Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
19.066 exploits
Exploit-DBVexDay Proof
piSignage 2.6.4 - Directory Traversal
CVE-2019-20354webappshardware07 jan 2020
The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user)
23RISCO
abrir
Exploit-DBVexDay Proof
nostromo 1.9.6 - Remote Code Execution
CVE-2019-16278CRITICALsob ataqueremotemultiple01 jan 2020
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft UPnP - Local Privilege Elevation (Metasploit)
CVE-2019-1322HIGHsob ataqueransomwarelocalwindows30 dez 2019
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft W
91RISCO
abrir
Exploit-DBVexDay Proof
OpenBSD - Dynamic Loader chpass Privilege Escalation (Metasploit)
CVE-2019-19726localopenbsd30 dez 2019
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RISCO
abrir
Exploit-DBVexDay Proof
Microsoft UPnP - Local Privilege Elevation (Metasploit)
CVE-2019-1405HIGHsob ataqueransomwarelocalwindows30 dez 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RISCO
abrir
Exploit-DBVexDay Proof
FreeBSD-SA-19:02.fd - Privilege Escalation
CVE-2019-5596localfreebsd30 dez 2019
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS
23RISCO
abrir
Exploit-DBVexDay Proof
Django < 3.0 < 2.2 < 1.11 - Account Hijack
CVE-2019-19844webappspython24 dez 2019
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
35RISCO
abrir
Exploit-DBVexDay Proof
OpenMRS - Java Deserialization RCE (Metasploit)
CVE-2018-19276CRITICALremotelinux18 dez 2019
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISCO
abrir
Exploit-DBVexDay Proof
OpenBSD 6.x - Dynamic Loader Privilege Escalation
CVE-2019-19726localopenbsd16 dez 2019
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RISCO
abrir
Exploit-DBVexDay Proof
Linux 5.3 - Privilege Escalation via io_uring Offload of sendmsg() onto Kernel Thread with Kernel Creds
CVE-2019-19241locallinux16 dez 2019
In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabili
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC - Heap-Based Memory Corruption due to Malformed TTF Font
CVE-2019-16451doswindows11 dez 2019
Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v
35RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro Deep Security Agent 11 - Arbitrary File Overwrite
CVE-2019-15627localwindows06 dez 2019
Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, w
23RISCO
abrir
Exploit-DBVexDay Proof
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
CVE-2018-9022webappswindows05 dez 2019
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec
28RISCO
abrir
Exploit-DBVexDay Proof
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
CVE-2018-9021webappswindows05 dez 2019
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec
23RISCO
abrir
Exploit-DBVexDay Proof
Internet Explorer - Use-After-Free in JScript Arguments During toJSON Callback
CVE-2019-1429HIGHsob ataquedoswindows22 nov 2019
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISCO
abrir
Exploit-DBVexDay Proof
FusionPBX - Operator Panel exec.php Command Execution (Metasploit)
CVE-2019-11409remotemultiple20 nov 2019
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerabili
60RISCO
abrir
Exploit-DBVexDay Proof
Pulse Secure VPN - Arbitrary Command Execution (Metasploit)
CVE-2019-11539HIGHsob ataqueransomwareremotemultiple20 nov 2019
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISCO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
CVE-2019-15791HIGHdoslinux20 nov 2019
Reference count underflow in shiftfs
41RISCO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
CVE-2019-15793MEDIUMdoslinux20 nov 2019
Mishandling of file-system uid/gid with namespaces in shiftfs
33RISCO
abrir
Exploit-DBVexDay Proof
Bludit - Directory Traversal Image File Upload (Metasploit)
CVE-2019-16113remotephp20 nov 2019
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISCO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - ubuntu-aufs-modified mmap_region() Breaks Refcounting in overlayfs/shiftfs Error Path
CVE-2019-15794HIGHdoslinux20 nov 2019
Reference counting error in overlayfs/shiftfs error path when used in conjuction with aufs
41RISCO
abrir
Exploit-DBVexDay Proof
Xorg X11 Server - Local Privilege Escalation (Metasploit)
CVE-2018-14665localunix20 nov 2019
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
50RISCO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
CVE-2019-15792HIGHdoslinux20 nov 2019
Type confusion in shiftfs
41RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream
CVE-2019-8195doswindows11 nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISCO
abrir
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
CVE-2019-8662dosmultiple11 nov 2019
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RISCO
abrir
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
CVE-2019-8641dosmultiple11 nov 2019
An out-of-bounds read was addressed with improved input validation.
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed OTF Font (CFF Table)
CVE-2019-8196doswindows11 nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISCO
abrir
Exploit-DBVexDay Proof
Android Janus - APK Signature Bypass (Metasploit)
CVE-2017-13156localandroid08 nov 2019
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RISCO
abrir
Exploit-DBVexDay Proof
rConfig - install Command Execution (Metasploit)
CVE-2019-16662remotelinux08 nov 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISCO
abrir
Exploit-DBVexDay Proof
JavaScriptCore - Type Confusion During Bailout when Reconstructing Arguments Objects
CVE-2019-8820dosmultiple05 nov 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPad
23RISCO
abrir

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.