Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DB
Vonage VDV-23 - Denial of Service
CVE-2017-16902doshardware21 nov 2017
On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or logi
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - 'nt!NtQueryDirectoryFile (luafv!LuafvCopyDirectoryEntry)' Pool Memory Disclosure
CVE-2017-11831doswindows21 nov 2017
Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2,
23RISCO
abrir
Exploit-DBVexDay Proof
iOS < 11.1 / tvOS < 11.1 / watchOS < 4.1 - Denial of Service
CVE-2017-13849dosios20 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS be
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - CiSetFileCache TOCTOU Security Feature Bypass
CVE-2017-11830localwindows20 nov 2017
Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allow
23RISCO
abrir
Exploit-DB
Microsoft Office - OLE Remote Code Execution
CVE-2017-11882HIGHsob ataqueransomwareremotewindows20 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
Exploit-DB
Icon Time Systems RTC-1000 Firmware 2.5.7458 - Cross-Site Scripting
CVE-2017-16819webappshardware17 nov 2017
A stored cross-site scripting vulnerability in the Icon Time Systems RTC-1000 v2.5.7458 and earlier time clock allows re
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - 'Object.setPrototypeOf' Memory Corruption
CVE-2017-8751doswindows16 nov 2017
Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute arbitrary code in the context of the current user
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra: JIT - 'Lowerer::LowerBoundCheck' Incorrect Integer Overflow Check
CVE-2017-11861doswindows16 nov 2017
Microsoft Edge in Windows 10 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker t
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Type Confusion with switch Statements
CVE-2017-11811doswindows16 nov 2017
ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra: JIT - 'OP_Memset' Type Confusion
CVE-2017-11873doswindows16 nov 2017
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709
35RISCO
abrir
Exploit-DB
Vonage VDV23 - Cross-Site Scripting
CVE-2017-16843webappshardware16 nov 2017
Vonage VDV-23 115 3.2.11-0.9.40 devices have stored XSS via the NewKeyword or NewDomain field to /goform/RgParentalBasic
23RISCO
abrir
Exploit-DB
LanSweeper 6.0.100.75 - Cross-Site Scripting
CVE-2017-16841webappsaspx16 nov 2017
LanSweeper 6.0.100.75 has XSS via the description parameter to /Calendar/CalendarActions.aspx.
23RISCO
abrir
Exploit-DBVexDay Proof
Zeta Components Mail 1.8.1 - Remote Code Execution
CVE-2017-15806webappsphp16 nov 2017
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the s
28RISCO
abrir
Exploit-DB
CommuniGatePro 6.1.16 - Cross-Site Scripting
CVE-2017-16962webappsmultiple15 nov 2017
The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities vi
23RISCO
abrir
Exploit-DB
PSFTPd Windows FTP Server 10.0.4 Build 729 - Log Injection / Use-After-Free
CVE-2017-15270doswindows14 nov 2017
The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) f
23RISCO
abrir
Exploit-DB
PSFTPd Windows FTP Server 10.0.4 Build 729 - Log Injection / Use-After-Free
CVE-2017-15271doswindows14 nov 2017
A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729. This issue could be
23RISCO
abrir
Exploit-DBVexDay Proof
D-Link DIR-605L < 2.08 - Denial of Service
CVE-2017-9675doshardware14 nov 2017
On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot.
28RISCO
abrir
Exploit-DBVexDay Proof
Kirby CMS < 2.5.7 - Cross-Site Scripting
CVE-2017-16807webappsphp13 nov 2017
A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exist
23RISCO
abrir
Exploit-DB
Ulterius Server < 1.9.5.0 - Directory Traversal
CVE-2017-16806remotewindows13 nov 2017
The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory
60RISCO
abrir
Exploit-DB
IKARUS anti.virus 2.16.7 - 'ntguard_x64' Local Privilege Escalation
CVE-2017-14961localwindows_x86-6413 nov 2017
In IKARUS anti.virus 2.16.7, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating
23RISCO
abrir
Exploit-DB
Web Viewer 1.0.0.193 (Samsung SRN-1670D) - Unrestricted File Upload
CVE-2017-16524webappsphp13 nov 2017
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_u
50RISCO
abrir
Exploit-DBVexDay Proof
MyBB 1.8.13 - Cross-Site Scripting
CVE-2017-16781webappsphp11 nov 2017
The installer in MyBB before 1.8.13 has XSS.
23RISCO
abrir
Exploit-DBVexDay Proof
MyBB 1.8.13 - Remote Code Execution
CVE-2017-16780webappsphp11 nov 2017
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration fi
23RISCO
abrir
Exploit-DBVexDay Proof
Symantec Endpoint Protection 12.1 - Tamper-Protection Bypass
CVE-2017-6331localwindows10 nov 2017
Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a
23RISCO
abrir
Exploit-DBVexDay Proof
PHP 7.1.8 - Heap Buffer Overflow
CVE-2017-16642dosmultiple09 nov 2017
In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian hand
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 - 'jscript!JsErrorToString' Use-After-Free
CVE-2017-11810doswindows09 nov 2017
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Window
35RISCO
abrir
Exploit-DB
ManageEngine Applications Manager 13 - SQL Injection
CVE-2017-16542webappswindows07 nov 2017
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name param
23RISCO
abrir
Exploit-DB
ManageEngine Applications Manager 13 - SQL Injection
CVE-2017-16543webappswindows07 nov 2017
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated
23RISCO
abrir
Exploit-DB
Ametys CMS 4.0.2 - Password Reset
CVE-2017-16935webappsphp07 nov 2017
Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to
23RISCO
abrir
Exploit-DB
Linux Kernel 4.13 (Ubuntu 17.10) - 'waitid()' SMEP/SMAP/Chrome Sandbox Privilege Escalation
CVE-2017-5123locallinux06 nov 2017
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RISCO
abrir
anteriorpágina 123 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.