Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
19.066 exploits
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Static Buffer Overflow due to Malformed Font Stream
CVE-2019-8048doswindows15 ago 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap Corruption in ReadTableIntoStructure
CVE-2019-1150HIGHdoswindows15 ago 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in WriteTableFromStructure
CVE-2019-1150HIGHdoswindows15 ago 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow While Processing Malformed PDF
CVE-2019-8050doswindows15 ago 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
35RISCO
abrir
Exploit-DBVexDay Proof
Ghidra (Linux) 9.0.4 - .gar Arbitrary Code Execution
CVE-2019-13623locallinux12 ago 2019
In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive)
23RISCO
abrir
Exploit-DBVexDay Proof
WebKit - UXSS via XSLT and Nested Document Replacements
CVE-2019-8690dosmultiple12 ago 2019
A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This i
23RISCO
abrir
Exploit-DBVexDay Proof
Apache Tika 1.15 - 1.17 - Header Command Injection (Metasploit)
CVE-2018-1335remotewindows05 ago 2019
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISCO
abrir
Exploit-DBVexDay Proof
macOS iMessage - Heap Overflow when Deserializing
CVE-2019-8661dosmacos05 ago 2019
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.6. A rem
28RISCO
abrir
Exploit-DBVexDay Proof
Oracle Hyperion Planning 11.1.2.3 - XML External Entity
CVE-2019-2861webappsmultiple31 jul 2019
Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported versi
23RISCO
abrir
Exploit-DBVexDay Proof
Amcrest Cameras 2.520.AC00.18.R - Unauthenticated Audio Streaming
CVE-2019-3948webappshardware30 jul 2019
The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0
28RISCO
abrir
Exploit-DBVexDay Proof
iMessage - NSKeyedUnarchiver Deserialization Allows file Backed NSData Objects
CVE-2019-8646dosmultiple30 jul 2019
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.
28RISCO
abrir
Exploit-DBVexDay Proof
iMessage - NSArray Deserialization can Invoke Subclass that does not Retain References
CVE-2019-8647dosmultiple30 jul 2019
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.4, tvOS 12.4, watchO
28RISCO
abrir
Exploit-DBVexDay Proof
iMessage - Memory Corruption when Decoding NSKnownKeysDictionary1
CVE-2019-8660dosmultiple30 jul 2019
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10
28RISCO
abrir
Exploit-DBVexDay Proof
macOS / iOS JavaScriptCore - Loop-Invariant Code Motion (LICM) Leaves Object Property Access Unguarded
CVE-2019-8671dosmultiple30 jul 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS M
23RISCO
abrir
Exploit-DBVexDay Proof
macOS / iOS NSKeyedUnarchiver - Use-After-Free of ObjC Objects when Unarchiving OITSUIntDictionary Instances
CVE-2019-8662dosmultiple30 jul 2019
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RISCO
abrir
Exploit-DBVexDay Proof
macOS / iOS JavaScriptCore - JSValue Use-After-Free in ValueProfiles
CVE-2019-8672dosmultiple30 jul 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS M
28RISCO
abrir
Exploit-DBVexDay Proof
Schneider Electric Pelco Endura NET55XX Encoder - Authentication Bypass (Metasploit)
CVE-2019-6814remoteunix29 jul 2019
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 wh
50RISCO
abrir
Exploit-DBVexDay Proof
Ahsay Backup 8.1.1.50 - Insecure File Upload and Code Execution (Authenticated)
CVE-2019-10267webappsjsp26 jul 2019
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to
60RISCO
abrir
Exploit-DBVexDay Proof
pdfresurrect 0.15 - Buffer Overflow
CVE-2019-14267doslinux26 jul 2019
PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is misha
23RISCO
abrir
Exploit-DBVexDay Proof
WebKit - Universal Cross-Site Scripting due to Synchronous Page Loads
CVE-2019-8649dosmultiple25 jul 2019
A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management
23RISCO
abrir
Exploit-DBVexDay Proof
Apple iMessage - DigitalTouch tap Message Processing Out-of-Bounds Read
CVE-2019-8624doswatchos24 jul 2019
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5.3. A remote attacke
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1903/1809 - RPCSS Activation Kernel Security Callback Privilege Escalation
CVE-2019-1089localwindows18 jul 2019
An elevation of privilege vulnerability exists in rpcss.dll when the RPC service Activation Kernel improperly handles an
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NtUserSetWindowFNID Win32k User Callback Privilege Escalation (Metasploit)
CVE-2018-8453HIGHsob ataqueransomwarelocalwindows17 jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
Exploit-DBVexDay Proof
Linux - Broken Permission and Object Lifetime Handling for PTRACE_TRACEME
CVE-2019-13272HIGHsob ataquelocallinux17 jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
Exploit-DBVexDay Proof
PHP Laravel Framework 5.5.40 / 5.6.x < 5.6.30 - token Unserialize Remote Command Execution (Metasploit)
CVE-2018-15133HIGHsob ataqueremotelinux16 jul 2019
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 < build 17763 - AppXSvc Hard Link Privilege Escalation (Metasploit)
CVE-2019-0841HIGHsob ataqueransomwarelocalwindows16 jul 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RISCO
abrir
Exploit-DBVexDay Proof
PHP Laravel Framework 5.5.40 / 5.6.x < 5.6.30 - token Unserialize Remote Command Execution (Metasploit)
CVE-2017-16894remotelinux16 jul 2019
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwo
60RISCO
abrir
Exploit-DBVexDay Proof
Citrix SD-WAN Appliance 10.2.2 - Authentication Bypass / Remote Command Execution
CVE-2019-12989CRITICALsob ataquewebappscgi12 jul 2019
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10.0.17134.648 - HTTP -> SMB NTLM Reflection Leads to Privilege Elevation
CVE-2019-1019HIGHlocalwindows12 jul 2019
Microsoft Windows Security Feature Bypass Vulnerability
46RISCO
abrir
Exploit-DBVexDay Proof
Xymon 4.3.25 - useradm Command Execution (Metasploit)
CVE-2016-2056remotemultiple12 jul 2019
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via
50RISCO
abrir
anteriorpágina 10 / 636próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.