Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
79.230 exploits
GitHub PoC4
Interactive-Like Command-Line Console for CVE-2019-16759
CVE-2019-16759CRITICALsob ataque12 out 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - win32k.sys TTF Font Processing Pool Corruption in win32k!ulClearTypeFilter
CVE-2019-1364doswindows10 out 2019
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in CI!CipFixImageType While Parsing Malformed PE File
CVE-2019-1344doswindows10 out 2019
An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memo
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - NULL Pointer Dereference in nt!MiOffsetToProtos While Parsing Malformed PE File
CVE-2019-1343doswindows10 out 2019
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in nt!MiParseImageLoadConfig While Parsing Malformed PE File
CVE-2019-1345doswindows10 out 2019
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
23RISCO
abrir
Exploit-DB
SMA Solar Technology AG Sunny WebBox device - 1.6 - Cross-Site Request Forgery
CVE-2019-13529HIGHwebappshardware10 out 2019
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action
41RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in nt!MiRelocateImage While Parsing Malformed PE File
CVE-2019-1347doswindows10 out 2019
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in CI!HashKComputeFirstPageHash While Parsing Malformed PE File
CVE-2019-1346doswindows10 out 2019
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RISCO
abrir
GitHub PoC1
CVE-2018-7600 and CVE-2018-7602 Mass Exploiter
CVE-2018-7600CRITICALsob ataqueransomware10 out 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHsob ataque10 out 2019
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALsob ataqueransomware10 out 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC10
PoC materials to exploit CVE-2018-6789
CVE-2018-6789CRITICALsob ataqueransomware10 out 2019
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-6789CRITICALsob ataqueransomware10 out 2019
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir
GitHub PoC16
Critical Remote Code Execution Vulnerability (CVE-2018-11776) Found in Apache Struts.
CVE-2018-11776HIGHsob ataque10 out 2019
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
Exploit-DB
TP-Link TL-WR1043ND 2 - Authentication Bypass
CVE-2019-6971webappshardware10 out 2019
An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packe
28RISCO
abrir
GitHub PoC2
The study of vulnerability CVE-2017-3066. Java deserialization
CVE-2017-3066CRITICALsob ataque09 out 2019
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-1584609 out 2019
Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.
35RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-1177009 out 2019
From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the su
50RISCO
abrir
Exploit-DBVexDay Proof
XNU - Remote Double-Free via Data Race in IPComp Input Path
CVE-2019-8717dosmacos09 out 2019
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15, tvOS
23RISCO
abrir
GitHub PoC2
KRAMER VIAware 2.5.0719.1034 - Remote Code Execution
CVE-2019-1712409 out 2019
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
28RISCO
abrir
GitHub PoC
Investigation of CVE-2018-11776 vulnerability that allows attackers to remotely execute code and gain control over Apache Struts-based applications.
CVE-2018-11776HIGHsob ataque08 out 2019
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
Exploit-DB
IBM Bigfix Platform 9.5.9.62 - Arbitrary File Upload
CVE-2019-4013CRITICALwebappsjava07 out 2019
IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root pr
53RISCO
abrir
Exploit-DB
Subrion 4.2.1 - 'Email' Persistant Cross-Site Scripting
CVE-2019-17225webappsphp07 out 2019
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" i
23RISCO
abrir
Exploit-DB
vBulletin 5.0 < 5.5.4 - 'updateAvatar' Authenticated Remote Code Execution
CVE-2019-17132webappsphp07 out 2019
vBulletin through 5.5.4 mishandles custom avatars.
28RISCO
abrir
Exploit-DB
CheckPoint Endpoint Security Client/ZoneAlarm 15.4.062.17802 - Privilege Escalation
CVE-2019-8452localwindows07 out 2019
A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security clien
23RISCO
abrir
GitHub PoC4
infiniteLoopers/CVE-2019-11932
CVE-2019-1193206 out 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC4
Double-Free BUG in WhatsApp exploit poc.
CVE-2019-1193205 out 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC79
timwr/CVE-2019-2215
CVE-2019-2215HIGHsob ataque04 out 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
Exploit-DBVexDay Proof
Android - Binder Driver Use-After-Free
CVE-2019-2215HIGHsob ataquelocalandroid04 out 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHsob ataque04 out 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
anteriorpágina 811 / 2.641próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.