Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DBVexDay Proof
Admidio 3.2.8 - Cross-Site Request Forgery
CVE-2017-8382webappsphp28 abr 2017
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user acc
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11.576.14393.0 - 'CStyleSheetArray::BuildListOfMatchedRules' Memory Corruption
CVE-2017-0202doswindows27 abr 2017
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerabi
35RISCO
abrir
Exploit-DBVexDay Proof
Apple Safari - Array concat Memory Corruption
CVE-2017-2464dosmultiple25 abr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISCO
abrir
Exploit-DB
LightDM (Ubuntu 16.04/16.10) - 'Guest Account' Local Privilege Escalation
CVE-2017-7358locallinux25 abr 2017
In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrar
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle VirtualBox Guest Additions 5.1.18 - Unprivileged Windows User-Mode Guest Code Double-Free
CVE-2017-3587dosmultiple25 abr 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Shared Folder). Supported ve
23RISCO
abrir
Exploit-DBVexDay Proof
HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusion
CVE-2017-5799webappsmultiple25 abr 2017
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP ve
28RISCO
abrir
Exploit-DB
Oracle PeopleSoft - 'PeopleSoftServiceListeningConnector' XML External Entity via DOCTYPE
CVE-2017-3548webappsxml25 abr 2017
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integratio
35RISCO
abrir
Exploit-DB
OpenText Documentum Content Server - dm_bp_transition.ebs docbase Method Arbitrary Code Execution
CVE-2017-7221webappsmultiple25 abr 2017
OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote aut
23RISCO
abrir
Exploit-DBVexDay Proof
Realtek Audio Driver 6.0.1.7898 (Windows 10) - Dolby Audio X2 Service Privilege Escalation
CVE-2017-7293localwindows25 abr 2017
The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Office Word - '.RTF' Malicious HTA Execution (Metasploit)
CVE-2017-0199HIGHsob ataqueransomwareremotewindows25 abr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
Exploit-DBVexDay Proof
HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusion
CVE-2017-5798webappsmultiple25 abr 2017
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP ve
23RISCO
abrir
Exploit-DB
Oracle E-Business Suite 12.2.3 - 'IESFOOTPRINT' SQL Injection
CVE-2017-3549webappsjsp25 abr 2017
Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Sup
28RISCO
abrir
Exploit-DB
SquirrelMail < 1.4.22 - Remote Code Execution
CVE-2017-7692remotelinux23 abr 2017
SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 (Build 10586) - 'IEETWCollector' Arbitrary Directory/File Deletion Privilege Escalation
CVE-2017-0165localwindows20 abr 2017
An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox - Environment and ioctl Unprivileged Host User to Host Kernel Privilege Escalation
CVE-2017-3561dosmultiple20 abr 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox - Guest-to-Host Privilege Escalation via Broken Length Handling in slirp Copy
CVE-2017-3558localmultiple20 abr 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - ManagementObject Arbitrary .NET Serialization Remote Code Execution
CVE-2017-0160remotewindows20 abr 2017
Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system t
28RISCO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox 5.0.32 r112930 (x64) - Windows Process COM Injection Privilege Escalation
CVE-2017-3563localwindows_x86-6420 abr 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox - 'virtio-net' Guest-to-Host Out-of-Bounds Write
CVE-2017-3575dosmultiple20 abr 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox 5.1.14 r112924 - Unprivileged Host User to Host Kernel Privilege Escalation via ALSA config
CVE-2017-3576locallinux20 abr 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - Runtime Broker ClipboardBroker Privilege Escalation
CVE-2017-0211localwindows20 abr 2017
An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows
28RISCO
abrir
Exploit-DBVexDay Proof
Dmitry 1.3a - Local Buffer Overflow (PoC)
CVE-2017-7938MEDIUMdoslinux19 abr 2017
Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cau
33RISCO
abrir
Exploit-DB
Tenable Appliance < 4.5 - Root Remote Code Execution
CVE-2017-8051remotelinux18 abr 2017
Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI.
28RISCO
abrir
Exploit-DB
Microsoft Word - '.RTF' Remote Code Execution
CVE-2017-0199HIGHsob ataqueransomwareremotewindows18 abr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0143HIGHsob ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0148HIGHsob ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0144HIGHsob ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0146HIGHsob ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0145HIGHsob ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0147HIGHsob ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
anteriorpágina 145 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.