Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.901exploits catalogados
32.161CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
WebKit JSC - arrayProtoFuncSplice does not Initialize all Indices
CVE-2017-698016 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RISCO
abrir
Exploit-DB
WebKit JSC - JIT Optimization Check Failed in IntegerCheckCombiningPhase::handleBlock
CVE-2017-254716 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
28RISCO
abrir
Exploit-DB
WebKit JSC - JSGlobalObject::haveABadTime Causes Type Confusions
CVE-2017-700516 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RISCO
abrir
Exploit-DB
Google Chrome - V8 Private Property Arbitrary Code Execution
CVE-2016-965114 jun 2017
A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a
28RISCO
abrir
Exploit-DB
HP PageWide Printers / HP OfficeJet Pro Printers (OfficeJet Pro 8210) - Arbitrary Code Execution
CVE-2017-274114 jun 2017
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RISCO
abrir
Exploit-DB
Sudo 1.8.20 - 'get_process_ttyname()' Local Privilege Escalation
CVE-2017-100036714 jun 2017
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RISCO
abrir
Exploit-DB
KBVault MySQL 0.16a - Arbitrary File Upload
CVE-2017-960214 jun 2017
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-man
23RISCO
abrir
Exploit-DB
GStreamer gst-plugins-bad Plugin - NULL Pointer Dereference
CVE-2016-981312 jun 2017
The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of ser
23RISCO
abrir
Exploit-DB
WordPress Plugin WP Jobs < 1.5 - SQL Injection
CVE-2017-960311 jun 2017
SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitra
23RISCO
abrir
Exploit-DB
VMware vSphere Data Protection 5.x/6.x - Java Deserialization
CVE-2017-491410 jun 2017
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of th
23RISCO
abrir
Exploit-DB
libquicktime 1.2.4 - Denial of Service
CVE-2017-912409 jun 2017
The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NU
23RISCO
abrir
Exploit-DB
libquicktime 1.2.4 - Denial of Service
CVE-2017-912309 jun 2017
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of se
23RISCO
abrir
Exploit-DB
libquicktime 1.2.4 - Denial of Service
CVE-2017-912809 jun 2017
The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of
23RISCO
abrir
Exploit-DB
libquicktime 1.2.4 - Denial of Service
CVE-2017-912609 jun 2017
The quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of serv
23RISCO
abrir
Exploit-DB
libquicktime 1.2.4 - Denial of Service
CVE-2017-912509 jun 2017
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of se
23RISCO
abrir
Exploit-DB
libquicktime 1.2.4 - Denial of Service
CVE-2017-912709 jun 2017
The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a deni
23RISCO
abrir
Exploit-DB
Apple macOS 10.12.3 / iOS < 10.3.2 - Userspace Entitlement Checking Race Condition
CVE-2017-700409 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The
23RISCO
abrir
Exploit-DB
Apple macOS - Disk Arbitration Daemon Race Condition
CVE-2017-253309 jun 2017
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "DiskArbitra
23RISCO
abrir
Exploit-DB
libcroco 0.6.12 - Denial of Service
CVE-2017-887109 jun 2017
The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial o
28RISCO
abrir
Exploit-DB
libquicktime 1.2.4 - Denial of Service
CVE-2017-912209 jun 2017
The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (i
23RISCO
abrir
Exploit-DB
Craft CMS 2.6 - Cross-Site Scripting
CVE-2017-951608 jun 2017
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
23RISCO
abrir
Exploit-DB
IDERA Uptime Monitor 7.8 - Multiple Vulnerabilities
CVE-2017-1147008 jun 2017
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the
23RISCO
abrir
Exploit-DB
IDERA Uptime Monitor 7.8 - Multiple Vulnerabilities
CVE-2017-1147108 jun 2017
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the el
23RISCO
abrir
Exploit-DB
IDERA Uptime Monitor 7.8 - Multiple Vulnerabilities
CVE-2017-1146908 jun 2017
get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter.
23RISCO
abrir
Exploit-DB
Net Monitor for Employees Pro < 5.3.4 - Unquoted Service Path Privilege Escalation
CVE-2017-718008 jun 2017
Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its
23RISCO
abrir
Exploit-DB
VMware Workstation 12 Pro - Denial of Service
CVE-2017-491608 jun 2017
VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Succes
23RISCO
abrir
Exploit-DB
Linux Kernel < 4.10.13 - 'keyctl_set_reqkey_keyring' Local Denial of Service
CVE-2017-747207 jun 2017
The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumptio
23RISCO
abrir
Exploit-DB
Linux Kernel - 'ping' Local Denial of Service
CVE-2017-267107 jun 2017
The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock a
23RISCO
abrir
Exploit-DB
Artifex MuPDF - Null Pointer Dereference
CVE-2017-599107 jun 2017
An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function i
28RISCO
abrir
Exploit-DB
PuTTY < 0.68 - 'ssh_agent_channel_data' Integer Overflow Heap Corruption
CVE-2017-654207 jun 2017
The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large
28RISCO
abrir
anteriorpágina 134 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.