Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
Microsoft Windows - NtImpersonateAnonymousToken AC to Non-AC Privilege Escalation
CVE-2018-075111 jan 2018
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RISCO
abrir
Exploit-DB
macOS - 'process_policy' Stack Leak Through Uninitialized Field
CVE-2017-715411 jan 2018
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISCO
abrir
Exploit-DB
Microsoft Windows - NtImpersonateAnonymousToken LPAC to Non-LPAC Privilege Escalation
CVE-2018-075211 jan 2018
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RISCO
abrir
Exploit-DB
Microsoft Edge Chakra - 'AppendLeftOverItemsFromEndSegment' Out-of-Bounds Read
CVE-2018-076711 jan 2018
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain info
35RISCO
abrir
Exploit-DB
Seagate Personal Cloud - Multiple Vulnerabilities
CVE-2018-534711 jan 2018
Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs
35RISCO
abrir
Exploit-DB
ALLMediaServer 0.95 - Remote Buffer Overflow
CVE-2017-1793211 jan 2018
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow
50RISCO
abrir
Exploit-DB
Microsoft Windows - NTFS Owner/Mandatory Label Privilege Bypass
CVE-2018-074811 jan 2018
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and
23RISCO
abrir
Exploit-DB
phpCollab 2.5.1 - File Upload (Metasploit)
CVE-2017-609011 jan 2018
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RISCO
abrir
Exploit-DB
Microsoft Windows SMB Server (v1/v2) - Mount Point Arbitrary Device Open Privilege Escalation
CVE-2018-074911 jan 2018
The Microsoft Server Message Block (SMB) Server in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2
23RISCO
abrir
Exploit-DB
Transmission - RPC DNS Rebinding
CVE-2018-570211 jan 2018
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access con
28RISCO
abrir
Exploit-DB
Joomla! Component Easydiscuss < 4.0.21 - Cross-Site Scripting
CVE-2018-526310 jan 2018
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.
23RISCO
abrir
Exploit-DB
DiskBoss Enterprise 8.8.16 - Remote Buffer Overflow
CVE-2018-526210 jan 2018
A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute
35RISCO
abrir
Exploit-DB
HPE iMC - dbman 'RestartDB' Remote Command Execution (Metasploit)
CVE-2017-581610 jan 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RISCO
abrir
Exploit-DB
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
CVE-2016-2388MEDIUMsob ataque10 jan 2018
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user infor
75RISCO
abrir
Exploit-DB
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
CVE-2016-191010 jan 2018
The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors,
23RISCO
abrir
Exploit-DB
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
CVE-2016-2386CRITICALsob ataque10 jan 2018
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISCO
abrir
Exploit-DB
WordPress Plugin Events Calendar - 'event_id' SQL Injection
CVE-2018-531510 jan 2018
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
23RISCO
abrir
Exploit-DB
Muviko 1.1 - SQL Injection
CVE-2017-1797010 jan 2018
Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1
23RISCO
abrir
Exploit-DB
Parity Browser < 1.6.10 - Bypass Same Origin Policy
CVE-2017-1801610 jan 2018
Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
23RISCO
abrir
Exploit-DB
HPE iMC - dbman 'RestoreDBase' Remote Command Execution (Metasploit)
CVE-2017-581710 jan 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RISCO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - 'Lowerer::LowerSetConcatStrMultiItem' Missing Integer Overflow Check
CVE-2018-075810 jan 2018
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RISCO
abrir
Exploit-DB
Jungo Windriver 12.5.1 - Local Privilege Escalation
CVE-2018-518910 jan 2018
Race condition in Jungo Windriver 12.5.1 allows local users to cause a denial of service (buffer overflow) or gain syste
23RISCO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQuerySystemInformation (information class 138_ QueryMemoryTopologyInformation)' Kernel Pool Memory Disclosure
CVE-2018-074609 jan 2018
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wi
23RISCO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - Escape Analysis Bug
CVE-2017-1191809 jan 2018
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to
35RISCO
abrir
Exploit-DB
Microsoft Office - 'Composite Moniker Remote Code Execution
CVE-2017-8570HIGHsob ataque09 jan 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISCO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - Op_MaxInAnArray and Op_MinInAnArray can Explicitly call User-Defined JavaScript Functions
CVE-2017-1189309 jan 2018
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execut
35RISCO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - BackwardPass::RemoveEmptyLoopAfterMemOp Does not Insert Branches
CVE-2017-1190909 jan 2018
ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i
35RISCO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQueryInformationProcess (information class 76_ QueryProcessEnergyValues)' Kernel Stack Memory Disclosure
CVE-2018-074509 jan 2018
The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an infor
23RISCO
abrir
Exploit-DB
Microsoft Edge Chakra - 'asm.js' Out-of-Bounds Read
CVE-2017-1191109 jan 2018
ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i
35RISCO
abrir
Exploit-DB
VX Search Enterprise 10.1.12 - Denial of Service
CVE-2017-1566208 jan 2018
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The atta
23RISCO
abrir
anteriorpágina 109 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.