Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.226exploits catalogados
36.422CVEs com exploração pública
24.695testados em laboratório
79.229 exploits
GitHub PoC5
Netis router RCE exploit ( CVE-2019-19356)
CVE-2019-19356HIGHsob ataque12 dez 2019
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page.
76RISCO
abrir
GitHub PoC
For test
CVE-2019-3396CRITICALsob ataqueransomware12 dez 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
Exploit-DB
Lenovo Power Management Driver 1.67.17.48 - 'pmdrvs.sys' Denial of Service (PoC)
CVE-2019-6192MEDIUMdoswindows12 dez 2019
A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a
33RISCO
abrir
GitHub PoC
CVE-2019-2725-POC
CVE-2019-2725HIGHsob ataqueransomware12 dez 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
Metasploit600
OpenBSD Dynamic Loader chpass Privilege Escalation
CVE-2019-1972611 dez 2019
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC - Heap-Based Memory Corruption due to Malformed TTF Font
CVE-2019-16451doswindows11 dez 2019
Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v
35RISCO
abrir
Exploit-DB
AppXSvc 17763 - Arbitrary File Overwrite (DoS)
CVE-2019-1476doswindows11 dez 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
23RISCO
abrir
Exploit-DB
Apache Olingo OData 4.0 - XML External Entity Injection
CVE-2019-17554webappsjava11 dez 2019
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resoluti
28RISCO
abrir
Metasploit300
Microsoft Windows Uninitialized Variable Local Privilege Elevation
CVE-2019-1458HIGHsob ataqueransomware10 dez 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC
CVE-2014-1322 - IPC Local Security Bypass | Mac OSX (Affected. >= 10.9.2)
CVE-2014-132210 dez 2019
The kernel in Apple OS X through 10.9.2 places a kernel pointer into an XNU object data structure accessible from user s
23RISCO
abrir
GitHub PoC30
详解 k8gege的SharePoint RCE exploit cve-2019-0604-exp.py的代码,动手制作自己的payload
CVE-2019-0604CRITICALsob ataqueransomware10 dez 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISCO
abrir
GitHub PoC1
FreePBX exploit <= 2.8.0
CVE-2010-349009 dez 2019
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interfa
23RISCO
abrir
Metasploit600
Telerik UI ASP.NET AJAX RadAsyncUpload Deserialization
CVE-2019-18935CRITICALsob ataqueransomware09 dez 2019
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir
Metasploit600
Telerik UI ASP.NET AJAX RadAsyncUpload Deserialization
CVE-2017-11317CRITICALsob ataque09 dez 2019
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RISCO
abrir
GitHub PoC1
CVE-2008-1611 TFTP 1.41 buffer overflow exploit in the filepath
CVE-2008-161108 dez 2019
Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or ex
50RISCO
abrir
Exploit-DB
Mozilla FireFox (Windows 10 x64) - Full Chain Client Side Attack
CVE-2019-9810localwindows_x86-6407 dez 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISCO
abrir
GitHub PoC9
Automated script for Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API. You must have a Shodan account to use this script.
CVE-2019-11510CRITICALsob ataqueransomware07 dez 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALsob ataqueransomware07 dez 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC109
CVE-2019-0708 (BlueKeep)
CVE-2019-0708CRITICALsob ataqueransomware07 dez 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-11510CRITICALsob ataqueransomware07 dez 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISCO
abrir
Exploit-DB
Mozilla FireFox (Windows 10 x64) - Full Chain Client Side Attack
CVE-2019-11708CRITICALsob ataquelocalwindows_x86-6407 dez 2019
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
90RISCO
abrir
Exploit-DB
Verot 2.0.3 - Remote Code Execution
CVE-2019-19576webappsphp06 dez 2019
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! an
28RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro Deep Security Agent 11 - Arbitrary File Overwrite
CVE-2019-15627localwindows06 dez 2019
Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, w
23RISCO
abrir
Exploit-DB
Integard Pro NoJs 2.2.0.9026 - Remote Buffer Overflow
CVE-2019-16702remotewindows06 dez 2019
Integard Pro 2.2.0.9026 allows remote attackers to execute arbitrary code via a buffer overflow involving a long NoJs pa
28RISCO
abrir
GitHub PoC3
AppXSvc Arbitrary File Overwrite DoS
CVE-2019-147605 dez 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
23RISCO
abrir
Exploit-DBVexDay Proof
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
CVE-2018-9022webappswindows05 dez 2019
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec
28RISCO
abrir
Exploit-DBVexDay Proof
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
CVE-2018-9021webappswindows05 dez 2019
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec
23RISCO
abrir
GitHub PoC12
This is a filter bypass exploit that results in arbitrary file upload and remote code execution in class.upload.php <= 2.0.3
CVE-2019-1957604 dez 2019
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! an
28RISCO
abrir
Exploit-DB
Cisco WLC 2504 8.9 - Denial of Service (PoC)
CVE-2019-15276HIGHdoshardware04 dez 2019
Cisco Wireless LAN Controller HTTP Parsing Engine Denial of Service Vulnerability
53RISCO
abrir
Exploit-DB
Revive Adserver 4.2 - Remote Code Execution
CVE-2019-5434webappsphp03 dez 2019
An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() cal
50RISCO
abrir
anteriorpágina 801 / 2.641próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.