Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DB
Linux Kernel < 4.14.rc3 - Local Denial of Service
CVE-2017-14489doslinux02 out 2017
The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to
23RISCO
abrir
Exploit-DBVexDay Proof
Dnsmasq < 2.78 - 2-byte Heap Overflow
CVE-2017-14491dosmultiple02 out 2017
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut
45RISCO
abrir
Exploit-DB
OpenText Document Sciences xPression 4.5SP1 Patch 13 - 'documentId' SQL Injection
CVE-2017-14758webappsjsp02 out 2017
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might b
23RISCO
abrir
Exploit-DBVexDay Proof
Qmail SMTP - Bash Environment Variable Injection (Metasploit)
CVE-2014-6271CRITICALsob ataqueremotelinux02 out 2017
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Exploit-DBVexDay Proof
Dnsmasq < 2.78 - Lack of free() Denial of Service
CVE-2017-14495dosmultiple02 out 2017
Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote
45RISCO
abrir
Exploit-DB
phpCollab 2.5.1 - SQL Injection
CVE-2017-6089webappsphp02 out 2017
SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
Exploit-DBVexDay Proof
phpCollab 2.5.1 - Arbitrary File Upload
CVE-2017-6090webappsphp02 out 2017
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RISCO
abrir
Exploit-DBVexDay Proof
Dnsmasq < 2.78 - Information Leak
CVE-2017-14494dosmultiple02 out 2017
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vect
35RISCO
abrir
Exploit-DBVexDay Proof
Dnsmasq < 2.78 - Integer Underflow
CVE-2017-14496dosmultiple02 out 2017
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-su
35RISCO
abrir
Exploit-DBVexDay Proof
Dnsmasq < 2.78 - Heap Overflow
CVE-2017-14492dosmultiple02 out 2017
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut
45RISCO
abrir
Exploit-DBVexDay Proof
Dnsmasq < 2.78 - Stack Overflow
CVE-2017-14493dosmultiple02 out 2017
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execu
45RISCO
abrir
Exploit-DB
Microsoft Excel - OLE Arbitrary Code Execution
CVE-2017-0199HIGHsob ataqueransomwaredoswindows30 set 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
Exploit-DB
FileRun < 2017.09.18 - SQL Injection
CVE-2017-14738webappsphp29 set 2017
FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize in
23RISCO
abrir
Exploit-DB
WordPress Plugin WPHRM - SQL Injection
CVE-2017-14848webappsphp29 set 2017
WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.
23RISCO
abrir
Exploit-DB
Trend Micro OfficeScan 11.0/XG (12.0) - Memory Corruption
CVE-2017-14089doswindows29 set 2017
An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated u
23RISCO
abrir
Exploit-DB
ConverTo Video Downloader & Converter 1.4.1 - Arbitrary File Download
CVE-2017-15956webappsphp29 set 2017
ConverTo Video Downloader & Converter 1.4.1 allows Arbitrary File Download via the token parameter to download.php.
23RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - Private Key Disclosure
CVE-2017-14083webappsphp28 set 2017
A vulnerability in Trend Micro OfficeScan 11.0 and XG allows remote unauthenticated users who can access the system to d
23RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - Information Disclosure
CVE-2017-14085webappsphp28 set 2017
Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can acc
23RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - Code Execution / Memory Corruption
CVE-2017-14086webappswindows28 set 2017
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated u
23RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - 'Host' Header Injection
CVE-2017-14087webappsphp28 set 2017
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Ho
23RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - Man In The Middle Remote Code Execution
CVE-2017-14084remotewindows28 set 2017
A potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to e
28RISCO
abrir
Exploit-DB
Cisco Prime Collaboration Provisioning < 12.1 - Authentication Bypass / Remote Code Execution
CVE-2017-6622remotehardware27 set 2017
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote a
35RISCO
abrir
Exploit-DB
SmarterStats 11.3.6347 - Cross-Site Scripting
CVE-2017-14620webappsaspx27 set 2017
SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQu
23RISCO
abrir
Exploit-DB
LAquis SCADA 4.1.0.2385 - Directory Traversal (Metasploit)
CVE-2017-6020remotemultiple27 set 2017
Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237
23RISCO
abrir
Exploit-DB
Oracle WebLogic Server 10.3.6.0 - Java Deserialization Remote Code Execution
CVE-2015-4852CRITICALsob ataqueremotejava27 set 2017
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISCO
abrir
Exploit-DB
SMSmaster - SQL Injection
CVE-2017-14842webappsphp26 set 2017
Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.
23RISCO
abrir
Exploit-DB
Photo Fusion - Arbitrary File Upload
CVE-2017-14839webappsphp26 set 2017
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
23RISCO
abrir
Exploit-DB
Linux Kernel 3.10.0-514.21.2.el7.x86_64 / 3.10.0-514.26.1.el7.x86_64 (CentOS 7) - SUID Position Independent Executable 'PIE' Local Privilege Escalation
CVE-2017-1000253HIGHsob ataqueransomwarelocallinux26 set 2017
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb7
76RISCO
abrir
Exploit-DB
WordPress Plugin School Management System - SQL Injection
CVE-2017-14843webappsphp26 set 2017
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
23RISCO
abrir
Exploit-DB
WordPress Plugin WPCHURCH - SQL Injection
CVE-2017-14845webappsphp26 set 2017
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
23RISCO
abrir
anteriorpágina 128 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.