Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DB
SMSmaster - SQL Injection
CVE-2017-14842webappsphp26 set 2017
Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.
23RISCO
abrir
Exploit-DB
WordPress Plugin WPAMS - SQL Injection
CVE-2017-14847webappsphp26 set 2017
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
23RISCO
abrir
Exploit-DB
WordPress Plugin WPGYM - SQL Injection
CVE-2017-14844webappsphp26 set 2017
Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
23RISCO
abrir
Exploit-DB
Linux Kernel 3.10.0-514.21.2.el7.x86_64 / 3.10.0-514.26.1.el7.x86_64 (CentOS 7) - SUID Position Independent Executable 'PIE' Local Privilege Escalation
CVE-2017-1000253HIGHsob ataqueransomwarelocallinux26 set 2017
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb7
76RISCO
abrir
Exploit-DB
WordPress Plugin WPCHURCH - SQL Injection
CVE-2017-14845webappsphp26 set 2017
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
23RISCO
abrir
Exploit-DB
WordPress Plugin Hospital Management System - SQL Injection
CVE-2017-14846webappsphp26 set 2017
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Read in applyToRange
CVE-2017-11282dosmultiple25 set 2017
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation co
35RISCO
abrir
Exploit-DB
Oracle 9i XDB 9.2.0.1 - HTTP PASS Buffer Overflow
CVE-2003-0727remotewindows25 set 2017
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RISCO
abrir
Exploit-DBVexDay Proof
Supervisor 3.0a1 < 3.3.2 - XML-RPC (Authenticated) Remote Code Execution (Metasploit)
CVE-2017-11610remotelinux25 set 2017
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Write in MP4 Edge Processing
CVE-2017-11281dosmultiple25 set 2017
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploita
35RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Memory Read in MP4 Parsing
CVE-2017-11281dosmultiple25 set 2017
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploita
35RISCO
abrir
Exploit-DBVexDay Proof
Apple iOS 10.2 - Broadcom Out-of-Bounds Write when Handling 802.11k Neighbor Report Response
CVE-2017-11120remoteios25 set 2017
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor repo
23RISCO
abrir
Exploit-DBVexDay Proof
CyberLink LabelPrint < 2.5 - Local Buffer Overflow (SEH Unicode)
CVE-2017-14627localwindows23 set 2017
Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) au
43RISCO
abrir
Exploit-DB
Claydip Airbnb Clone 1.0 - Arbitrary File Upload
CVE-2017-14704webappsphp22 set 2017
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Larav
23RISCO
abrir
Exploit-DB
Cash Back Comparison Script 1.0 - SQL Injection
CVE-2017-14703webappsphp22 set 2017
SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'Parser::ParseCatch' Does Not Handle 'eval()' (Denial of Service)
CVE-2017-11764doswindows21 set 2017
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - Chakra Incorrectly Parses Object Patterns
CVE-2017-8729doswindows21 set 2017
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RISCO
abrir
Exploit-DB
Linux Kernel < 4.13.1 - BlueTooth Buffer Overflow (PoC)
CVE-2017-1000251doslinux21 set 2017
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and includ
28RISCO
abrir
Exploit-DB
ERS Data System 1.8.1 - Java Deserialization
CVE-2017-14702remotewindows21 set 2017
ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.Upd
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JavascriptFunction::ReparseAsmJsModule' Incorrectly Re-parses
CVE-2017-8755doswindows21 set 2017
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Deferred Parsing Makes Wrong Scopes
CVE-2017-8740doswindows21 set 2017
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RISCO
abrir
Exploit-DB
PHPMyFAQ 2.9.8 - Cross-Site Scripting (1)
CVE-2017-14618webappsphp21 set 2017
Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject
23RISCO
abrir
Exploit-DB
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1)
CVE-2017-12615HIGHsob ataqueransomwarewebappswindows20 set 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
Exploit-DB
Android Bluetooth - 'Blueborne' Information Leak (2)
CVE-2017-0785remoteandroid20 set 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge 38.14393.1066.0 - Memory Corruption with Partial Page Loading
CVE-2017-8731doswindows19 set 2017
Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the
35RISCO
abrir
Exploit-DB
HPE < 7.2 - Java Deserialization
CVE-2016-4372remotejava19 set 2017
HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01,
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge 38.14393.1066.0 - 'COptionsCollectionCacheItem::GetAt' Out-of-Bounds Read
CVE-2017-8734doswindows19 set 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arb
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiDoBanding' Stack Memory Disclosure
CVE-2017-8687doswindows18 set 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' '.TTF' Font Processing Out-of-Bounds Reads/Writes with Malformed 'fpgm' table 'win32k!bGeneratePath' (Denial of Service)
CVE-2017-8682doswindows18 set 2017
Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold a
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' '.TTF' Font Processing Out-of-Bounds Read with Malformed 'glyf' Table 'win32k!fsc_CalcGrayRow' (Denial of Service)
CVE-2017-8683doswindows18 set 2017
Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold a
28RISCO
abrir
anteriorpágina 129 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.