Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
24.695 exploits
Exploit-DBVexDay Proof
Skia and Firefox - Integer Overflow in SkTDArray Leading to Out-of-Bounds Write
CVE-2018-5159dosmultiple25 mai 2018
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks,
28RISCO
abrir
Exploit-DBVexDay Proof
Oracle WebCenter Sites 11.1.1.8.0/12.2.1.x - Cross-Site Scripting
CVE-2018-2791webappsmultiple25 mai 2018
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported
50RISCO
abrir
Exploit-DBVexDay Proof
Samsung Galaxy S7 Edge - Overflow in OMACP WbXml String Extension Processing
CVE-2018-10751dosandroid23 mai 2018
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Ex
23RISCO
abrir
Exploit-DBVexDay Proof
AMD / ARM / Intel - Speculative Execution Variant 4 Speculative Store Bypass
CVE-2018-3639MEDIUMdoshardware22 mai 2018
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Magic Value Type Confusion
CVE-2018-0953doswindows22 mai 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'POP/MOV SS' Privilege Escalation
CVE-2018-8897localwindows22 mai 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RISCO
abrir
Exploit-DBVexDay Proof
Linux 4.4.0 < 4.4.0-53 - 'AF_PACKET chocobo_root' Local Privilege Escalation (Metasploit)
CVE-2016-8655locallinux22 mai 2018
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RISCO
abrir
Exploit-DBVexDay Proof
Linux 2.6.30 < 2.6.36-rc8 - Reliable Datagram Sockets (RDS) Privilege Escalation (Metasploit)
CVE-2010-3904HIGHsob ataquelocallinux21 mai 2018
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RISCO
abrir
Exploit-DBVexDay Proof
Linux 4.8.0 < 4.8.0-46 - AF_PACKET packet_set_ring Privilege Escalation (Metasploit)
CVE-2017-7308locallinux18 mai 2018
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer
43RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Bound Check Elimination Bug
CVE-2018-0980doswindows18 mai 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISCO
abrir
Exploit-DBVexDay Proof
DynoRoot DHCP Client - Command Injection
CVE-2018-1111HIGHlocallinux18 mai 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISCO
abrir
Exploit-DBVexDay Proof
Nanopool Claymore Dual Miner 7.3 - Remote Code Execution
CVE-2018-1000049remotewindows17 mai 2018
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
60RISCO
abrir
Exploit-DBVexDay Proof
Apache Struts 2 - Struts 1 Plugin Showcase OGNL Code Execution (Metasploit)
CVE-2017-9791CRITICALsob ataqueremotemultiple17 mai 2018
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RISCO
abrir
Exploit-DBVexDay Proof
Jenkins CLI - HTTP Java Deserialization (Metasploit)
CVE-2016-9299remotelinux17 mai 2018
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a
60RISCO
abrir
Exploit-DBVexDay Proof
Libuser - 'roothelper' Local Privilege Escalation (Metasploit)
CVE-2015-3246MEDIUMsob ataquelocallinux16 mai 2018
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
78RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Token Process Trust SID Access Check Bypass Privilege Escalation
CVE-2018-8134localwindows16 mai 2018
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows
23RISCO
abrir
Exploit-DBVexDay Proof
Libuser - 'roothelper' Local Privilege Escalation (Metasploit)
CVE-2015-3245locallinux16 mai 2018
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 2003 SP2 - 'RRAS' SMB Remote Code Execution
CVE-2017-11885remotewindows13 mai 2018
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold,
35RISCO
abrir
Exploit-DBVexDay Proof
Mantis Bug Tracker 1.1.3 - 'manage_proj_page' PHP Code Execution (Metasploit)
CVE-2008-4687remotephp10 mai 2018
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISCO
abrir
Exploit-DBVexDay Proof
PlaySMS 1.4 - 'sendfromfile.php?Filename' (Authenticated) 'Code Execution (Metasploit)
CVE-2017-9080remotephp08 mai 2018
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile
50RISCO
abrir
Exploit-DBVexDay Proof
PlaySMS - 'import.php' (Authenticated) CSV File Upload Code Execution (Metasploit)
CVE-2017-9101remotephp08 mai 2018
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RISCO
abrir
Exploit-DBVexDay Proof
FTPShell Client 6.7 - Buffer Overflow
CVE-2018-7573remotewindows08 mai 2018
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with t
50RISCO
abrir
Exploit-DBVexDay Proof
Palo Alto Networks - 'readSessionVarsFromFile()' Session Corruption (Metasploit)
CVE-2017-15944CRITICALsob ataqueremoteunix08 mai 2018
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows WMI - Recieve Notification Exploit (Metasploit)
CVE-2016-0040HIGHsob ataquelocalwindows_x86-6404 mai 2018
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RISCO
abrir
Exploit-DBVexDay Proof
Google Chrome V8 - Object Allocation Size Integer Overflow
CVE-2018-6065HIGHsob ataqueremotemultiple04 mai 2018
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RISCO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::jsElementScrollHeightGetter' Use-After-Free
CVE-2018-4200dosmultiple02 mai 2018
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud
23RISCO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-8736webappsphp30 abr 2018
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC
50RISCO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-8733webappsphp30 abr 2018
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an
43RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS - ReportCrash mach port Replacement due to Failure to Respect MIG Ownership Rules
CVE-2018-4206dosmultiple30 abr 2018
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.13.2 - Double mach_port_deallocate in kextd due to Failure to Comply with MIG Ownership Rules
CVE-2018-4139dosmacos30 abr 2018
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools"
23RISCO
abrir
anteriorpágina 24 / 824próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.