Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0148HIGHsob ataqueransomware10 mai 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DB
CMS Made Simple 2.1.6 - Multiple Vulnerabilities
CVE-2017-8912HIGH10 mai 2017
CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code para
41RISCO
abrir
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0144HIGHsob ataqueransomware10 mai 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DB
SAP SAPCAR 721.510 - Heap Buffer Overflow
CVE-2017-885210 mai 2017
SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file
23RISCO
abrir
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0147HIGHsob ataqueransomware10 mai 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0146HIGHsob ataqueransomware10 mai 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DB
Cisco DPC3928 Router - Arbitrary File Disclosure
CVE-2017-1150210 mai 2017
Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /..
23RISCO
abrir
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0145HIGHsob ataqueransomware10 mai 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DB
Intel Active Management Technology - System Privileges
CVE-2017-5689CRITICALsob ataque10 mai 2017
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RISCO
abrir
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0143HIGHsob ataqueransomware10 mai 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DB
Microsoft Security Essentials / SCEP (Microsoft Windows 8/8.1/10 / Windows Server) - 'MsMpEng' Remote Type Confusion
CVE-2017-029009 mai 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
45RISCO
abrir
Exploit-DB
wolfSSL 3.10.2 - x509 Certificate Text Parsing Off-by-One
CVE-2017-2800HIGH09 mai 2017
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting
41RISCO
abrir
Exploit-DB
Personify360 7.5.2/7.6.1 - Improper Access Restrictions
CVE-2017-731209 mai 2017
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add
23RISCO
abrir
Exploit-DB
Personify360 7.5.2/7.6.1 - Improper Database Schema Access Restrictions
CVE-2017-731409 mai 2017
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating
23RISCO
abrir
Exploit-DB
Gemalto SmartDiag Diagnosis Tool < 2.5 - Local Buffer Overflow (SEH)
CVE-2017-695308 mai 2017
Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card
23RISCO
abrir
Exploit-DB
RPCBind / libtirpc - Denial of Service
CVE-2017-877908 mai 2017
rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider t
60RISCO
abrir
Exploit-DB
MediaCoder 0.8.48.5888 - Local Buffer Overflow (SEH)
CVE-2017-886908 mai 2017
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RISCO
abrir
Exploit-DB
Technicolor DPC3928SL - SNMP Authentication Bypass
CVE-2017-513505 mai 2017
Certain Technicolor devices have an SNMP access-control bypass, possibly involving an ISP customization in some cases. T
28RISCO
abrir
Exploit-DB
ViMbAdmin 3.0.15 - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2017-608605 mai 2017
Multiple cross-site request forgery (CSRF) vulnerabilities in the addAction and purgeAction functions in ViMbAdmin 3.0.1
23RISCO
abrir
Exploit-DB
CloudBees Jenkins 2.32.1 - Java Deserialization
CVE-2017-1000353CRITICALsob ataque05 mai 2017
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RISCO
abrir
Exploit-DB
Apple Safari 10.0.3 - 'JSC::CachedCall' Use-After-Free
CVE-2017-249104 mai 2017
Use after free vulnerability in the String.replace method JavaScriptCore in Apple Safari in iOS before 10.3 allows remot
23RISCO
abrir
Exploit-DB
WordPress Core < 4.7.4 - Unauthorized Password Reset
CVE-2017-829503 mai 2017
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for re
28RISCO
abrir
Exploit-DB
WordPress Core 4.6 - Remote Code Execution
CVE-2016-10033CRITICALsob ataque03 mai 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
Exploit-DB
Ghostscript 9.21 - Type Confusion Arbitrary Command Execution (Metasploit)
CVE-2017-8291HIGHsob ataque02 mai 2017
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISCO
abrir
Exploit-DB
Tuleap Project Wiki 8.3 < 9.6.99.86 - Command Injection
CVE-2017-798101 mai 2017
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project W
28RISCO
abrir
Exploit-DB
MySQL < 5.6.35 / < 5.7.17 - Integer Overflow
CVE-2017-359901 mai 2017
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions t
45RISCO
abrir
Exploit-DB
Admidio 3.2.8 - Cross-Site Request Forgery
CVE-2017-838228 abr 2017
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user acc
23RISCO
abrir
Exploit-DB
Microsoft Internet Explorer 11.576.14393.0 - 'CStyleSheetArray::BuildListOfMatchedRules' Memory Corruption
CVE-2017-020227 abr 2017
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerabi
35RISCO
abrir
Exploit-DB
HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusion
CVE-2017-579925 abr 2017
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP ve
28RISCO
abrir
Exploit-DB
Oracle PeopleSoft - 'PeopleSoftServiceListeningConnector' XML External Entity via DOCTYPE
CVE-2017-354825 abr 2017
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integratio
28RISCO
abrir
anteriorpágina 138 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.