Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
Co-work Space Search Script 1.0 - 'city' SQL Injection
CVE-2017-1760608 dez 2017
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir
Exploit-DB
Consumer Complaints Clone Script 1.0 - 'id' SQL Injection
CVE-2017-1760508 dez 2017
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.
23RISCO
abrir
Exploit-DB
Nearbuy Clone Script 3.2 - 'search' SQL Injection
CVE-2017-1759708 dez 2017
Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.
23RISCO
abrir
Exploit-DB
FS Shutterstock Clone 1.0 - 'keywords' SQL Injection
CVE-2017-1758308 dez 2017
FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter.
23RISCO
abrir
Exploit-DB
Doctor Search Script 1.0 - 'city' SQL Injection
CVE-2017-1761108 dez 2017
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir
Exploit-DB
Simple Chatting System 1.0.0 - Arbitrary File Upload
CVE-2017-1759308 dez 2017
Simple Chatting System 1.0 allows Arbitrary File Upload via view/my_profile.php, which places files under uploads/.
23RISCO
abrir
Exploit-DB
FS Quibids Clone 1.0 - SQL Injection
CVE-2017-1758108 dez 2017
FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.
23RISCO
abrir
Exploit-DB
FS Thumbtack Clone 1.0 - 'cat' / 'sc' SQL Injection
CVE-2017-1758908 dez 2017
FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parame
23RISCO
abrir
Exploit-DB
FS Olx Clone 1.0 - 'scat' / 'pid' SQL Injection
CVE-2017-1758608 dez 2017
FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.
23RISCO
abrir
Exploit-DB
Chartered Accountant Booking Script 1.0 - 'city' SQL Injection
CVE-2017-1760908 dez 2017
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
23RISCO
abrir
Exploit-DB
Child Care Script 1.0 - 'city' SQL Injection
CVE-2017-1760808 dez 2017
Child Care Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir
Exploit-DB
Cab Booking Script 1.0 - 'city' SQL Injection
CVE-2017-1760108 dez 2017
Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter.
23RISCO
abrir
Exploit-DB
CMS Auditor Website 1.0 - SQL Injection
CVE-2017-1760708 dez 2017
CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.
23RISCO
abrir
Exploit-DB
E-commerce MLM Software 1.0 - SQL Injection
CVE-2017-1761008 dez 2017
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid paramet
23RISCO
abrir
Exploit-DB
DomainSale PHP Script 1.0 - 'id' SQL Injection
CVE-2017-1759408 dez 2017
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.
23RISCO
abrir
Exploit-DB
FS Stackoverflow Clone 1.0 - 'keywords' SQL Injection
CVE-2017-1759008 dez 2017
FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.
23RISCO
abrir
Exploit-DB
Website Auction Marketplace 2.0.5 - 'cat_id' SQL Injection
CVE-2017-1759208 dez 2017
Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.
23RISCO
abrir
Exploit-DB
FS Makemytrip Clone 1.0 - 'fl_orig' / 'fl_dest' SQL Injection
CVE-2017-1758408 dez 2017
FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter.
23RISCO
abrir
Exploit-DB
FS Monster Clone 1.0 - 'Employer_Details.php?id' SQL Injection
CVE-2017-1758508 dez 2017
FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter.
23RISCO
abrir
Exploit-DB
Apple macOS High Sierra 10.13 - 'ctl_ctloutput-leak' Information Leak
CVE-2017-1386807 dez 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISCO
abrir
Exploit-DB
Claymore Dual ETH + DCR/SC/LBC/PASC GPU Miner - Stack Buffer Overflow / Path Traversal
CVE-2017-1692907 dez 2017
The remote management interface on the Claymore Dual GPU miner 10.1 is vulnerable to an authenticated directory traversa
28RISCO
abrir
Exploit-DB
Linux Kernel 4.10.5 / < 4.14.3 (Ubuntu) - DCCP Socket Use-After-Free
CVE-2017-882407 dez 2017
The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privilege
23RISCO
abrir
Exploit-DB
Claymore Dual ETH + DCR/SC/LBC/PASC GPU Miner - Stack Buffer Overflow / Path Traversal
CVE-2017-1693007 dez 2017
The remote management interface on the Claymore Dual GPU miner 10.1 allows an unauthenticated remote attacker to execute
35RISCO
abrir
Exploit-DB
Wireshark 2.4.0 < 2.4.2 / 2.2.0 < 2.2.10 - CIP Safety Dissector Crash
CVE-2017-1708507 dez 2017
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissec
28RISCO
abrir
Exploit-DB
Arq 5.9.7 - Local Privilege Escalation
CVE-2017-1689506 dez 2017
The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper
23RISCO
abrir
Exploit-DB
Sera 1.2 - Local Privilege Escalation / Password Disclosure
CVE-2017-1591806 dez 2017
Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial
23RISCO
abrir
Exploit-DB
Arq 5.9.6 - Local Privilege Escalation
CVE-2017-1535706 dez 2017
The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges v
23RISCO
abrir
Exploit-DB
Hashicorp vagrant-vmware-fusion 4.0.23 - Local Privilege Escalation
CVE-2017-1174106 dez 2017
HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo help
23RISCO
abrir
Exploit-DB
Hashicorp vagrant-vmware-fusion 4.0.24 - Local Privilege Escalation
CVE-2017-1257906 dez 2017
An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and ear
23RISCO
abrir
Exploit-DB
Techno Portfolio Management Panel - 'id' SQL Injection
CVE-2017-1711005 dez 2017
Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.
23RISCO
abrir
anteriorpágina 115 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.