Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DBVexDay Proof
Microsoft GDI+ - 'gdiplus!GetRECTSForPlayback' Out-of-Bounds Read (MS17-013)
CVE-2017-0060doswindows20 mar 2017
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Font Processing Multiple Heap Out-of-Bounds and Wild Reads (MS17-011)
CVE-2017-0115doswindows20 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Font Processing Multiple Heap Out-of-Bounds and Wild Reads (MS17-011)
CVE-2017-0128doswindows20 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Font Processing Multiple Heap Out-of-Bounds and Wild Reads (MS17-011)
CVE-2017-0083doswindows20 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'USP10!otlList::insertAt' Uniscribe Font Processing Heap Buffer Overflow (MS17-011)
CVE-2017-0108doswindows20 mar 2017
The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 20
35RISCO
abrir
Exploit-DB
DIGISOL DG-HR1400 1.00.02 Wireless Router - Privilege Escalation
CVE-2017-6896webappshardware18 mar 2017
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from
23RISCO
abrir
Exploit-DB
AXIS (Multiple Products) - Cross-Site Request Forgery
CVE-2015-8255webappshardware17 mar 2017
AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
23RISCO
abrir
Exploit-DB
AXIS Communications - Cross-Site Scripting / Content Injection
CVE-2015-8258webappshardware17 mar 2017
AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via v
23RISCO
abrir
Exploit-DB
Oracle Knowledge Management 12.1.1 < 12.2.5 - XML External Entity Leading To Remote Code Execution
CVE-2016-3542webappsmultiple17 mar 2017
Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3
23RISCO
abrir
Exploit-DB
Cisco IOS 12.2 < 12.4 / 15.0 < 15.6 - Security Association Negotiation Request Device Memory
CVE-2016-6415HIGHsob ataqueremotehardware17 mar 2017
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x
100RISCO
abrir
Exploit-DB
Cerberus FTP Server 8.0.10.3 - 'MLST' Buffer Overflow (PoC)
CVE-2017-6880doswindows16 mar 2017
Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or p
28RISCO
abrir
Exploit-DB
WordPress Plugin Membership Simplified 1.58 - Arbitrary File Download
CVE-2017-1002008webappsphp16 mar 2017
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membe
28RISCO
abrir
Exploit-DB
Microsoft Windows DVD Maker 6.1.7 - XML External Entity Injection
CVE-2017-0045localwindows16 mar 2017
Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse cr
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge 38.14393.0.0 - JavaScript Engine Use-After-Free
CVE-2017-0070doswindows16 mar 2017
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
45RISCO
abrir
Exploit-DB
CommVault Edge 11 SP6 - Stack Buffer Overflow (PoC)
CVE-2017-3195doswindows16 mar 2017
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - MovieClip Attach init Object Use-After-Free
CVE-2017-2932dosmultiple15 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - ATF Thumbnailing Heap Overflow
CVE-2017-2933dosmultiple15 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture co
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Metadata Parsing Out-of-Bounds Read
CVE-2017-2931dosmultiple15 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability related to the pa
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - ATF Planar Decompression Heap Overflow
CVE-2017-2934dosmultiple15 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when parsing Adobe Te
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - AVC Header Slicing Heap Overflow
CVE-2017-2935dosmultiple15 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the F
28RISCO
abrir
Exploit-DBVexDay Proof
Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - 'Jakarta' Multipart Parser OGNL Injection (Metasploit)
CVE-2017-5638CRITICALsob ataqueransomwareremotemultiple15 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
Exploit-DB
Microsoft Windows - 'LoadUvsTable()' Heap Buffer Overflow
CVE-2016-7274doswindows15 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - COM Session Moniker Privilege Escalation (MS17-012)
CVE-2017-0100localwindows15 mar 2017
A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold
23RISCO
abrir
Exploit-DBVexDay Proof
IBM WebSphere - RCE Java Deserialization (Metasploit)
CVE-2015-7450CRITICALsob ataqueremotewindows15 mar 2017
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and
100RISCO
abrir
Exploit-DB
Sitecore CMS 8.1 Update-3 - Cross-Site Scripting
CVE-2016-8855webappsaspx15 mar 2017
Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience
23RISCO
abrir
Exploit-DB
APNGDis 2.8 - 'chunk size descriptor' Heap Buffer Overflow
CVE-2017-6192dosmultiple14 mar 2017
Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arb
23RISCO
abrir
Exploit-DB
APNGDis 2.8 - 'image width / height chunk' Heap Buffer Overflow
CVE-2017-6193dosmultiple14 mar 2017
Buffer overflow in APNGDis 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arb
23RISCO
abrir
Exploit-DB
APNGDis 2.8 - 'filename' Stack Buffer Overflow (PoC)
CVE-2017-6191dosmultiple14 mar 2017
Buffer overflow in APNGDis 2.8 and below allows a remote attacker to execute arbitrary code via a crafted filename.
23RISCO
abrir
Exploit-DBVexDay Proof
Netgear R7000 / R6400 - 'cgi-bin' Command Injection (Metasploit)
CVE-2016-6277HIGHsob ataqueremotecgi13 mar 2017
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.B
100RISCO
abrir
Exploit-DB
Cerberus FTP Server 8.0.10.1 - Denial of Service
CVE-2017-6367doswindows13 mar 2017
In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology invo
23RISCO
abrir
anteriorpágina 150 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.