Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
19.066 exploits
Exploit-DBVexDay Proof
Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scripting
CVE-2016-8527webappsxml01 mar 2017
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). Th
43RISCO
abrir
Exploit-DBVexDay Proof
Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scripting
CVE-2016-8526webappsxml01 mar 2017
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a
23RISCO
abrir
Exploit-DBVexDay Proof
Sophos Web Appliance 4.3.1.1 - Session Fixation
CVE-2017-6412webappsphp28 fev 2017
In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.
23RISCO
abrir
Exploit-DBVexDay Proof
Netgear DGN2200v1/v2/v3/v4 - 'dnslookup.cgi' Remote Command Execution
CVE-2017-6334HIGHsob ataquewebappshardware25 fev 2017
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute ar
100RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit 10.0.2 - 'Frame::setDocument' Universal Cross-Site Scripting
CVE-2017-2365webappsmultiple24 fev 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit 10.0.2 - 'FrameLoader::clear' Universal Cross-Site Scripting
CVE-2017-2363webappsmacos24 fev 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge / Internet Explorer - 'HandleColumnBreakOnColumnSpanningElement' Type Confusion
CVE-2017-0037HIGHsob ataquedoswindows24 fev 2017
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilde
93RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit 10.0.2 - Cross-Origin or Sandboxed IFRAME Pop-up Blocker Bypass
CVE-2017-2371webappsmultiple24 fev 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" compon
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS HelpViewer 10.12.1 - XSS Leads to Arbitrary File Execution / Arbitrary File Read
CVE-2017-2361remotemacos23 fev 2017
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Help Viewer
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - YUVPlane Decoding Heap Overflow
CVE-2017-2986dosmultiple21 fev 2017
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the Flash Video (F
35RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Use-After-Free in Applying Bitmap Filter
CVE-2017-2985dosmultiple21 fev 2017
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - SWF Stack Corruption
CVE-2017-2988dosmultiple21 fev 2017
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability when performing g
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - MP4 AMF Parsing Overflow
CVE-2017-2992dosmultiple21 fev 2017
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 h
35RISCO
abrir
Exploit-DBVexDay Proof
Artifex MuPDF mujstest 1.10a - Null Pointer Dereference
CVE-2017-6060doslinux17 fev 2017
Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers t
23RISCO
abrir
Exploit-DBVexDay Proof
dotCMS 3.6.1 - Blind Boolean SQL Injection
CVE-2017-5344webappsphp16 fev 2017
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessib
23RISCO
abrir
Exploit-DBVexDay Proof
GOM Player 2.3.10.5266 - '.fpx' Denial of Service
CVE-2017-5881doswindows15 fev 2017
GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspeci
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'gdi32.dll' EMR_SETDIBITSTODEVICE Heap Out-of-Bounds Reads / Memory Disclosure
CVE-2017-0038doswindows15 fev 2017
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
45RISCO
abrir
Exploit-DBVexDay Proof
Cisco ASA - WebVPN CIFS Handling Buffer Overflow
CVE-2017-3807doshardware15 fev 2017
A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software,
28RISCO
abrir
Exploit-DBVexDay Proof
Geutebruck 5.02024 G-Cam/EFD-2250 - 'testaction.cgi' Remote Command Execution (Metasploit)
CVE-2017-5174webappshardware15 fev 2017
An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authenticatio
35RISCO
abrir
Exploit-DBVexDay Proof
Geutebruck 5.02024 G-Cam/EFD-2250 - 'testaction.cgi' Remote Command Execution (Metasploit)
CVE-2017-5173webappshardware15 fev 2017
An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD
28RISCO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver 375.70 - Buffer Overflow in Command Buffer Submission
CVE-2017-0313doswindows15 fev 2017
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implem
23RISCO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver 375.70 - DxgkDdiEscape 0x100008b Out-of-Bounds Read/Write
CVE-2017-0312doswindows15 fev 2017
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handle
23RISCO
abrir
Exploit-DBVexDay Proof
ntfs-3g - Unsanitized modprobe Environment Privilege Escalation
CVE-2017-0358HIGHlocallinux14 fev 2017
ntfs-3g: Modprobe influence vulnerability via environment variables
56RISCO
abrir
Exploit-DBVexDay Proof
Google Android - Inter-process munmap in android.util.MemoryIntArray
CVE-2017-0411dosandroid14 fev 2017
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RISCO
abrir
Exploit-DBVexDay Proof
Google Android - android.util.MemoryIntArray Ashmem Race Conditions
CVE-2017-0412dosandroid14 fev 2017
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - TypedArray.sort Use-After-Free (MS16-145)
CVE-2016-7288doswindows14 fev 2017
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (m
45RISCO
abrir
Exploit-DBVexDay Proof
HP Smart Storage Administrator 2.30.6.0 - Remote Command Injection (Metasploit)
CVE-2016-8523remotemultiple10 fev 2017
A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found.
28RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit - Type Confusion in RenderBox with Accessibility Enabled
CVE-2017-2373dosmultiple01 fev 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit - 'HTMLKeygenElement' Type Confusion
CVE-2017-2369dosmultiple01 fev 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISCO
abrir
Exploit-DBVexDay Proof
Apple WebKit - 'HTMLFormElement::reset()' Use-After Free
CVE-2017-2362dososx01 fev 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISCO
abrir
anteriorpágina 50 / 636próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.