Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.183exploits catalogados
37.028CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DBVexDay Proof
Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
CVE-2017-8536doswindows29 mai 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
CVE-2017-8538doswindows29 mai 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
35RISCO
abrir
Exploit-DBVexDay Proof
Samba 3.5.0 < 4.4.14/4.5.10/4.6.4 - 'is_known_pipename()' Arbitrary Module Load (Metasploit)
CVE-2017-7494CRITICALsob ataqueransomwareremotelinux29 mai 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
CVE-2017-8535doswindows29 mai 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RISCO
abrir
Exploit-DBVexDay Proof
WebKit - 'enqueuePageshowEvent' / 'enqueuePopstateEvent' Universal Cross-Site Scripting
CVE-2017-2510webappsmultiple25 mai 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit / Safari 10.0.3(12602.4.8) - 'Editor::Command::execute' Universal Cross-Site Scripting
CVE-2017-2504webappsmultiple25 mai 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit / Safari 10.0.3(12602.4.8) - 'WebCore::FrameView::scheduleRelayout' Use-After-Free
CVE-2017-2514dosmultiple25 mai 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RISCO
abrir
Exploit-DB
Sophos Cyberoam - Cross-site scripting
CVE-2016-9834webappshardware25 mai 2017
An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Soph
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox < 53 - 'ConvolvePixel' Memory Disclosure
CVE-2017-5465dosmultiple25 mai 2017
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for other
28RISCO
abrir
Exploit-DBVexDay Proof
WebKit - 'FrameLoader::clear' Stealing Variables via Page Navigation
CVE-2017-2515webappsmultiple25 mai 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RISCO
abrir
Exploit-DBVexDay Proof
WebKit - 'ContainerNode::parserInsertBefore' Universal Cross-Site Scripting
CVE-2017-2508webappsmultiple25 mai 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox < 53 - 'gfxTextRun' Out-of-Bounds Read
CVE-2017-5447dosmultiple25 mai 2017
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitabl
28RISCO
abrir
Exploit-DBVexDay Proof
Samba 3.5.0 - Remote Code Execution
CVE-2017-7494CRITICALsob ataqueransomwareremotelinux24 mai 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS Kernel - Use-After-Free Due to Bad Locking in Unix Domain Socket File Descriptor Externalization
CVE-2017-2501dosmultiple23 mai 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS - 'CAMediaTimingFunctionBuiltin' NSKeyedArchiver Memory Corruption Due to Lack of Bounds Checking
CVE-2017-2527dosmultiple23 mai 2017
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "CoreAnimati
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS - Memory Corruption Due to Bad Bounds Checking in NSCharacterSet Coding for NSKeyedUnarchiver
CVE-2017-2522dosmultiple23 mai 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS - 'TIKeyboardLayout initWithCoder:' NSKeyedArchiver Heap Corruption Due to Rounding Error
CVE-2017-2524dosmultiple23 mai 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS - NSUnarchiver Heap Corruption Due to Lack of Bounds Checking in [NSBuiltinCharacterSet initWithCoder:]
CVE-2017-2523dosmultiple23 mai 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
28RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS - Lack of Bounds Checking in HIServices Custom CFObject Serialization Local Privilege Escalation
CVE-2017-6978dosmacos23 mai 2017
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Accessibili
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS - '32-bit syscall exit' Kernel Register Leak
CVE-2017-2509dosmacos22 mai 2017
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" com
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 4.11 - eBPF Verifier Log Leaks Lower Half of map Pointer
CVE-2017-9150doslinux22 mai 2017
The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value
23RISCO
abrir
Exploit-DBVexDay Proof
VMware Workstation for Linux 12.5.2 build-4638234 - ALSA Configuration Host Local Privilege Escalation
CVE-2017-4915locallinux22 mai 2017
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration fil
38RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS - 'stackshot' Raw Frame Pointers
CVE-2017-2516dosmacos22 mai 2017
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" com
23RISCO
abrir
Exploit-DBVexDay Proof
PlaySMS 1.4 - 'import.php' Remote Code Execution
CVE-2017-9101webappsphp21 mai 2017
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RISCO
abrir
Exploit-DB
KMCIS CaseAware - Cross-Site Scripting
CVE-2017-5631webappsphp20 mai 2017
An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr"
38RISCO
abrir
Exploit-DB
Secure Auditor 3.0 - Directory Traversal
CVE-2017-9024remotewindows20 mai 2017
Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Tra
28RISCO
abrir
Exploit-DB
Mantis Bug Tracker 1.3.10/2.3.0 - Cross-Site Request Forgery
CVE-2017-7620webappsphp20 mai 2017
MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequen
23RISCO
abrir
Exploit-DB
Tecnovision DLX Spot - SSH Backdoor Access
CVE-2017-12929remotemultiple19 mai 2017
Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users
28RISCO
abrir
Exploit-DB
SAP Business One for Android 1.2.3 - XML External Entity Injection
CVE-2016-6256webappsxml19 mai 2017
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML
23RISCO
abrir
Exploit-DB
Tecnovision DLX Spot - SSH Backdoor Access
CVE-2017-12930remotemultiple19 mai 2017
SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users
23RISCO
abrir
anteriorpágina 142 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.