Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
8.460 exploits
VulnCheck XDB
client-side
CVE-2017-8570HIGHsob ataque27 mar 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISCO
abrir
VulnCheck XDB
local
CVE-2017-0213HIGHsob ataqueransomware21 mar 2018
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALsob ataqueransomware20 mar 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-7445CRITICALsob ataque18 mar 2018
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remot
90RISCO
abrir
VulnCheck XDB
local
CVE-2018-6789CRITICALsob ataqueransomware16 mar 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALsob ataqueransomware14 mar 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-2380MEDIUMsob ataqueransomware14 mar 2018
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information pr
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-804612 mar 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-3066CRITICALsob ataque12 mar 2018
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHsob ataqueransomware01 mar 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALsob ataqueransomware28 fev 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-8570HIGHsob ataque26 fev 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-4878HIGHsob ataqueransomware23 fev 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
VulnCheck XDB
local
CVE-2017-1530322 fev 2018
In CPUID CPU-Z before 1.43, there is an arbitrary memory write that results directly in elevation of privileges, because
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALsob ataqueransomware15 fev 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-537414 fev 2018
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01;
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-4878HIGHsob ataqueransomware10 fev 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-11826HIGHsob ataque09 fev 2018
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Serv
93RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-4878HIGHsob ataqueransomware09 fev 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALsob ataque09 fev 2018
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-12617HIGHsob ataque09 fev 2018
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISCO
abrir
VulnCheck XDB
local
CVE-2018-100000107 fev 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2018-010107 fev 2018
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Softw
45RISCO
abrir
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALsob ataque06 fev 2018
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2006-477706 fev 2018
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) fo
60RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-1254205 fev 2018
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2009-1151CRITICALsob ataque03 fev 2018
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALsob ataqueransomware28 jan 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
VulnCheck XDB
local
CVE-2018-100000122 jan 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHsob ataqueransomware16 jan 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
anteriorpágina 272 / 282próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.