Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
79.230 exploits
Exploit-DB
Atlassian Confluence 6.15.1 - Directory Traversal
CVE-2019-3398HIGHsob ataquewebappsjsp12 nov 2019
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RISCO
abrir
Exploit-DB
eMerge E3 Access Controller 4.6.07 - Remote Code Execution
CVE-2019-7265remotehardware12 nov 2019
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
28RISCO
abrir
Exploit-DB
eMerge E3 1.00-06 - Privilege Escalation
CVE-2019-7254webappshardware12 nov 2019
Linear eMerge E3-Series devices allow File Inclusion.
60RISCO
abrir
Exploit-DB
eMerge E3 1.00-06 - Cross-Site Request Forgery
CVE-2019-7262webappshardware12 nov 2019
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
28RISCO
abrir
Exploit-DB
Computrols CBAS-Web 19.0.0 - 'username' Reflected Cross-Site Scripting
CVE-2019-10846webappshardware12 nov 2019
Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and passw
23RISCO
abrir
Exploit-DB
CBAS-Web 19.0.0 - Information Disclosure
CVE-2019-10849remotehardware12 nov 2019
Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
23RISCO
abrir
Exploit-DB
Optergy 2.3.0a - Remote Code Execution (Backdoor)
CVE-2019-7276webappshardware12 nov 2019
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
60RISCO
abrir
Exploit-DB
Prima Access Control 2.3.35 - 'HwName' Persistent Cross-Site Scripting
CVE-2019-7671webappsalpha12 nov 2019
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being ret
23RISCO
abrir
GitHub PoC19
Suricata LUA scripts to detect CVE-2019-12255, CVE-2019-12256, CVE-2019-12258, and CVE-2019-12260
CVE-2019-1225512 nov 2019
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TC
45RISCO
abrir
GitHub PoC1
load-scripts.php file, which purpose is to retrieve several JavaScript packages through one single request.
CVE-2018-638911 nov 2019
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
GitHub PoC
cve-2019-14287
CVE-2019-1428711 nov 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
CVE-2019-8641dosmultiple11 nov 2019
An out-of-bounds read was addressed with improved input validation.
28RISCO
abrir
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
CVE-2019-8662dosmultiple11 nov 2019
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed OTF Font (CFF Table)
CVE-2019-8196doswindows11 nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream
CVE-2019-8195doswindows11 nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-11043HIGHsob ataqueransomware11 nov 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC16
Ladon POC Moudle CVE-2019-11043 (PHP-FPM + Ngnix)
CVE-2019-11043HIGHsob ataqueransomware11 nov 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC13
The official exploit for rConfig 3.9.2 Pre-auth Remote Code Execution CVE-2019-16662
CVE-2019-1666210 nov 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-1666210 nov 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISCO
abrir
VulnCheck XDB
local
CVE-2022-21882HIGHsob ataqueransomware10 nov 2019
Win32k Elevation of Privilege Vulnerability
98RISCO
abrir
GitHub PoC8
A standalone POC for CVE-2019-12840
CVE-2019-1284009 nov 2019
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISCO
abrir
GitHub PoC1
Centreon v.19.04 Remote Code Execution exploit (CVE-2019-13024)
CVE-2019-1302408 nov 2019
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitra
35RISCO
abrir
Exploit-DB
Adive Framework 2.0.7 - Privilege Escalation
CVE-2019-14347webappsphp08 nov 2019
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an ad
23RISCO
abrir
Exploit-DBVexDay Proof
rConfig - install Command Execution (Metasploit)
CVE-2019-16662remotelinux08 nov 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2018-14847CRITICALsob ataque08 nov 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
Exploit-DB
Jenkins build-metrics plugin 1.3 - 'label' Cross-Site Scripting
CVE-2019-10475webappsjava08 nov 2019
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML
50RISCO
abrir
Exploit-DBVexDay Proof
Android Janus - APK Signature Bypass (Metasploit)
CVE-2017-13156localandroid08 nov 2019
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RISCO
abrir
GitHub PoC10
Case study and POC of CVE-2017-12635: Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation
CVE-2017-1263507 nov 2019
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISCO
abrir
GitHub PoC1
phongld97/detect-cve-2018-16858
CVE-2018-16858HIGH07 nov 2019
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RISCO
abrir
GitHub PoC
create12138/CVE-2018-15982
CVE-2018-15982HIGHsob ataqueransomware06 nov 2019
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
anteriorpágina 805 / 2.641próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.