Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
libvorbis 1.3.5 - Multiple Vulnerabilities
CVE-2017-1133331 jul 2017
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial
23RISCO
abrir
Exploit-DB
DivFix++ 0.34 - Denial of Service
CVE-2017-1133031 jul 2017
The DivFixppCore::avi_header_fix function in DivFix++Core.cpp in DivFix++ v0.34 allows remote attackers to cause a denia
23RISCO
abrir
Exploit-DB
Sound eXchange (SoX) 14.4.2 - Multiple Vulnerabilities
CVE-2017-1135931 jul 2017
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (d
23RISCO
abrir
Exploit-DB
Sound eXchange (SoX) 14.4.2 - Multiple Vulnerabilities
CVE-2017-1133231 jul 2017
The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (div
23RISCO
abrir
Exploit-DB
McAfee Security Scan Plus - Remote Command Execution
CVE-2017-389730 jul 2017
A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior
28RISCO
abrir
Exploit-DB
Jenkins < 1.650 - Java Deserialization
CVE-2016-079230 jul 2017
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex
60RISCO
abrir
Exploit-DB
LAME 3.99.5 - Multiple Vulnerabilities
CVE-2017-941228 jul 2017
The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of ser
23RISCO
abrir
Exploit-DB
SoundTouch 1.9.2 - Multiple Vulnerabilities
CVE-2017-926028 jul 2017
The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attack
23RISCO
abrir
Exploit-DB
SoundTouch 1.9.2 - Multiple Vulnerabilities
CVE-2017-925928 jul 2017
The TDStretch::acceptNewOverlapLength function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote atta
23RISCO
abrir
Exploit-DB
libjpeg-turbo 1.5.1 - Denial of Service
CVE-2017-961428 jul 2017
The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service
23RISCO
abrir
Exploit-DB
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
CVE-2017-313328 jul 2017
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthor
43RISCO
abrir
Exploit-DB
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
CVE-2017-313228 jul 2017
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthor
38RISCO
abrir
Exploit-DB
SoundTouch 1.9.2 - Multiple Vulnerabilities
CVE-2017-925828 jul 2017
The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to
23RISCO
abrir
Exploit-DB
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
CVE-2017-313128 jul 2017
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to exec
38RISCO
abrir
Exploit-DB
GNU libiberty - Buffer Overflow
CVE-2016-222627 jul 2017
Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary
23RISCO
abrir
Exploit-DB
AudioCoder 0.8.46 - Local Buffer Overflow (SEH)
CVE-2017-887026 jul 2017
Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RISCO
abrir
Exploit-DB
Microsoft Windows - '.LNK' Shortcut File Code Execution (Metasploit)
CVE-2017-8464HIGHsob ataque26 jul 2017
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISCO
abrir
Exploit-DB
WebKit JSC - 'DFG::ByteCodeParser::flush(InlineStackEntry* inlineStackEntry)' Incorrect Scope Register Handling
CVE-2017-701825 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir
Exploit-DB
WebKit JSC - 'ArgumentsEliminationPhase::transform' Incorrect LoadVarargs Handling
CVE-2017-705625 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir
Exploit-DB
WebKit JSC - 'JSObject::putInlineSlow' / 'JSValue::putToPrimitive' Universal Cross-Site Scripting
CVE-2017-703725 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir
Exploit-DB
WebKit JSC - 'JSArray::appendMemcpy' Uninitialized Memory Copy
CVE-2017-706425 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir
Exploit-DB
Nitro Pro PDF - Multiple Vulnerabilities
CVE-2017-795024 jul 2017
Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX
23RISCO
abrir
Exploit-DB
WebKit - 'WebCore::AccessibilityNodeObject::textUnderElement' Use-After-Free
CVE-2017-704824 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir
Exploit-DB
ManageEngine Desktop Central 10 Build 100087 - Remote Code Execution (Metasploit)
CVE-2017-1134624 jul 2017
Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors invo
35RISCO
abrir
Exploit-DB
vBulletin 5.1.2 < 5.1.9 - Unserialize Code Execution (Metasploit)
CVE-2015-780824 jul 2017
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RISCO
abrir
Exploit-DB
Microsoft Internet Explorer - 'mshtml.dll' Remote Code Execution (MS17-007)
CVE-2017-0037HIGHsob ataque24 jul 2017
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilde
93RISCO
abrir
Exploit-DB
Microsoft Internet Explorer - 'mshtml.dll' Remote Code Execution (MS17-007)
CVE-2017-0059MEDIUMsob ataque24 jul 2017
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via
75RISCO
abrir
Exploit-DB
Razer Synapse 2.20.15.1104 - rzpnk.sys ZwOpenProcess (Metasploit)
CVE-2017-976924 jul 2017
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpe
60RISCO
abrir
Exploit-DB
Linux Kernel - 'BadIRET' Local Privilege Escalation
CVE-2014-932224 jul 2017
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack S
23RISCO
abrir
Exploit-DB
WebKit - 'WebCore::Node::nextSibling' Use-After-Free
CVE-2017-703924 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir
anteriorpágina 129 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.