Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
dnaLIMS DNA Sequencing - Directory Traversal / Session Hijacking / Cross-Site Scripting
CVE-2017-652910 mar 2017
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to session hijacking by guessing the UID pa
23RISCO
abrir
Exploit-DB
Kinsey Infor/Lawson / ESBUS - SQL Injection
CVE-2017-655010 mar 2017
Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitra
23RISCO
abrir
Exploit-DB
dnaLIMS DNA Sequencing - Directory Traversal / Session Hijacking / Cross-Site Scripting
CVE-2017-652810 mar 2017
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/
23RISCO
abrir
Exploit-DB
Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 - Denial of Service
CVE-2017-655209 mar 2017
Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing
23RISCO
abrir
Exploit-DB
Wireless IP Camera (P2P) WIFICAM - Remote Code Execution
CVE-2017-822508 mar 2017
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An
28RISCO
abrir
Exploit-DB
ASUSWRT RT-AC53 (3.0.0.4.380.6038) - Session Stealing
CVE-2017-654908 mar 2017
Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W
23RISCO
abrir
Exploit-DB
Wireless IP Camera (P2P) WIFICAM - Remote Code Execution
CVE-2017-822308 mar 2017
On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streamin
23RISCO
abrir
Exploit-DB
Wireless IP Camera (P2P) WIFICAM - Remote Code Execution
CVE-2017-822408 mar 2017
Wireless IP Camera (P2P) WIFICAM devices have a backdoor root account that can be accessed with TELNET.
23RISCO
abrir
Exploit-DB
ASUSWRT RT-AC53 (3.0.0.4.380.6038) - Cross-Site Scripting
CVE-2017-654708 mar 2017
Cross-site scripting (XSS) vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC
23RISCO
abrir
Exploit-DB
Wireless IP Camera (P2P) WIFICAM - Remote Code Execution
CVE-2017-822108 mar 2017
Wireless IP Camera (P2P) WIFICAM devices rely on a cleartext UDP tunnel protocol (aka the Cloud feature) for communicati
23RISCO
abrir
Exploit-DB
Wireless IP Camera (P2P) WIFICAM - Remote Code Execution
CVE-2017-822208 mar 2017
Wireless IP Camera (P2P) WIFICAM devices have an "Apple Production IOS Push Services" private RSA key and certificate st
23RISCO
abrir
Exploit-DB
ASUSWRT RT-AC53 (3.0.0.4.380.6038) - Remote Code Execution
CVE-2017-654808 mar 2017
Buffer overflows in networkmap on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC
28RISCO
abrir
Exploit-DB
Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code Execution
CVE-2017-5638CRITICALsob ataqueransomware07 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
Exploit-DB
USBPcap 1.1.0.0 (WireShark 2.2.5) - Local Privilege Escalation
CVE-2017-617807 mar 2017
The IofCallDriver function in USBPcap 1.1.0.0 allows local users to gain privileges via a crafted 0x00090028 IOCTL call,
23RISCO
abrir
Exploit-DB
iBall Baton 150M Wireless Router - Authentication Bypass
CVE-2017-655807 mar 2017
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vuln
28RISCO
abrir
Exploit-DB
Azure Data Expert Ultimate 2.2.16 - Remote Buffer Overflow
CVE-2017-650607 mar 2017
In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leadi
28RISCO
abrir
Exploit-DB
Evostream Media Server 1.7.1 (x64) - Denial of Service
CVE-2017-642707 mar 2017
A Buffer Overflow was discovered in EvoStream Media Server 1.7.1. A crafted HTTP request with a malicious header will ca
23RISCO
abrir
Exploit-DB
Deluge Web UI 1.3.13 - Cross-Site Request Forgery
CVE-2017-717806 mar 2017
CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted p
23RISCO
abrir
Exploit-DB
MikroTik Router - ARP Table OverFlow Denial Of Service
CVE-2017-644405 mar 2017
The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast netw
28RISCO
abrir
Exploit-DB
FTPShell Client 6.53 - Remote Buffer Overflow
CVE-2017-646504 mar 2017
Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP serv
50RISCO
abrir
Exploit-DB
Multiple WordPress Plugins - Arbitrary File Upload
CVE-2017-100200203 mar 2017
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http:
28RISCO
abrir
Exploit-DB
Multiple WordPress Plugins - Arbitrary File Upload
CVE-2017-100200003 mar 2017
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-
28RISCO
abrir
Exploit-DB
WordPress Core < 4.7.1 - Username Enumeration
CVE-2017-548703 mar 2017
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISCO
abrir
Exploit-DB
Multiple WordPress Plugins - Arbitrary File Upload
CVE-2017-100200303 mar 2017
Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulner
28RISCO
abrir
Exploit-DB
Multiple WordPress Plugins - Arbitrary File Upload
CVE-2017-100200103 mar 2017
Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS so
28RISCO
abrir
Exploit-DB
Multiple WordPress Plugins - Arbitrary File Upload
CVE-2017-610403 mar 2017
Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.
23RISCO
abrir
Exploit-DB
EPSON TMNet WebConfig 1.00 - Cross-Site Scripting
CVE-2017-644303 mar 2017
Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web s
23RISCO
abrir
Exploit-DB
Conext ComBox 865-1058 - Denial of Service
CVE-2017-601902 mar 2017
An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830
35RISCO
abrir
Exploit-DB
Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scripting
CVE-2016-852701 mar 2017
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). Th
43RISCO
abrir
Exploit-DB
Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scripting
CVE-2016-852601 mar 2017
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a
23RISCO
abrir
anteriorpágina 145 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.