Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.230 exploits
GitHub PoC21
PoC of CVE-2018-14847 Mikrotik Vulnerability using simple script
CVE-2018-14847CRITICALsob ataque29 set 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
GitHub PoC624
Full exploit chain (CVE-2019-11708 & CVE-2019-9810) against Firefox on Windows 64-bit.
CVE-2019-11708CRITICALsob ataque29 set 2019
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
90RISCO
abrir
GitHub PoC75
it works on xp (all version sp2 sp3)
CVE-2019-0708CRITICALsob ataqueransomware29 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-845128 set 2019
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con
60RISCO
abrir
GitHub PoC5
Exploit code for CVE-2019-16692
CVE-2019-1669227 set 2019
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is us
28RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-16759CRITICALsob ataque26 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-16759CRITICALsob ataque26 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-845126 set 2019
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con
60RISCO
abrir
GitHub PoC21
vBulletin 5.x 未授权远程代码执行漏洞
CVE-2019-16759CRITICALsob ataque26 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC3
Nmap NSE Script to Detect vBulletin pre-auth 5.x RCE CVE-2019-16759
CVE-2019-16759CRITICALsob ataque26 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
Metasploit600
Android Binder Use-After-Free Exploit
CVE-2019-2215HIGHsob ataque26 set 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
Exploit-DB
NPMJS gitlabhook 0.0.17 - 'repository' Remote Command Execution
CVE-2019-5485webappsjson25 set 2019
NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be inje
35RISCO
abrir
GitHub PoC5
Vbulletin rce exploit CVE-2019-16759
CVE-2019-16759CRITICALsob ataque25 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC1
Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)
CVE-2018-14847CRITICALsob ataque25 set 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
Exploit-DB
Microsoft SharePoint 2013 SP1 - 'DestinationFolder' Persistant Cross-Site Scripting
CVE-2019-1262webappsaspx25 set 2019
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-16759CRITICALsob ataque25 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
Exploit-DBVexDay Proof
ABRT - sosreport Privilege Escalation (Metasploit)
CVE-2015-5287HIGHsob ataquelocallinux25 set 2019
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RISCO
abrir
VulnCheck XDB
infoleak
CVE-2018-14847CRITICALsob ataque25 set 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
GitHub PoC10
PoC for distributed NTP reflection DoS (CVE-2013-5211)
CVE-2013-521124 set 2019
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - BlueKeep RDP Remote Windows Kernel Use After Free (Metasploit)
CVE-2019-0708CRITICALsob ataqueransomwareremotewindows24 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC6
CVE-2018-13379 Exploit
CVE-2018-13379CRITICALsob ataqueransomware24 set 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
Exploit-DB
Pfsense 2.3.4 / 2.4.4-p3 - Remote Code Injection
CVE-2019-16701webappsphp24 set 2019
pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_ph
28RISCO
abrir
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary Can Read Object Out of Bounds
CVE-2019-8641dosios24 set 2019
An out-of-bounds read was addressed with improved input validation.
28RISCO
abrir
Metasploit300
File Sharing Wizard - POST SEH Overflow
CVE-2019-1672424 set 2019
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Excepti
60RISCO
abrir
GitHub PoC3
CVE-2019-1367
CVE-2019-1367HIGHsob ataqueransomware24 set 2019
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
83RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-845124 set 2019
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con
60RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2013-521124 set 2019
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-13379CRITICALsob ataqueransomware24 set 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
Exploit-DB
Gila CMS < 1.11.1 - Local File Inclusion
CVE-2019-16679webappsmultiple23 set 2019
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
23RISCO
abrir
Exploit-DB
iOS < 12.4.1 - 'Jailbreak' Local Privilege Escalation
CVE-2019-8605HIGHsob ataquelocalios23 set 2019
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RISCO
abrir
anteriorpágina 813 / 2.641próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.