Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
79.230 exploits
Exploit-DB
Technicolor TD5130.2 - Remote Command Execution
CVE-2019-18396webappshardware13 nov 2019
An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Comm
28RISCO
abrir
GitHub PoC
Sindayifu/CVE-2019-14287-CVE-2014-6271
CVE-2019-1428713 nov 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC348
Privilege Escalation: Weaponizing CVE-2019-1405 and CVE-2019-1322
CVE-2019-1405HIGHsob ataqueransomware13 nov 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RISCO
abrir
VulnCheck XDB
local
CVE-2019-1322HIGHsob ataqueransomware13 nov 2019
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft W
91RISCO
abrir
VulnCheck XDB
local
CVE-2019-1405HIGHsob ataqueransomware13 nov 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RISCO
abrir
GitHub PoC
cve-2014-6271
CVE-2014-6271CRITICALsob ataque13 nov 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
Sindayifu/CVE-2019-14287-CVE-2014-6271
CVE-2014-6271CRITICALsob ataque13 nov 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Metasploit300
WordPress Email Subscribers and Newsletter Hash SQLi Scanner
CVE-2019-20361HIGH13 nov 2019
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b
78RISCO
abrir
Exploit-DB
FUDForum 3.0.9 - Remote Code Execution
CVE-2019-18873webappsphp13 nov 2019
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An
23RISCO
abrir
Exploit-DB
Prima Access Control 2.3.35 - 'HwName' Persistent Cross-Site Scripting
CVE-2019-7671webappsalpha12 nov 2019
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being ret
23RISCO
abrir
Exploit-DB
CBAS-Web 19.0.0 - Information Disclosure
CVE-2019-10849remotehardware12 nov 2019
Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
23RISCO
abrir
Metasploit600
Microsoft UPnP Local Privilege Elevation Vulnerability
CVE-2019-1405HIGHsob ataqueransomware12 nov 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RISCO
abrir
Exploit-DB
eMerge E3 1.00-06 - Remote Code Execution
CVE-2019-7256CRITICALsob ataquewebappshardware12 nov 2019
Linear eMerge E3-Series devices allow Command Injections.
100RISCO
abrir
Metasploit600
Microsoft UPnP Local Privilege Elevation Vulnerability
CVE-2019-1322HIGHsob ataqueransomware12 nov 2019
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft W
91RISCO
abrir
Exploit-DB
eMerge E3 1.00-06 - Cross-Site Request Forgery
CVE-2019-7262webappshardware12 nov 2019
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
28RISCO
abrir
Exploit-DB
CBAS-Web 19.0.0 - Username Enumeration
CVE-2019-10848webappshardware12 nov 2019
Computrols CBAS 18.0.0 allows Username Enumeration.
23RISCO
abrir
Exploit-DB
eMerge E3 1.00-06 - Unauthenticated Directory Traversal
CVE-2019-7254webappshardware12 nov 2019
Linear eMerge E3-Series devices allow File Inclusion.
60RISCO
abrir
Exploit-DB
eMerge E3 1.00-06 - Arbitrary File Upload
CVE-2019-7257webappshardware12 nov 2019
Linear eMerge E3-Series devices allow Unrestricted File Upload.
35RISCO
abrir
Exploit-DB
Optergy 2.3.0a - Cross-Site Request Forgery (Add Admin)
CVE-2019-7273webappshardware12 nov 2019
Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
23RISCO
abrir
Exploit-DB
Atlassian Confluence 6.15.1 - Directory Traversal
CVE-2019-3398HIGHsob ataquewebappsjsp12 nov 2019
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RISCO
abrir
Exploit-DB
eMerge50P 5000P 4.6.07 - Remote Code Execution
CVE-2019-7269webappshardware12 nov 2019
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.
35RISCO
abrir
Exploit-DB
Prima Access Control 2.3.35 - Arbitrary File Upload
CVE-2019-9189webappshardware12 nov 2019
Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when
28RISCO
abrir
Exploit-DB
eMerge E3 Access Controller 4.6.07 - Remote Code Execution
CVE-2019-7265remotehardware12 nov 2019
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
28RISCO
abrir
Exploit-DB
FlexAir Access Control 2.3.35 - Authentication Bypass
CVE-2019-7666webappshardware12 nov 2019
Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash valu
28RISCO
abrir
Exploit-DB
Optergy 2.3.0a - Username Disclosure
CVE-2019-7272webappshardware12 nov 2019
Optergy Proton/Enterprise devices allow Username Disclosure.
28RISCO
abrir
Exploit-DB
Optergy 2.3.0a - Remote Code Execution
CVE-2019-7274webappshardware12 nov 2019
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
28RISCO
abrir
Exploit-DB
eMerge E3 1.00-06 - 'layout' Reflected Cross-Site Scripting
CVE-2019-7255webappshardware12 nov 2019
Linear eMerge E3-Series devices allow XSS.
50RISCO
abrir
Exploit-DB
Computrols CBAS-Web 19.0.0 - 'username' Reflected Cross-Site Scripting
CVE-2019-10846webappshardware12 nov 2019
Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and passw
23RISCO
abrir
GitHub PoC
Sindadziy/cve-2019-14287
CVE-2019-1428712 nov 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
Exploit-DB
eMerge E3 1.00-06 - Privilege Escalation
CVE-2019-7254webappshardware12 nov 2019
Linear eMerge E3-Series devices allow File Inclusion.
60RISCO
abrir
anteriorpágina 804 / 2.641próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.