Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
19.066 exploits
Exploit-DBVexDay Proof
KVM (Nested Virtualization) - L1 Guest Privilege Escalation
CVE-2018-12904doslinux25 jun 2018
In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause
23RISCO
abrir
Exploit-DBVexDay Proof
Foxit Reader 9.0.1.1049 - Remote Code Execution
CVE-2018-9948remotewindows25 jun 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RISCO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (2)
CVE-2018-12613webappsphp22 jun 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (1)
CVE-2018-12613webappsphp21 jun 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir
Exploit-DBVexDay Proof
Apache CouchDB < 2.1.0 - Remote Code Execution
CVE-2017-12636webappslinux20 jun 2018
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - Desktop Bridge Virtual Registry CVE-2018-0880 Incomplete Fix Privilege Escalation
CVE-2018-8214doswindows20 jun 2018
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - Desktop Bridge Activation Arbitrary Directory Creation Privilege Escalation
CVE-2018-8208doswindows20 jun 2018
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RISCO
abrir
Exploit-DBVexDay Proof
DHCP Client - Command Injection 'DynoRoot' (Metasploit)
CVE-2018-1111HIGHremotelinux13 jun 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISCO
abrir
Exploit-DBVexDay Proof
glibc - 'realpath()' Privilege Escalation (Metasploit)
CVE-2018-1000001locallinux13 jun 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - Child Process Restriction Mitigation Bypass
CVE-2018-0982localwindows13 jun 2018
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows
23RISCO
abrir
Exploit-DBVexDay Proof
WebRTC - VP9 Frame Processing Out-of-Bounds Memory Access
CVE-2018-6130dosmultiple08 jun 2018
Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to pot
23RISCO
abrir
Exploit-DBVexDay Proof
WebKit - WebAssembly Compilation Info Leak
CVE-2018-4222dosmultiple08 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
28RISCO
abrir
Exploit-DBVexDay Proof
TrendMicro OfficeScan XG 11.0 - Change Prevention Bypass
CVE-2018-10507localwindows08 jun 2018
A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or
23RISCO
abrir
Exploit-DBVexDay Proof
WebKit - Use-After-Free when Resuming Generator
CVE-2018-4218dosmultiple08 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
23RISCO
abrir
Exploit-DBVexDay Proof
WebRTC - VP9 Missing Frame Processing Out-of-Bounds Memory Access
CVE-2018-6129dosmultiple08 jun 2018
Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially per
23RISCO
abrir
Exploit-DBVexDay Proof
Google Chrome - Integer Overflow when Processing WebAssembly Locals
CVE-2018-6092dosmultiple08 jun 2018
An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker t
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS Kernel - Heap Overflow Due to Lack of Lower Size Check in getvolattrlist
CVE-2018-4243dosmultiple06 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
28RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS Kernel - Use-After-Free Due to Lack of Locking in nvidia GeForce Driver
CVE-2018-4230dosmacos06 jun 2018
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "NVIDIA Grap
23RISCO
abrir
Exploit-DBVexDay Proof
XNU Kernel - Heap Overflow Due to Bad Bounds Checking in MPTCP
CVE-2018-4241dosmultiple06 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RISCO
abrir
Exploit-DBVexDay Proof
PHP 7.2.2 - 'php_stream_url_wrap_http_ex' Buffer Overflow
CVE-2018-7584dosphp06 jun 2018
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer
45RISCO
abrir
Exploit-DBVexDay Proof
MyBB Recent Threads Plugin 1.0 - Cross-Site Scripting
CVE-2018-11715webappsphp05 jun 2018
The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject.
23RISCO
abrir
Exploit-DBVexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
CVE-2016-4657HIGHsob ataqueremoteios05 jun 2018
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISCO
abrir
Exploit-DBVexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
CVE-2016-4655MEDIUMsob ataqueremoteios05 jun 2018
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RISCO
abrir
Exploit-DBVexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
CVE-2016-4656HIGHsob ataqueremoteios05 jun 2018
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denia
91RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - EntrySimpleObjectSlotGetter Type Confusion
CVE-2018-8133doswindows31 mai 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISCO
abrir
Exploit-DBVexDay Proof
Dolibarr ERP/CRM 7.0.0 - (Authenticated) SQL Injection
CVE-2018-10094webappsphp30 mai 2018
SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vecto
60RISCO
abrir
Exploit-DBVexDay Proof
MachForm < 4.2.3 - SQL Injection / Path Traversal / Upload Bypass
CVE-2018-6410webappsphp30 mai 2018
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
MachForm < 4.2.3 - SQL Injection / Path Traversal / Upload Bypass
CVE-2018-6409webappsphp30 mai 2018
An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path fr
28RISCO
abrir
Exploit-DBVexDay Proof
MachForm < 4.2.3 - SQL Injection / Path Traversal / Upload Bypass
CVE-2018-6411webappsphp30 mai 2018
An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle WebCenter Sites 11.1.1.8.0/12.2.1.x - Cross-Site Scripting
CVE-2018-2791webappsmultiple25 mai 2018
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported
50RISCO
abrir
anteriorpágina 23 / 636próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.