Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
Splunk Enterprise - Information Disclosure
CVE-2017-560731 mar 2017
Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3
23RISCO
abrir
Exploit-DB
Apple macOS/IOS 10.12.2 (16C67) - 'mach_msg' Heap Overflow
CVE-2017-245630 mar 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISCO
abrir
Exploit-DB
Sync Breeze Enterprise 9.5.16 - 'Import Command' Local Buffer Overflow
CVE-2017-731029 mar 2017
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9
50RISCO
abrir
Exploit-DB
MikroTik RouterBoard 6.38.5 - Denial of Service
CVE-2017-728528 mar 2017
A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remot
28RISCO
abrir
Exploit-DB
Intermec PM43 Industrial Printer - Local Privilege Escalation
CVE-2017-567128 mar 2017
Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x befo
23RISCO
abrir
Exploit-DB
Nuxeo 6.0/7.1/7.2/7.3 - Remote Code Execution (Metasploit)
CVE-2017-586927 mar 2017
Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote auth
35RISCO
abrir
Exploit-DB
Apple Safari - Out-of-Bounds Read when Calling Bound Function
CVE-2017-244727 mar 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISCO
abrir
Exploit-DB
EyesOfNetwork (EON) 5.0 - SQL Injection
CVE-2017-608827 mar 2017
Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to ex
23RISCO
abrir
Exploit-DB
EyesOfNetwork (EON) 5.0 - Remote Code Execution
CVE-2017-608727 mar 2017
EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacte
23RISCO
abrir
Exploit-DB
QNAP QTS < 4.2.4 - Domain Privilege Escalation
CVE-2017-522727 mar 2017
QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by
23RISCO
abrir
Exploit-DB
Apple Safari - 'DateTimeFormat.format' Type Confusion
CVE-2017-244627 mar 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISCO
abrir
Exploit-DB
Samba 4.5.2 - Symlink Race Permits Opening Files Outside Share Directory
CVE-2017-261927 mar 2017
Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access
28RISCO
abrir
Exploit-DB
Microsoft IIS 6.0 - WebDAV 'ScStoragePathFromUrl' Remote Buffer Overflow
CVE-2017-7269CRITICALsob ataque27 mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
Exploit-DB
Apple Safari - Builtin JavaScript Allows Function.caller to be Used in Strict Mode
CVE-2017-244627 mar 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISCO
abrir
Exploit-DB
D-Link DCS-936L Network Camera - Cross-Site Request Forgery
CVE-2017-785126 mar 2017
D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the devi
23RISCO
abrir
Exploit-DB
Fortinet FortiClient 5.2.3 (Windows 10 x64 Pre-Anniversary) - Local Privilege Escalation
CVE-2015-573625 mar 2017
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel
23RISCO
abrir
Exploit-DB
Fortinet FortiClient 5.2.3 (Windows 10 x64 Post-Anniversary) - Local Privilege Escalation
CVE-2015-573625 mar 2017
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel
23RISCO
abrir
Exploit-DB
Miele Professional PG 8528 - Directory Traversal
CVE-2017-724024 mar 2017
An issue was discovered on Miele Professional PST10 devices. The corresponding embedded webserver "PST10 WebServer" typi
28RISCO
abrir
Exploit-DB
Netgear WNR2000v5 - 'hidden_lang_avi' Remote Stack Overflow (Metasploit)
CVE-2016-10174CRITICALsob ataque24 mar 2017
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cg
100RISCO
abrir
Exploit-DB
Linux Kernel 3.11 < 4.8 0 - 'SO_SNDBUFFORCE' / 'SO_RCVBUFFORCE' Local Privilege Escalation
CVE-2016-979322 mar 2017
The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbu
23RISCO
abrir
Exploit-DB
Microsoft Windows - Uniscribe Font Processing Multiple Heap Out-of-Bounds and Wild Reads (MS17-011)
CVE-2017-011320 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RISCO
abrir
Exploit-DB
Microsoft Windows - Uniscribe Font Processing Out-of-Bounds Read in usp10!otlChainRuleSetTable::rule (MS17-011)
CVE-2017-008520 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RISCO
abrir
Exploit-DB
Microsoft Windows - Uniscribe Font Processing Heap Out-of-Bounds Write in 'USP10!UpdateGlyphFlags' (MS17-011)
CVE-2017-008920 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
35RISCO
abrir
Exploit-DB
Microsoft Internet Explorer 11 - 'textarea.defaultValue' Memory Disclosure (MS17-006)
CVE-2017-0059MEDIUMsob ataque20 mar 2017
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via
75RISCO
abrir
Exploit-DB
ExtraPuTTY 0.29-RC2 - Denial of Service
CVE-2017-718320 mar 2017
The TFTP server in ExtraPuTTY 0.30 and earlier allows remote attackers to cause a denial of service (crash) via a large
23RISCO
abrir
Exploit-DB
Microsoft Windows - Uniscribe Font Processing Multiple Heap Out-of-Bounds and Wild Reads (MS17-011)
CVE-2017-011820 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
28RISCO
abrir
Exploit-DB
Microsoft Windows - 'USP10!otlList::insertAt' Uniscribe Font Processing Heap Buffer Overflow (MS17-011)
CVE-2017-010820 mar 2017
The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 20
35RISCO
abrir
Exploit-DB
Microsoft GDI+ - 'gdiplus!GetRECTSForPlayback' Out-of-Bounds Read (MS17-013)
CVE-2017-006020 mar 2017
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
28RISCO
abrir
Exploit-DB
D-Link DGS-1510 - Multiple Vulnerabilities
CVE-2017-620620 mar 2017
D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devi
28RISCO
abrir
Exploit-DB
Microsoft Windows - Uniscribe Font Processing Heap Out-of-Bounds Read/Write in 'USP10!AssignGlyphTypes' (MS17-011)
CVE-2017-008420 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
35RISCO
abrir
anteriorpágina 142 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.