Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
19.066 exploits
Exploit-DBVexDay Proof
MikroTik RouterOS < 6.43.12 (stable) / < 6.42.12 (long-term) - Firewall and NAT Bypass
CVE-2019-3924remotehardware21 fev 2019
MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The so
28RISCO
abrir
Exploit-DBVexDay Proof
FaceTime - Texture Processing Memory Corruption
CVE-2019-6224dosmacos20 fev 2019
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.
23RISCO
abrir
Exploit-DBVexDay Proof
Jenkins Plugin Script Security < 1.50/Declarative < 1.3.4.1/Groovy < 2.61.1 - Remote Code Execution (PoC)
CVE-2019-1003002webappsjava19 fev 2019
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RISCO
abrir
Exploit-DBVexDay Proof
Jenkins Plugin Script Security < 1.50/Declarative < 1.3.4.1/Groovy < 2.61.1 - Remote Code Execution (PoC)
CVE-2019-1003001webappsjava19 fev 2019
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RISCO
abrir
Exploit-DBVexDay Proof
Jenkins Plugin Script Security < 1.50/Declarative < 1.3.4.1/Groovy < 2.61.1 - Remote Code Execution (PoC)
CVE-2019-1003000webappsjava19 fev 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISCO
abrir
Exploit-DBVexDay Proof
Linux - 'kvm_ioctl_create_device()' NULL Pointer Dereference
CVE-2019-6974doslinux15 fev 2019
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because
28RISCO
abrir
Exploit-DBVexDay Proof
DomainMOD 4.11.01 - 'assets/add/dns.php' Cross-Site Scripting
CVE-2018-19914webappsphp14 fev 2019
DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field.
38RISCO
abrir
Exploit-DBVexDay Proof
DomainMOD 4.11.01 - 'assets/edit/host.php?whid=5' Cross-Site Scripting
CVE-2018-19915webappsphp14 fev 2019
DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.
38RISCO
abrir
Exploit-DBVexDay Proof
DomainMOD 4.11.01 - 'category.php CatagoryName_ StakeHolder' Cross-Site Scripting
CVE-2018-20011webappsphp14 fev 2019
DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.
38RISCO
abrir
Exploit-DBVexDay Proof
DomainMOD 4.11.01 - 'ssl-accounts.php username' Cross-Site Scripting
CVE-2018-20010webappsphp14 fev 2019
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.
38RISCO
abrir
Exploit-DBVexDay Proof
DomainMOD 4.11.01 - 'ssl-provider-name' Cross-Site Scripting
CVE-2018-20009webappsphp14 fev 2019
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.
38RISCO
abrir
Exploit-DBVexDay Proof
Android - binder Use-After-Free via fdget() Optimization
CVE-2019-2000dosandroid12 fev 2019
In several functions of binder.c, there is possible memory corruption due to a use after free. This could lead to local
23RISCO
abrir
Exploit-DBVexDay Proof
Android - binder Use-After-Free of VMA via race Between reclaim and munmap
CVE-2019-1999dosandroid12 fev 2019
In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to
23RISCO
abrir
Exploit-DBVexDay Proof
BlogEngine.NET 3.3.6 - Directory Traversal / Remote Code Execution
CVE-2019-6714webappsaspx12 fev 2019
An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in Po
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - DeleteRangeTimelineOperation Type Confusion (Metasploit)
CVE-2016-4117HIGHsob ataqueremoteosx11 fev 2019
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as
100RISCO
abrir
Exploit-DBVexDay Proof
Evince - CBT File Command Injection (Metasploit)
CVE-2017-1000083locallinux11 fev 2019
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RISCO
abrir
Exploit-DBVexDay Proof
NUUO NVRmini - upgrade_handle.php Remote Command Execution (Metasploit)
CVE-2018-14933CRITICALsob ataqueremotephp11 fev 2019
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par
100RISCO
abrir
Exploit-DBVexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Arbitrary mach Port Name Deallocation in XPC Services due to Invalid mach Message Parsing in _xpc_serializer_unpack
CVE-2019-6218dosmultiple31 jan 2019
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave
28RISCO
abrir
Exploit-DBVexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Kernel Heap Overflow in PF_KEY due to Lack of Bounds Checking when Retrieving Statistics
CVE-2019-6213dosmultiple31 jan 2019
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3,
28RISCO
abrir
Exploit-DBVexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Sandbox Escapes due to Type Confusions and Memory Safety Issues in iohideventsystem
CVE-2019-6214dosmultiple31 jan 2019
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.1
23RISCO
abrir
Exploit-DBVexDay Proof
macOS XNU - Copy-on-Write Behaviour Bypass via Partial-Page Truncation of File
CVE-2019-6208dosmacos31 jan 2019
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Moja
23RISCO
abrir
Exploit-DBVexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 XNU - 'vm_map_copy' Optimization which Requires Atomicity isn't Atomic
CVE-2019-6205dosmultiple31 jan 2019
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Moja
23RISCO
abrir
Exploit-DBVexDay Proof
iOS/macOS 10.13.6 - 'if_ports_used_update_wakeuuid()' 16-byte Uninitialized Kernel Stack Disclosure
CVE-2019-6209dosmultiple30 jan 2019
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input
23RISCO
abrir
Exploit-DBVexDay Proof
Cisco Firepower Management Center 6.2.2.2 / 6.2.3 - Cross-Site Scripting
CVE-2019-1642MEDIUMwebappshardware28 jan 2019
Cisco Firepower Management Center Cross-Site Scripting Vulnerability
33RISCO
abrir
Exploit-DBVexDay Proof
Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 - Command Injection
CVE-2019-1652HIGHsob ataquewebappshardware25 jan 2019
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RISCO
abrir
Exploit-DBVexDay Proof
iOS/macOS - 'task_swap_mach_voucher()' Use-After-Free
CVE-2019-6225dosmultiple25 jan 2019
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
28RISCO
abrir
Exploit-DBVexDay Proof
Ghostscript 9.26 - Pseudo-Operator Remote Code Execution
CVE-2019-6116remotelinux24 jan 2019
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JsBuiltInEngineInterfaceExtensionObject::InjectJsBuiltInLibraryCode' Use-After-Free
CVE-2019-0568doswindows18 jan 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'NewScObjectNoCtor' or 'InitProto' Type Confusion
CVE-2019-0539doswindows18 jan 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'NewScObjectNoCtor' or 'InitProto' Type Confusion
CVE-2019-0567doswindows18 jan 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISCO
abrir
anteriorpágina 15 / 636próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.