Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
24.695 exploits
Exploit-DBVexDay Proof
FS Groupon Clone 1.0 - 'id' SQL Injection
CVE-2017-17575webappsphp09 dez 2017
FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
FS Olx Clone 1.0 - 'scat' / 'pid' SQL Injection
CVE-2017-17586webappsphp08 dez 2017
FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Website Auction Marketplace 2.0.5 - 'cat_id' SQL Injection
CVE-2017-17592webappsphp08 dez 2017
Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
FS Makemytrip Clone 1.0 - 'fl_orig' / 'fl_dest' SQL Injection
CVE-2017-17584webappsphp08 dez 2017
FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
FS Stackoverflow Clone 1.0 - 'keywords' SQL Injection
CVE-2017-17590webappsphp08 dez 2017
FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
FS Shutterstock Clone 1.0 - 'keywords' SQL Injection
CVE-2017-17583webappsphp08 dez 2017
FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Realestate Crowdfunding Script 2.7.2 - 'pid' SQL Injection
CVE-2017-17591webappsphp08 dez 2017
Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
FS Monster Clone 1.0 - 'Employer_Details.php?id' SQL Injection
CVE-2017-17585webappsphp08 dez 2017
FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
FS Thumbtack Clone 1.0 - 'cat' / 'sc' SQL Injection
CVE-2017-17589webappsphp08 dez 2017
FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parame
23RISCO
abrir
Exploit-DBVexDay Proof
FS Quibids Clone 1.0 - SQL Injection
CVE-2017-17581webappsphp08 dez 2017
FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
DomainSale PHP Script 1.0 - 'id' SQL Injection
CVE-2017-17594webappsphp08 dez 2017
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Simple Chatting System 1.0.0 - Arbitrary File Upload
CVE-2017-17593webappsphp08 dez 2017
Simple Chatting System 1.0 allows Arbitrary File Upload via view/my_profile.php, which places files under uploads/.
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 4.10.5 / < 4.14.3 (Ubuntu) - DCCP Socket Use-After-Free
CVE-2017-8824doslinux07 dez 2017
The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privilege
23RISCO
abrir
Exploit-DBVexDay Proof
Wireshark 2.4.0 < 2.4.2 / 2.2.0 < 2.2.10 - CIP Safety Dissector Crash
CVE-2017-17085dosmultiple07 dez 2017
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissec
28RISCO
abrir
Exploit-DBVexDay Proof
Arq 5.9.6 - Local Privilege Escalation
CVE-2017-15357localmacos06 dez 2017
The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges v
23RISCO
abrir
Exploit-DBVexDay Proof
Arq 5.9.7 - Local Privilege Escalation
CVE-2017-16895localmacos06 dez 2017
The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper
23RISCO
abrir
Exploit-DBVexDay Proof
Hashicorp vagrant-vmware-fusion 5.0.0 - Local Privilege Escalation
CVE-2017-15884localmacos06 dez 2017
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.0, a local attacker or malware can silently su
23RISCO
abrir
Exploit-DBVexDay Proof
Hashicorp vagrant-vmware-fusion 5.0.3 - Local Privilege Escalation
CVE-2017-16777localmacos06 dez 2017
If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a loc
23RISCO
abrir
Exploit-DBVexDay Proof
Hashicorp vagrant-vmware-fusion 5.0.1 - Local Privilege Escalation
CVE-2017-16001localmacos06 dez 2017
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently su
23RISCO
abrir
Exploit-DBVexDay Proof
Hashicorp vagrant-vmware-fusion 4.0.24 - Local Privilege Escalation
CVE-2017-12579localmacos06 dez 2017
An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and ear
23RISCO
abrir
Exploit-DBVexDay Proof
Hashicorp vagrant-vmware-fusion 4.0.23 - Local Privilege Escalation
CVE-2017-11741localmacos06 dez 2017
HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo help
23RISCO
abrir
Exploit-DBVexDay Proof
Techno Portfolio Management Panel - 'id' SQL Injection
CVE-2017-17110webappsphp05 dez 2017
Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.
23RISCO
abrir
Exploit-DBVexDay Proof
Perspective ICM Investigation & Case 5.1.1.16 - Privilege Escalation
CVE-2017-11319webappswindows05 dez 2017
Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and c
23RISCO
abrir
Exploit-DBVexDay Proof
Readymade Classifieds Script 1.0 - SQL Injection
CVE-2017-17111webappsphp05 dez 2017
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-detail
23RISCO
abrir
Exploit-DBVexDay Proof
MistServer 2.12 - Cross-Site Scripting
CVE-2017-16884webappsmultiple01 dez 2017
Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web scrip
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.13.1 (High Sierra) - 'Blank Root' Local Privilege Escalation (Metasploit)
CVE-2017-13872localmacos30 nov 2017
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RISCO
abrir
Exploit-DBVexDay Proof
HP iMC Plat 7.2 - Remote Code Execution (2)
CVE-2017-5816remotewindows29 nov 2017
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RISCO
abrir
Exploit-DBVexDay Proof
QEMU - NBD Server Long Export Name Stack Buffer Overflow
CVE-2017-15118HIGHdoslinux29 nov 2017
A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client
46RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.13.1 (High Sierra) - 'Blank Root' Local Privilege Escalation
CVE-2017-13872localmacos28 nov 2017
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RISCO
abrir
Exploit-DBVexDay Proof
HP iMC Plat 7.2 - Remote Code Execution
CVE-2017-5817remotewindows28 nov 2017
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RISCO
abrir
anteriorpágina 34 / 824próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.