Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DBVexDay Proof
Mantis Bug Tracker 1.3.0/2.3.0 - Password Reset
CVE-2017-7615webappsphp16 abr 2017
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value
60RISCO
abrir
Exploit-DB
Linux Kernel 4.8.0 UDEV < 232 - Local Privilege Escalation
CVE-2017-7874locallinux15 abr 2017
20RISCO
abrir
Exploit-DBVexDay Proof
Concrete5 CMS 8.1.0 - 'Host' Header Injection
CVE-2017-7725webappsphp14 abr 2017
concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "ca
23RISCO
abrir
Exploit-DB
Mozilla Firefox - Address Bar Spoofing
CVE-2017-5415localmultiple14 abr 2017
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leadin
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32kfull!SfnINLPUAHDRAWMENUITEM' Stack Memory Disclosure
CVE-2017-0167doswindows13 abr 2017
An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and W
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Creative Cloud Desktop Application < 4.0.0.185 - Local Privilege Escalation
CVE-2017-3006localwindows13 abr 2017
Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions durin
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' Multiple 'NtGdiGetDIBitsInternal' System Call
CVE-2017-0058doswindows13 abr 2017
A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides
23RISCO
abrir
Exploit-DB
Cisco Catalyst 2960 IOS 12.2(55)SE11 - 'ROCEM' Remote Code Execution
CVE-2017-3881CRITICALsob ataqueremotehardware12 abr 2017
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RISCO
abrir
Exploit-DB
Cisco Catalyst 2960 IOS 12.2(55)SE1 - 'ROCEM' Remote Code Execution
CVE-2017-3881CRITICALsob ataqueremotehardware12 abr 2017
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RISCO
abrir
Exploit-DB
Proxifier for Mac 2.17/2.18 - Privesc Escalation
CVE-2017-7643localmacos11 abr 2017
Proxifier for Mac before 2.19 allows local users to gain privileges via the first parameter to the KLoader setuid progra
23RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit / Safari 10.0.3 (12602.4.8) - Synchronous Page Load Universal Cross-Site Scripting
CVE-2017-2480webappsmultiple11 abr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud b
23RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit / Safari 10.0.3 (12602.4.8) - Universal Cross-Site Scripting via a Focus Event and a Link Element
CVE-2017-2479webappsmultiple11 abr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud b
23RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit - 'JSC::SymbolTableEntry::isWatchable' Heap Buffer Overflow
CVE-2017-2469dosmultiple11 abr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISCO
abrir
Exploit-DB
Brother MFC-J6520DW - Authentication Bypass / Password Change
CVE-2017-7588webappshardware11 abr 2017
On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a
35RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit - 'JSC::B3::Procedure::resetReachability' Use-After-Free
CVE-2017-2470dosmultiple11 abr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit - 'Document::adoptNode' Use-After-Free
CVE-2017-2468dosmultiple11 abr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISCO
abrir
Exploit-DBVexDay Proof
Xen - Broken Check in 'memory_exchange()' Permits PV Guest Breakout
CVE-2017-7228localmultiple11 abr 2017
An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The e
23RISCO
abrir
Exploit-DB
Moxa MXview 2.8 - Denial of Service
CVE-2017-7456doswindows10 abr 2017
Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView
28RISCO
abrir
Exploit-DB
Moxa MX AOPC-Server 1.5 - XML External Entity Injection
CVE-2017-7457remotewindows10 abr 2017
XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure.
23RISCO
abrir
Exploit-DB
Quest Privilege Manager 6.0.0 - Arbitrary File Write
CVE-2017-6554remotelinux10 abr 2017
pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to wr
28RISCO
abrir
Exploit-DB
Moxa MXview 2.8 - Private Key Disclosure
CVE-2017-7455remotewindows10 abr 2017
Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.
28RISCO
abrir
Exploit-DB
D-Link DWR-116 / DWR-116A1 - Arbitrary File Download
CVE-2017-6190webappshardware07 abr 2017
Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows
28RISCO
abrir
Exploit-DBVexDay Proof
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
CVE-2017-6360webappscgi07 abr 2017
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information
35RISCO
abrir
Exploit-DB
Intellinet NFC-30IR Camera - Multiple Vulnerabilities
CVE-2017-7461webappshardware07 abr 2017
Directory traversal vulnerability in the web-based management site on the Intellinet NFC-30ir IP Camera with firmware LM
28RISCO
abrir
Exploit-DBVexDay Proof
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
CVE-2017-6361webappscgi07 abr 2017
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
35RISCO
abrir
Exploit-DB
Adobe (Multiple Products) - XML Injection File Content Disclosure
CVE-2009-3960MEDIUMsob ataqueransomwarewebappsxml07 abr 2017
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Service
100RISCO
abrir
Exploit-DBVexDay Proof
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
CVE-2017-6359webappscgi07 abr 2017
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands vi
28RISCO
abrir
Exploit-DB
Intellinet NFC-30IR Camera - Multiple Vulnerabilities
CVE-2017-7462webappshardware07 abr 2017
Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI scr
28RISCO
abrir
Exploit-DB
Cesanta Mongoose OS - Use-After-Free
CVE-2017-7185doshardware06 abr 2017
Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embed
28RISCO
abrir
Exploit-DB
Moodle 2.x/3.x - SQL Injection
CVE-2017-2641webappsphp06 abr 2017
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
28RISCO
abrir
anteriorpágina 146 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.