Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DB
Netgear DGN2200v1/v2/v3/v4 - 'ping.cgi' Remote Command Execution
CVE-2017-6077CRITICALsob ataquewebappshardware18 fev 2017
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitra
90RISCO
abrir
Exploit-DB
WordPress Plugin Mail Masta 1.0 - SQL Injection
CVE-2017-6095webappsphp18 fev 2017
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/list
23RISCO
abrir
Exploit-DB
Sawmill Enterprise 8.7.9 - Authentication Bypass
CVE-2017-5496webappswindows18 fev 2017
Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash.
23RISCO
abrir
Exploit-DB
WordPress Plugin Mail Masta 1.0 - SQL Injection
CVE-2017-6098webappsphp18 fev 2017
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/camp
23RISCO
abrir
Exploit-DB
WordPress Plugin Mail Masta 1.0 - SQL Injection
CVE-2017-6096webappsphp18 fev 2017
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/list
23RISCO
abrir
Exploit-DBVexDay Proof
Artifex MuPDF mujstest 1.10a - Null Pointer Dereference
CVE-2017-6060doslinux17 fev 2017
Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers t
23RISCO
abrir
Exploit-DBVexDay Proof
dotCMS 3.6.1 - Blind Boolean SQL Injection
CVE-2017-5344webappsphp16 fev 2017
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessib
23RISCO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver 375.70 - DxgkDdiEscape 0x100008b Out-of-Bounds Read/Write
CVE-2017-0312doswindows15 fev 2017
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handle
23RISCO
abrir
Exploit-DBVexDay Proof
Geutebruck 5.02024 G-Cam/EFD-2250 - 'testaction.cgi' Remote Command Execution (Metasploit)
CVE-2017-5174webappshardware15 fev 2017
An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authenticatio
35RISCO
abrir
Exploit-DBVexDay Proof
GOM Player 2.3.10.5266 - '.fpx' Denial of Service
CVE-2017-5881doswindows15 fev 2017
GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspeci
23RISCO
abrir
Exploit-DBVexDay Proof
Geutebruck 5.02024 G-Cam/EFD-2250 - 'testaction.cgi' Remote Command Execution (Metasploit)
CVE-2017-5173webappshardware15 fev 2017
An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD
28RISCO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver 375.70 - Buffer Overflow in Command Buffer Submission
CVE-2017-0313doswindows15 fev 2017
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implem
23RISCO
abrir
Exploit-DB
OpenText Documentum D2 - Remote Code Execution
CVE-2017-5586remotejava15 fev 2017
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a craf
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'gdi32.dll' EMR_SETDIBITSTODEVICE Heap Out-of-Bounds Reads / Memory Disclosure
CVE-2017-0038doswindows15 fev 2017
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
45RISCO
abrir
Exploit-DBVexDay Proof
Cisco ASA - WebVPN CIFS Handling Buffer Overflow
CVE-2017-3807doshardware15 fev 2017
A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software,
28RISCO
abrir
Exploit-DBVexDay Proof
Google Android - Inter-process munmap in android.util.MemoryIntArray
CVE-2017-0411dosandroid14 fev 2017
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - TypedArray.sort Use-After-Free (MS16-145)
CVE-2016-7288doswindows14 fev 2017
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (m
45RISCO
abrir
Exploit-DBVexDay Proof
Google Android - android.util.MemoryIntArray Ashmem Race Conditions
CVE-2017-0412dosandroid14 fev 2017
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RISCO
abrir
Exploit-DB
F5 BIG-IP 11.6 SSL Virtual Server - 'Ticketbleed' Memory Disclosure
CVE-2016-9244remotehardware14 fev 2017
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RISCO
abrir
Exploit-DBVexDay Proof
ntfs-3g - Unsanitized modprobe Environment Privilege Escalation
CVE-2017-0358HIGHlocallinux14 fev 2017
ntfs-3g: Modprobe influence vulnerability via environment variables
56RISCO
abrir
Exploit-DB
Linux Kernel 3.10.0 (CentOS 7) - Denial of Service
CVE-2017-5972doslinux12 fev 2017
The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fa
28RISCO
abrir
Exploit-DB
F5 BIG-IP SSL Virtual Server - 'Ticketbleed' Memory Disclosure
CVE-2016-9244remotehardware10 fev 2017
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RISCO
abrir
Exploit-DBVexDay Proof
HP Smart Storage Administrator 2.30.6.0 - Remote Command Injection (Metasploit)
CVE-2016-8523remotemultiple10 fev 2017
A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found.
28RISCO
abrir
Exploit-DB
Node.JS - 'node-serialize' Remote Code Execution
CVE-2017-5941remotelinux08 fev 2017
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISCO
abrir
Exploit-DB
OpenBSD HTTPd < 6.0 - Memory Exhaustion Denial of Service
CVE-2017-5850dosopenbsd07 fev 2017
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for
28RISCO
abrir
Exploit-DB
CUPS < 2.0.3 - Remote Command Execution
CVE-2015-1158remotelinux03 fev 2017
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-va
28RISCO
abrir
Exploit-DB
ntfs-3g (Debian 9) - Local Privilege Escalation
CVE-2017-0358HIGHlocallinux03 fev 2017
ntfs-3g: Modprobe influence vulnerability via environment variables
56RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit - Type Confusion in RenderBox with Accessibility Enabled
CVE-2017-2373dosmultiple01 fev 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit - 'HTMLKeygenElement' Type Confusion
CVE-2017-2369dosmultiple01 fev 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit - 'HTMLFormElement::reset()' Use-After Free
CVE-2017-2362dososx01 fev 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISCO
abrir
anteriorpágina 153 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.