Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DB
Multiple WordPress Plugins - Arbitrary File Upload
CVE-2017-1002002webappsphp03 mar 2017
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http:
28RISCO
abrir
Exploit-DB
Multiple WordPress Plugins - Arbitrary File Upload
CVE-2017-1002003webappsphp03 mar 2017
Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulner
28RISCO
abrir
Exploit-DB
Multiple WordPress Plugins - Arbitrary File Upload
CVE-2017-1002001webappsphp03 mar 2017
Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS so
28RISCO
abrir
Exploit-DBVexDay Proof
Conext ComBox 865-1058 - Denial of Service
CVE-2017-6019doshardware02 mar 2017
An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830
35RISCO
abrir
Exploit-DB
D-Link DSL-2730U Wireless N 150 - Cross-Site Request Forgery
CVE-2017-6411webappshardware01 mar 2017
Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or fi
23RISCO
abrir
Exploit-DBVexDay Proof
Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scripting
CVE-2016-8526webappsxml01 mar 2017
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a
23RISCO
abrir
Exploit-DBVexDay Proof
Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scripting
CVE-2016-8527webappsxml01 mar 2017
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). Th
43RISCO
abrir
Exploit-DB
Netgear DGN2200v1/v2/v3/v4 - Cross-Site Request Forgery
CVE-2017-6334HIGHsob ataquewebappshardware28 fev 2017
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute ar
100RISCO
abrir
Exploit-DB
Netgear DGN2200v1/v2/v3/v4 - Cross-Site Request Forgery
CVE-2017-6366webappshardware28 fev 2017
Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 all
23RISCO
abrir
Exploit-DB
Synchronet BBS 3.16c - Denial of Service
CVE-2017-6371doswindows28 fev 2017
Synchronet BBS 3.16c for Windows allows remote attackers to cause a denial of service (service crash) via a long string
23RISCO
abrir
Exploit-DB
Cisco AnyConnect Secure Mobility Client 4.3.04027 - Local Privilege Escalation
CVE-2017-3813localwindows28 fev 2017
A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows c
23RISCO
abrir
Exploit-DBVexDay Proof
Sophos Web Appliance 4.3.1.1 - Session Fixation
CVE-2017-6412webappsphp28 fev 2017
In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.
23RISCO
abrir
Exploit-DB
WePresent WiPG-1500 - Backdoor Account
CVE-2017-6351remotehardware27 fev 2017
The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password
23RISCO
abrir
Exploit-DB
Linux Kernel 4.4.0 (Ubuntu) - DCCP Double-Free (PoC)
CVE-2017-6074doslinux26 fev 2017
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST p
23RISCO
abrir
Exploit-DB
Linux Kernel 4.4.0 (Ubuntu) - DCCP Double-Free Privilege Escalation
CVE-2017-6074locallinux26 fev 2017
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST p
23RISCO
abrir
Exploit-DBVexDay Proof
Netgear DGN2200v1/v2/v3/v4 - 'dnslookup.cgi' Remote Command Execution
CVE-2017-6334HIGHsob ataquewebappshardware25 fev 2017
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute ar
100RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit 10.0.2 - 'FrameLoader::clear' Universal Cross-Site Scripting
CVE-2017-2363webappsmacos24 fev 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge / Internet Explorer - 'HandleColumnBreakOnColumnSpanningElement' Type Confusion
CVE-2017-0037HIGHsob ataquedoswindows24 fev 2017
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilde
93RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit 10.0.2 - Cross-Origin or Sandboxed IFRAME Pop-up Blocker Bypass
CVE-2017-2371webappsmultiple24 fev 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" compon
23RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit 10.0.2 - 'Frame::setDocument' Universal Cross-Site Scripting
CVE-2017-2365webappsmultiple24 fev 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS HelpViewer 10.12.1 - XSS Leads to Arbitrary File Execution / Arbitrary File Read
CVE-2017-2361remotemacos23 fev 2017
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Help Viewer
28RISCO
abrir
Exploit-DB
Disk Savvy Enterprise 9.4.18 - Remote Buffer Overflow (SEH)
CVE-2017-6187remotewindows22 fev 2017
Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary c
50RISCO
abrir
Exploit-DB
D-Link DCS Series Cameras - Insecure Crossdomain
CVE-2017-7852webappshardware22 fev 2017
D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access
23RISCO
abrir
Exploit-DB
EasyCom For PHP 4.0.0 - Denial of Service
CVE-2017-5359doswindows22 fev 2017
EasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI.
23RISCO
abrir
Exploit-DB
EasyCom For PHP 4.0.0 - Buffer Overflow (PoC)
CVE-2017-5358doswindows22 fev 2017
Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbi
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - MP4 AMF Parsing Overflow
CVE-2017-2992dosmultiple21 fev 2017
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 h
35RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - SWF Stack Corruption
CVE-2017-2988dosmultiple21 fev 2017
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability when performing g
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Use-After-Free in Applying Bitmap Filter
CVE-2017-2985dosmultiple21 fev 2017
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - YUVPlane Decoding Heap Overflow
CVE-2017-2986dosmultiple21 fev 2017
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the Flash Video (F
35RISCO
abrir
Exploit-DB
WordPress Plugin Mail Masta 1.0 - SQL Injection
CVE-2017-6095webappsphp18 fev 2017
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/list
23RISCO
abrir
anteriorpágina 152 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.