Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.526exploits catalogados
36.593CVEs com exploração pública
24.695testados em laboratório
19.066 exploits
Exploit-DBVexDay Proof
Palo Alto Networks Firewalls - Root Remote Code Execution
CVE-2017-15944CRITICALsob ataqueremotehardware14 dez 2017
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component JEXTN Video Gallery 3.0.5 - 'id' SQL Injection
CVE-2017-17872webappsphp13 dez 2017
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
23RISCO
abrir
Exploit-DBVexDay Proof
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
CVE-2017-1000408locallinux13 dez 2017
A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environme
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component JEXTN Question And Answer 3.1.0 - SQL Injection
CVE-2017-17871webappsphp13 dez 2017
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action
23RISCO
abrir
Exploit-DBVexDay Proof
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
CVE-2017-1000409locallinux13 dez 2017
A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environ
23RISCO
abrir
Exploit-DBVexDay Proof
Apple XNU Kernel - Memory Corruption due to Integer Overflow in __offsetof Usage in posix_spawn on 32-bit Platforms
CVE-2017-13876dosmultiple12 dez 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS - Kernel Double Free due to Incorrect API Usage in Flow Divert Socket Option Handling
CVE-2017-13867dosmultiple12 dez 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS - Multiple Kernel Use-After-Frees due to Incorrect IOKit Object Lifetime Management in IOTimeSyncClockManagerUserClient
CVE-2017-13847dosmultiple12 dez 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The is
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS - Kernel Code Execution due to Lack of Bounds Checking in AppleIntelCapriController::GetLinkConfig
CVE-2017-13875dosmacos12 dez 2017
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graph
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component JBuildozer 1.4.1 - 'appid' SQL Injection
CVE-2017-17870webappsphp12 dez 2017
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
23RISCO
abrir
Exploit-DBVexDay Proof
Readymade Video Sharing Script 3.2 - SQL Injection
CVE-2017-17627webappsphp11 dez 2017
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Freelance Website Script 2.0.6 - 'pr_id' / 'catid' SQL Injection
CVE-2017-17613webappsphp11 dez 2017
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RISCO
abrir
Exploit-DBVexDay Proof
Facebook Clone Script 1.0 - 'id' / 'send' SQL Injection
CVE-2017-17615webappsphp11 dez 2017
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS - Kernel Double Free due to IOSurfaceRootUserClient not Respecting MIG Ownership Rules
CVE-2017-13861dosmultiple11 dez 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS be
43RISCO
abrir
Exploit-DBVexDay Proof
Kickstarter Clone Acript 2.0 - 'projid' SQL Injection
CVE-2017-17618webappsphp11 dez 2017
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Advanced Real Estate Script 4.0.7 - SQL Injection
CVE-2017-17603webappsphp11 dez 2017
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_
23RISCO
abrir
Exploit-DBVexDay Proof
Laundry Booking Script 1.0 - 'list?city' SQL Injection
CVE-2017-17619webappsphp11 dez 2017
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Online Exam Test Application Script 1.6 - 'exams.php?sort' SQL Injection
CVE-2017-17622webappsphp11 dez 2017
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS - 'necp_get_socket_attributes' so_pcb Type Confusion
CVE-2017-13855dosmacos11 dez 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISCO
abrir
Exploit-DBVexDay Proof
Multireligion Responsive Matrimonial 4.7.2 - 'succid' SQL Injection
CVE-2017-17631webappsphp11 dez 2017
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS XNU Kernel - Memory Disclosure due to bug in Kernel API for Detecting Kernel Memory Disclosures
CVE-2017-13865dosmacos11 dez 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISCO
abrir
Exploit-DBVexDay Proof
Opensource Classified Ads Script 3.2 - SQL Injection
CVE-2017-17623webappsphp11 dez 2017
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
PHP Multivendor Ecommerce 1.0 - 'sid' / 'searchcat' / 'chid1' SQL Injection
CVE-2017-17624webappsphp11 dez 2017
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
23RISCO
abrir
Exploit-DBVexDay Proof
Professional Service Script 1.0 - 'service-list?city' SQL Injection
CVE-2017-17625webappsphp11 dez 2017
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
MLM Forced Matrix 2.0.9 - 'newid' SQL Injection
CVE-2017-17636webappsphp11 dez 2017
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Groupon Clone Script 3.01 - 'state_id' / 'search' SQL Injection
CVE-2017-17638webappsphp11 dez 2017
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Hot Scripts Clone 3.1 - 'subctid' / 'mctid' SQL Injection
CVE-2017-17612webappsphp11 dez 2017
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Muslim Matrimonial Script 3.02 - 'succid' SQL Injection
CVE-2017-17639webappsphp11 dez 2017
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Resume Clone Script 2.0.5 - SQL Injection
CVE-2017-17641webappsphp11 dez 2017
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Foodspotting Clone Script 1.0 - 'quicksearch.php?q' SQL Injection
CVE-2017-17617webappsphp11 dez 2017
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RISCO
abrir
anteriorpágina 32 / 636próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.