Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
19.066 exploits
Exploit-DBVexDay Proof
OpenSSH 2.3 < 7.7 - Username Enumeration
CVE-2018-15473MEDIUMremotelinux21 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
Exploit-DBVexDay Proof
Easylogin Pro 1.3.0 - 'Encryptor.php' Unserialize Remote Code Execution
CVE-2018-15576remotephp20 ago 2018
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Parameter Scope Parsing Type Confusion
CVE-2018-8279doswindows17 ago 2018
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - InitializeNumberFormat and InitializeDateTimeFormat Type Confusion
CVE-2018-8298HIGHsob ataquedoswindows17 ago 2018
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
93RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'DictionaryPropertyDescriptor::CopyFrom' Type Confusion
CVE-2018-8291doswindows17 ago 2018
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - ImplicitCallFlags Check Bypass with Intl
CVE-2018-8288doswindows17 ago 2018
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
35RISCO
abrir
Exploit-DBVexDay Proof
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
CVE-2018-15141webappslinux16 ago 2018
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RISCO
abrir
Exploit-DBVexDay Proof
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
CVE-2018-15140webappslinux16 ago 2018
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RISCO
abrir
Exploit-DBVexDay Proof
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
CVE-2018-15142webappslinux16 ago 2018
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RISCO
abrir
Exploit-DBVexDay Proof
OpenSSH 2.3 < 7.7 - Username Enumeration (PoC)
CVE-2018-15473MEDIUMremotelinux16 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
Exploit-DBVexDay Proof
Oracle GlassFish Server Open Source Edition 4.1 - Path Traversal (Metasploit)
CVE-2017-1000028webappswindows14 ago 2018
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RISCO
abrir
Exploit-DBVexDay Proof
Oracle Weblogic Server - Deserialization Remote Code Execution (Metasploit)
CVE-2018-2628CRITICALsob ataqueremotewindows13 ago 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
Exploit-DBVexDay Proof
IBM Sterling B2B Integrator 5.2.0.1/5.2.6.3 - Cross-Site Scripting
CVE-2018-1563MEDIUMwebappsmultiple13 ago 2018
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site
33RISCO
abrir
Exploit-DBVexDay Proof
Android - Directory Traversal over USB via Injection in blkid Output
CVE-2018-9445localandroid13 ago 2018
In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local
23RISCO
abrir
Exploit-DBVexDay Proof
IBM Sterling B2B Integrator 5.2.0.1/5.2.6.3 - Cross-Site Scripting
CVE-2018-1513MEDIUMwebappsmultiple13 ago 2018
IBM Sterling B2B Integrator Standard Edition 5.2.0 through 5.2.6 is vulnerable to cross-site scripting. This vulnerabili
33RISCO
abrir
Exploit-DBVexDay Proof
Fortinet FortiClient 5.2.3 (Windows 10 x64 Creators) - Local Privilege Escalation
CVE-2015-4077localwindows_x86-6405 ago 2018
The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient b
23RISCO
abrir
Exploit-DBVexDay Proof
Fortinet FortiClient 5.2.3 (Windows 10 x64 Creators) - Local Privilege Escalation
CVE-2015-5736localwindows_x86-6405 ago 2018
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel - UDP Fragmentation Offset 'UFO' Privilege Escalation (Metasploit)
CVE-2017-1000112locallinux03 ago 2018
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISCO
abrir
Exploit-DBVexDay Proof
fusermount - user_allow_other Restriction Bypass and SELinux Label Control
CVE-2018-10906MEDIUMdoslinux30 jul 2018
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is act
33RISCO
abrir
Exploit-DBVexDay Proof
SoftNAS Cloud < 4.0.3 - OS Command Injection
CVE-2018-14417webappsphp27 jul 2018
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particul
45RISCO
abrir
Exploit-DBVexDay Proof
Skia - Heap Overflow in SkScan::FillPath due to Precision Error
CVE-2018-6126dosmultiple27 jul 2018
A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds m
23RISCO
abrir
Exploit-DBVexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
CVE-2018-10662remotelinux27 jul 2018
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
60RISCO
abrir
Exploit-DBVexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
CVE-2018-10660remotelinux27 jul 2018
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
60RISCO
abrir
Exploit-DBVexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
CVE-2018-10661remotelinux27 jul 2018
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
60RISCO
abrir
Exploit-DBVexDay Proof
Linux - BPF Sign Extension Local Privilege Escalation (Metasploit)
CVE-2017-16995locallinux19 jul 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
Exploit-DBVexDay Proof
Nanopool Claymore Dual Miner - APIs Remote Code Execution (Metasploit)
CVE-2018-1000049remotemultiple17 jul 2018
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
60RISCO
abrir
Exploit-DBVexDay Proof
QNAP Q'Center - 'change_passwd' Command Execution (Metasploit)
CVE-2018-0706remotelinux17 jul 2018
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate
50RISCO
abrir
Exploit-DBVexDay Proof
QNAP Q'Center - 'change_passwd' Command Execution (Metasploit)
CVE-2018-0707remotelinux17 jul 2018
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
50RISCO
abrir
Exploit-DBVexDay Proof
Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injection
CVE-2018-12463HIGHwebappsjava16 jul 2018
MFSBGN03811 rev.1 - Fortify Software Security Center (SSC), Multiple vulnerabilities
46RISCO
abrir
Exploit-DBVexDay Proof
Linux (Ubuntu) - Other Users coredumps Can Be Read via setgid Directory and killpriv Bypass
CVE-2018-13405doslinux16 jul 2018
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an
23RISCO
abrir
anteriorpágina 21 / 636próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.