Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
24.695 exploits
Exploit-DBVexDay Proof
Qualcomm Android - Kernel Use-After-Free via Incorrect set_page_dirty() in KGSL
CVE-2019-10529dosandroid29 mai 2019
Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set
23RISCO
abrir
Exploit-DBVexDay Proof
Spidermonkey - IonMonkey Leaks JS_OPTIMIZED_OUT Magic Value to Script
CVE-2019-9792dosmultiple29 mai 2019
The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during
28RISCO
abrir
Exploit-DBVexDay Proof
Shopware - createInstanceFromNamedArguments PHP Object Instantiation Remote Code Execution (Metasploit)
CVE-2017-18357remotephp23 mai 2019
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of t
43RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OS X - Feedback Assistant Race Condition (Metasploit)
CVE-2019-8565localmacos23 mai 2019
A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A mali
43RISCO
abrir
Exploit-DBVexDay Proof
Visual Voicemail for iPhone - IMAP NAMESPACE Processing Use-After-Free
CVE-2019-8613dosios23 mai 2019
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchO
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1809 - 'CmKeyBodyRemapToVirtualForEnum' Arbitrary Key Enumeration Privilege Escalation
CVE-2019-0881localwindows23 mai 2019
An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumeration, aka 'Windows
23RISCO
abrir
Exploit-DBVexDay Proof
Brocade Network Advisor 14.4.1 - Unauthenticated Remote Code Execution
CVE-2018-6443webappsjava21 mai 2019
A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 JavaScriptCore - AIR Optimization Incorrectly Removes Assignment to Register
CVE-2019-8611dosmultiple21 mai 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS M
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 JavaScriptCore - Loop-Invariant Code Motion (LICM) in DFG JIT Leaves Stack Variable Uninitialized
CVE-2019-8623dosmultiple21 mai 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS M
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 DFG JIT Compiler - 'HasIndexedProperty' Use-After-Free
CVE-2019-8622dosmultiple21 mai 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS M
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 XNU - 'in6_pcbdetach' Stale Pointer Use-After-Free
CVE-2019-8605HIGHsob ataquedosmultiple21 mai 2019
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 XNU - Wild-read due to bad cast in stf_ioctl
CVE-2019-8591dosmultiple21 mai 2019
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.
23RISCO
abrir
Exploit-DBVexDay Proof
GetSimpleCMS - Unauthenticated Remote Code Execution (Metasploit)
CVE-2019-11231remotephp20 mai 2019
An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows
50RISCO
abrir
Exploit-DBVexDay Proof
Cisco Prime Infrastructure Health Monitor HA TarArchive - Directory Traversal / Remote Code Execution
CVE-2019-1821HIGHremotelinux17 mai 2019
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
78RISCO
abrir
Exploit-DBVexDay Proof
VMware Workstation 15.1.0 - DLL Hijacking
CVE-2019-5526localwindows16 mai 2019
VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by t
28RISCO
abrir
Exploit-DBVexDay Proof
OpenProject 5.0.0 - 8.3.1 - SQL Injection
CVE-2019-11600webappsphp13 mai 2019
A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbi
35RISCO
abrir
Exploit-DBVexDay Proof
Cortex Unshortenlink Analyzer < 1.1 - Server-Side Request Forgery
CVE-2019-7652webappsmultiple10 mai 2019
TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the
23RISCO
abrir
Exploit-DBVexDay Proof
Google Chrome 72.0.3626.119 - 'FileReader' Use-After-Free (Metasploit)
CVE-2019-5786MEDIUMsob ataqueremotewindows_x8608 mai 2019
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISCO
abrir
Exploit-DBVexDay Proof
PostgreSQL 9.3 - COPY FROM PROGRAM Command Execution (Metasploit)
CVE-2019-9193remotemultiple08 mai 2019
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
Exploit-DBVexDay Proof
Oracle Weblogic Server - 'AsyncResponseService' Deserialization Remote Code Execution (Metasploit)
CVE-2019-2725HIGHsob ataqueransomwareremotemultiple08 mai 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
Exploit-DBVexDay Proof
Ruby On Rails - DoubleTap Development Mode secret_key_base Remote Code Execution (Metasploit)
CVE-2019-5420remotelinux02 mai 2019
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir
Exploit-DBVexDay Proof
AIS logistics ESEL-Server - Unauthenticated SQL Injection Remote Code Execution (Metasploit)
CVE-2019-10123remotewindows30 abr 2019
SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app)
50RISCO
abrir
Exploit-DBVexDay Proof
Domoticz 4.10577 - Unauthenticated Remote Command Execution
CVE-2019-10678webappsmultiple30 abr 2019
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
28RISCO
abrir
Exploit-DBVexDay Proof
Linux - Missing Locking Between ELF coredump code and userfaultfd VMA Modification
CVE-2019-11599doslinux30 abr 2019
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la
23RISCO
abrir
Exploit-DBVexDay Proof
Pimcore < 5.71 - Unserialize Remote Code Execution (Metasploit)
CVE-2019-10867remotephp30 abr 2019
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/c
50RISCO
abrir
Exploit-DBVexDay Proof
Domoticz 4.10577 - Unauthenticated Remote Command Execution
CVE-2019-10664webappsmultiple30 abr 2019
Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.
23RISCO
abrir
Exploit-DBVexDay Proof
systemd - DynamicUser can Create setuid Binaries when Assisted by Another Process
CVE-2019-3844MEDIUMdoslinux26 abr 2019
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of
33RISCO
abrir
Exploit-DBVexDay Proof
systemd - DynamicUser can Create setuid Binaries when Assisted by Another Process
CVE-2019-3843MEDIUMdoslinux26 abr 2019
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allo
33RISCO
abrir
Exploit-DBVexDay Proof
RARLAB WinRAR 5.61 - ACE Format Input Validation Remote Code Execution (Metasploit)
CVE-2018-20250HIGHsob ataqueransomwarelocalwindows25 abr 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
Exploit-DBVexDay Proof
VirtualBox 6.0.4 r128413 - COM RPC Interface Code Injection Host Privilege Escalation
CVE-2019-2721localwindows24 abr 2019
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISCO
abrir
anteriorpágina 12 / 824próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.