CVE-2017-16887webappshardware08 jan 2018
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact
35RISCO
abrir
Exploit-DB
DiskBoss Enterprise 8.5.12 - Denial of Service
CVE-2017-15665doswindows08 jan 2018
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack
23RISCO
abrir
Exploit-DBVexDay Proof
Android - Inter-Process munmap due to Race Condition in ashmem
CVE-2017-13216dosandroid08 jan 2018
In ashmem_ioctl of ashmem.c, there is an out-of-bounds write due to insufficient locking when accessing asma. This could
23RISCO
abrir
Exploit-DB
Disk Pulse Enterprise 10.1.18 - Denial of Service
CVE-2017-15663doswindows08 jan 2018
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The att
28RISCO
abrir
Exploit-DB
FiberHome LM53Q1 - Multiple Vulnerabilities
CVE-2017-16885webappshardware08 jan 2018
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining informati
35RISCO
abrir
Exploit-DB
Sync Breeze Enterprise 10.1.16 - Denial of Service
CVE-2017-15664doswindows08 jan 2018
In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The at
23RISCO
abrir
Exploit-DB
gps-server.net GPS Tracking Software < 3.1 - Multiple Vulnerabilities
CVE-2017-17097webappsphp05 jan 2018
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords
23RISCO
abrir
anteriorpágina 115 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.