Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DBVexDay Proof
OpenVPN 2.4.0 - Denial of Service
CVE-2017-7478dosmultiple11 mai 2017
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft IIS - WebDav 'ScStoragePathFromUrl' Remote Overflow (Metasploit)
CVE-2017-7269CRITICALsob ataqueremotewindows11 mai 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
Exploit-DB
Vanilla Forums < 2.3 - Remote Code Execution
CVE-2016-10073remotephp11 mai 2017
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the emai
60RISCO
abrir
Exploit-DB
MiniUPnP MiniUPnPc < 2.0 - Remote Denial of Service
CVE-2017-8798dosmultiple11 mai 2017
Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of s
28RISCO
abrir
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0144HIGHsob ataqueransomwareremotewindows_x86-6410 mai 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0146HIGHsob ataqueransomwareremotewindows_x86-6410 mai 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0145HIGHsob ataqueransomwareremotewindows_x86-6410 mai 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DBVexDay Proof
SAP SAPCAR 721.510 - Heap Buffer Overflow
CVE-2017-8852doslinux10 mai 2017
SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file
23RISCO
abrir
Exploit-DB
CMS Made Simple 2.1.6 - Multiple Vulnerabilities
CVE-2017-8912HIGHwebappsphp10 mai 2017
CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code para
41RISCO
abrir
Exploit-DB
Cisco DPC3928 Router - Arbitrary File Disclosure
CVE-2017-11502webappshardware10 mai 2017
Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /..
23RISCO
abrir
Exploit-DB
Intel Active Management Technology - System Privileges
CVE-2017-5689CRITICALsob ataqueremotemultiple10 mai 2017
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RISCO
abrir
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0147HIGHsob ataqueransomwareremotewindows_x86-6410 mai 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0148HIGHsob ataqueransomwareremotewindows_x86-6410 mai 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0143HIGHsob ataqueransomwareremotewindows_x86-6410 mai 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DB
wolfSSL 3.10.2 - x509 Certificate Text Parsing Off-by-One
CVE-2017-2800HIGHdosmultiple09 mai 2017
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting
41RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Security Essentials / SCEP (Microsoft Windows 8/8.1/10 / Windows Server) - 'MsMpEng' Remote Type Confusion
CVE-2017-0290remotewindows09 mai 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
45RISCO
abrir
Exploit-DB
Personify360 7.5.2/7.6.1 - Improper Database Schema Access Restrictions
CVE-2017-7314webappsaspx09 mai 2017
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating
23RISCO
abrir
Exploit-DB
Personify360 7.5.2/7.6.1 - Improper Access Restrictions
CVE-2017-7312webappsaspx09 mai 2017
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add
23RISCO
abrir
Exploit-DBVexDay Proof
Gemalto SmartDiag Diagnosis Tool < 2.5 - Local Buffer Overflow (SEH)
CVE-2017-6953localwindows08 mai 2017
Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card
23RISCO
abrir
Exploit-DBVexDay Proof
MediaCoder 0.8.48.5888 - Local Buffer Overflow (SEH)
CVE-2017-8869localwindows08 mai 2017
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RISCO
abrir
Exploit-DB
RPCBind / libtirpc - Denial of Service
CVE-2017-8779doslinux08 mai 2017
rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider t
60RISCO
abrir
Exploit-DB
ViMbAdmin 3.0.15 - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2017-6086webappsphp05 mai 2017
Multiple cross-site request forgery (CSRF) vulnerabilities in the addAction and purgeAction functions in ViMbAdmin 3.0.1
23RISCO
abrir
Exploit-DB
Technicolor DPC3928SL - SNMP Authentication Bypass
CVE-2017-5135remotehardware05 mai 2017
Certain Technicolor devices have an SNMP access-control bypass, possibly involving an ISP customization in some cases. T
28RISCO
abrir
Exploit-DB
CloudBees Jenkins 2.32.1 - Java Deserialization
CVE-2017-1000353CRITICALsob ataquedosjava05 mai 2017
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RISCO
abrir
Exploit-DBVexDay Proof
Apple Safari 10.0.3 - 'JSC::CachedCall' Use-After-Free
CVE-2017-2491remotemacos04 mai 2017
Use after free vulnerability in the String.replace method JavaScriptCore in Apple Safari in iOS before 10.3 allows remot
23RISCO
abrir
Exploit-DB
WordPress Core < 4.7.4 - Unauthorized Password Reset
CVE-2017-8295webappslinux03 mai 2017
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for re
28RISCO
abrir
Exploit-DB
WordPress Core 4.6 - Remote Code Execution
CVE-2016-10033CRITICALsob ataquewebappslinux03 mai 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
Exploit-DBVexDay Proof
Ghostscript 9.21 - Type Confusion Arbitrary Command Execution (Metasploit)
CVE-2017-8291HIGHsob ataquelocallinux02 mai 2017
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISCO
abrir
Exploit-DBVexDay Proof
Tuleap Project Wiki 8.3 < 9.6.99.86 - Command Injection
CVE-2017-7981webappsphp01 mai 2017
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project W
28RISCO
abrir
Exploit-DBVexDay Proof
MySQL < 5.6.35 / < 5.7.17 - Integer Overflow
CVE-2017-3599dosmultiple01 mai 2017
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions t
45RISCO
abrir
anteriorpágina 144 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.