Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
19.066 exploits
Exploit-DBVexDay Proof
Oracle JDeveloper 11.1.x/12.x - Directory Traversal
CVE-2017-10273webappsjava21 jan 2018
Vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware (subcomponent: Deployment). Supported versi
23RISCO
abrir
Exploit-DBVexDay Proof
macOS 10.13 (17A365) - Kernel Memory Disclosure due to Lack of Bounds Checking in 'AppleIntelCapriController::getDisplayPipeCapability'
CVE-2017-13878dosmacos19 jan 2018
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graph
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Stack-to-Heap Copy
CVE-2018-0776doswindows17 jan 2018
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Incorrect Scope Handling
CVE-2018-0774doswindows17 jan 2018
Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due t
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'AsmJSByteCodeGenerator::EmitCall' Out-of-Bounds Read
CVE-2018-0780doswindows17 jan 2018
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtai
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Incorrect Bounds Calculation
CVE-2018-0769doswindows17 jan 2018
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Out-of-Bounds Write
CVE-2018-0777doswindows17 jan 2018
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JavascriptGeneratorFunction::GetPropertyBuiltIns' Type Confusion
CVE-2017-11914doswindows17 jan 2018
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain t
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Deferred Parsing Makes Wrong Scopes (2)
CVE-2018-0775doswindows17 jan 2018
Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due t
35RISCO
abrir
Exploit-DBVexDay Proof
glibc < 2.26 - 'getcwd()' Local Privilege Escalation
CVE-2018-1000001locallinux16 jan 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir
Exploit-DBVexDay Proof
Oracle E-Business Suite 12.1.3/12.2.x - Open Redirect
CVE-2017-3528webappsjsp15 jan 2018
Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (li
43RISCO
abrir
Exploit-DBVexDay Proof
ILIAS < 5.2.4 - Cross-Site Scripting
CVE-2018-5688webappsphp15 jan 2018
ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'AppendLeftOverItemsFromEndSegment' Out-of-Bounds Read
CVE-2018-0767doswindows11 jan 2018
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain info
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NtImpersonateAnonymousToken AC to Non-AC Privilege Escalation
CVE-2018-0751doswindows11 jan 2018
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RISCO
abrir
Exploit-DBVexDay Proof
Transmission - RPC DNS Rebinding
CVE-2018-5702remotemultiple11 jan 2018
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access con
28RISCO
abrir
Exploit-DBVexDay Proof
phpCollab 2.5.1 - File Upload (Metasploit)
CVE-2017-6090remotephp11 jan 2018
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NTFS Owner/Mandatory Label Privilege Bypass
CVE-2018-0748doswindows11 jan 2018
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows SMB Server (v1/v2) - Mount Point Arbitrary Device Open Privilege Escalation
CVE-2018-0749doswindows11 jan 2018
The Microsoft Server Message Block (SMB) Server in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2
23RISCO
abrir
Exploit-DBVexDay Proof
macOS - 'process_policy' Stack Leak Through Uninitialized Field
CVE-2017-7154dosmacos11 jan 2018
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NtImpersonateAnonymousToken LPAC to Non-LPAC Privilege Escalation
CVE-2018-0752doswindows11 jan 2018
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RISCO
abrir
Exploit-DBVexDay Proof
Android - Hardware Service Manager Arbitrary Service Replacement due to getpidcon
CVE-2017-13209dosandroid11 jan 2018
In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the
23RISCO
abrir
Exploit-DBVexDay Proof
HPE iMC - dbman 'RestoreDBase' Remote Command Execution (Metasploit)
CVE-2017-5817remotewindows10 jan 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RISCO
abrir
Exploit-DBVexDay Proof
HPE iMC - dbman 'RestartDB' Remote Command Execution (Metasploit)
CVE-2017-5816remotewindows10 jan 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Easydiscuss < 4.0.21 - Cross-Site Scripting
CVE-2018-5263webappsphp10 jan 2018
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'Lowerer::LowerSetConcatStrMultiItem' Missing Integer Overflow Check
CVE-2018-0758doswindows10 jan 2018
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Escape Analysis Bug
CVE-2017-11918doswindows09 jan 2018
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Op_MaxInAnArray and Op_MinInAnArray can Explicitly call User-Defined JavaScript Functions
CVE-2017-11893doswindows09 jan 2018
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execut
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryInformationProcess (information class 76_ QueryProcessEnergyValues)' Kernel Stack Memory Disclosure
CVE-2018-0745doswindows09 jan 2018
The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an infor
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - BackwardPass::RemoveEmptyLoopAfterMemOp Does not Insert Branches
CVE-2017-11909doswindows09 jan 2018
ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'asm.js' Out-of-Bounds Read
CVE-2017-11911doswindows09 jan 2018
ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i
35RISCO
abrir
anteriorpágina 30 / 636próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.