Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'TryUndeleteProperty' Incorrect Usage (Denial of Service)
CVE-2017-8635doswindows17 ago 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge 40.15063.0.0 Chakra - Incorrect JIT Optimization with TypedArray Setter #3
CVE-2017-8601doswindows17 ago 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'InterpreterStackFrame::ProcessLinkFailedAsmJsModule' Incorrect Usage of 'PushPopFrameHelper' (Denial of Service)
CVE-2017-8646doswindows17 ago 2017
Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in t
35RISCO
abrir
Exploit-DB
Microsoft Edge Chakra - Heap Buffer Overflow
CVE-2017-8636doswindows17 ago 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JavascriptArray::ConcatArgs' Type Confusion
CVE-2017-8634doswindows17 ago 2017
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Incorrect JIT Optimization with TypedArray Setter #2
CVE-2017-8548doswindows17 ago 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain
35RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Invoke Accesses Trait Out-of-Bounds
CVE-2017-3106doswindows17 ago 2017
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF fil
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'EmitNew' Integer Overflow
CVE-2017-8636doswindows17 ago 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'PreVisitCatch' Missing Call
CVE-2017-8656doswindows17 ago 2017
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Uninitialized Arguments (2)
CVE-2017-8670doswindows17 ago 2017
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code
35RISCO
abrir
Exploit-DB
Microsoft Edge Chakra - Buffer Overflow
CVE-2017-8636doswindows17 ago 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - Out-of-Bounds Access when Fetching Source
CVE-2017-8657doswindows17 ago 2017
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'InterpreterStackFrame::ProcessLinkFailedAsmJsModule' Incorrectly Re-parses
CVE-2017-8645doswindows17 ago 2017
Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in t
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Uninitialized Arguments (1)
CVE-2017-8640doswindows17 ago 2017
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary cod
35RISCO
abrir
Exploit-DB
Microsoft Edge Chakra - 'chakra!Js::GlobalObject' Integer overflow
CVE-2017-8641doswindows17 ago 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JavascriptFunction::EntryCall' Fails to Handle 'CallInfo' Properly
CVE-2017-8671doswindows17 ago 2017
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
35RISCO
abrir
Exploit-DB
Microsoft Edge Chakra - NULL Pointer Dereference
CVE-2017-8636doswindows17 ago 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RISCO
abrir
Exploit-DB
Apple macOS Sierra 10.12.3 - 'IOFireWireFamily-null-deref' FireWire Port Denial of Service
CVE-2017-2388dosmacos16 ago 2017
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireF
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge 38.14393.1066.0 - 'CInputDateTimeScrollerElement::_SelectValueInternal' Out-of-Bounds Read
CVE-2017-8644doswindows16 ago 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose in
28RISCO
abrir
Exploit-DB
Quali CloudShell 7.1.0.6508 (Patch 6) - Persistent Cross-Site Scripting
CVE-2017-9767webappswindows14 ago 2017
Multiple cross-site scripting (XSS) vulnerabilities in Quali CloudShell before 8 allow remote authenticated users to inj
23RISCO
abrir
Exploit-DBVexDay Proof
Xamarin Studio for Mac 6.2.1 (build 3) / 6.3 (build 863) - Local Privilege Escalation
CVE-2017-8665localmacos14 ago 2017
The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel < 4.4.0-83 / < 4.8.0-58 (Ubuntu 14.04/16.04) - Local Privilege Escalation (KASLR / SMEP)
CVE-2017-1000112locallinux13 ago 2017
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge 38.14393.1066.0 - 'textarea.defaultValue' Memory Disclosure
CVE-2017-8652doswindows_x86-6410 ago 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose in
28RISCO
abrir
Exploit-DB
Red-Gate SQL Monitor < 3.10 / 4.2 - Authentication Bypass
CVE-2015-9098webappswindows10 ago 2017
In Redgate SQL Monitor before 3.10 and 4.x before 4.2, a remote attacker can gain unauthenticated access to the Base Mon
28RISCO
abrir
Exploit-DB
NoMachine 5.3.9 - Local Privilege Escalation
CVE-2017-12763localosx09 ago 2017
An unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privil
23RISCO
abrir
Exploit-DBVexDay Proof
Symantec Messaging Gateway < 10.6.3-267 - Cross-Site Request Forgery
CVE-2017-6328webappsmultiple09 ago 2017
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one
23RISCO
abrir
Exploit-DB
Android Bluetooth - 'Blueborne' Information Leak (1)
CVE-2017-0781remoteandroid09 ago 2017
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RISCO
abrir
Exploit-DBVexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
CVE-2017-11153webappshardware08 ago 2017
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allo
28RISCO
abrir
Exploit-DBVexDay Proof
Unitrends UEB 9.1 - Privilege Escalation
CVE-2017-12479webappsphp08 ago 2017
It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR env
28RISCO
abrir
Exploit-DBVexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
CVE-2017-11154webappshardware08 ago 2017
Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-296
23RISCO
abrir
anteriorpágina 133 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.