Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
19.066 exploits
Exploit-DBVexDay Proof
WebKit JSC - 'BytecodeGenerator::emitGetByVal' Incorrect Optimization (1)
CVE-2017-7061dosmultiple12 set 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir
Exploit-DBVexDay Proof
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Pool Overflow / Local Privilege Escalation (2)
CVE-2017-14344localwindows12 set 2017
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RISCO
abrir
Exploit-DBVexDay Proof
Apache Struts 2.0.1 < 2.3.33 / 2.5 < 2.5.10 - Arbitrary Code Execution
CVE-2017-12611remotemultiple08 set 2017
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in
60RISCO
abrir
Exploit-DBVexDay Proof
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Out-of-Bounds Write Privilege Escalation
CVE-2017-14075localwindows06 set 2017
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RISCO
abrir
Exploit-DBVexDay Proof
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Pool Overflow / Local Privilege Escalation (1)
CVE-2017-14153localwindows06 set 2017
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RISCO
abrir
Exploit-DBVexDay Proof
RubyGems < 2.6.13 - Arbitrary File Overwrite
CVE-2017-0901locallinux04 set 2017
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potenti
28RISCO
abrir
Exploit-DBVexDay Proof
IBM Notes 8.5.x/9.0.x - Denial of Service
CVE-2017-1129dosmultiple02 set 2017
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RISCO
abrir
Exploit-DBVexDay Proof
Git < 2.7.5 - Command Injection (Metasploit)
CVE-2017-1000117remotepython31 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RISCO
abrir
Exploit-DBVexDay Proof
IBM Notes 8.5.x/9.0.x - Denial of Service (2)
CVE-2017-1130dosmultiple31 ago 2017
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it woul
43RISCO
abrir
Exploit-DBVexDay Proof
Metasploit Web UI < 4.14.1-20170828 - Cross-Site Request Forgery
CVE-2017-15084webappsruby30 ago 2017
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
23RISCO
abrir
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6995localios26 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISCO
abrir
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6996localios26 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISCO
abrir
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6999localios26 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISCO
abrir
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6998localios26 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISCO
abrir
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6997localios26 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISCO
abrir
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6979localios26 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RISCO
abrir
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6994localios26 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISCO
abrir
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6989localios26 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISCO
abrir
Exploit-DBVexDay Proof
IBM OpenAdmin Tool - SOAP welcomeServer PHP Code Execution (Metasploit)
CVE-2017-1092remotephp22 ago 2017
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system a
60RISCO
abrir
Exploit-DBVexDay Proof
Symantec Messaging Gateway 10.6.3-2 - Root Remote Command Execution
CVE-2017-6327HIGHsob ataquewebappsjsp18 ago 2017
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situ
83RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'PreVisitCatch' Missing Call
CVE-2017-8656doswindows17 ago 2017
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'InterpreterStackFrame::ProcessLinkFailedAsmJsModule' Incorrect Usage of 'PushPopFrameHelper' (Denial of Service)
CVE-2017-8646doswindows17 ago 2017
Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in t
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'InterpreterStackFrame::ProcessLinkFailedAsmJsModule' Incorrectly Re-parses
CVE-2017-8645doswindows17 ago 2017
Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in t
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'EmitNew' Integer Overflow
CVE-2017-8636doswindows17 ago 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'TryUndeleteProperty' Incorrect Usage (Denial of Service)
CVE-2017-8635doswindows17 ago 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
35RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Invoke Accesses Trait Out-of-Bounds
CVE-2017-3106doswindows17 ago 2017
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF fil
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge 40.15063.0.0 Chakra - Incorrect JIT Optimization with TypedArray Setter #3
CVE-2017-8601doswindows17 ago 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JavascriptFunction::EntryCall' Fails to Handle 'CallInfo' Properly
CVE-2017-8671doswindows17 ago 2017
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Uninitialized Arguments (1)
CVE-2017-8640doswindows17 ago 2017
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary cod
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Incorrect JIT Optimization with TypedArray Setter #2
CVE-2017-8548doswindows17 ago 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain
35RISCO
abrir
anteriorpágina 38 / 636próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.