Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
Exploit-DB
DASAN Zhone ZNID GPON 2426A EU - Multiple Cross-Site Scripting
CVE-2019-10677webappshardware04 set 2019
Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devic
23RISCO
abrir
GitHub PoC132
Exploit for the Post-Auth RCE vulnerability in Pulse Secure Connect
CVE-2019-11539HIGHsob ataqueransomware04 set 2019
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISCO
abrir
Exploit-DB
WordPress Plugin Download Manager 2.9.93 - Cross-Site Scripting
CVE-2019-15889MEDIUMwebappsphp04 set 2019
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by t
53RISCO
abrir
Metasploit300
Metasploit HTTP(S) handler DoS
CVE-2019-5645HIGH04 set 2019
Rapid7 Metasploit HTTP Handler Denial of Service
48RISCO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager - Unauthenticated Remote Code Execution (Metasploit)
CVE-2019-1619CRITICALremotejava03 set 2019
Cisco Data Center Network Manager Authentication Bypass Vulnerability
85RISCO
abrir
Exploit-DBVexDay Proof
Cisco UCS Director - default scpuser password (Metasploit)
CVE-2019-1935CRITICALremoteunix03 set 2019
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
85RISCO
abrir
GitHub PoC1
jaychouzzk/CVE-2019-0193-exp
CVE-2019-0193HIGHsob ataque03 set 2019
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISCO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager - Unauthenticated Remote Code Execution (Metasploit)
CVE-2019-1622MEDIUMremotejava03 set 2019
Cisco Data Center Network Manager Information Disclosure Vulnerability
70RISCO
abrir
Exploit-DBVexDay Proof
Cisco RV110W/RV130(W)/RV215W Routers Management Interface - Remote Command Execution (Metasploit)
CVE-2019-1663CRITICALremotehardware03 set 2019
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RISCO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager - Unauthenticated Remote Code Execution (Metasploit)
CVE-2019-1620CRITICALremotejava03 set 2019
Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability
85RISCO
abrir
GitHub PoC2
CVE-2019-0708 BlueKeep漏洞批量扫描工具和POC,暂时只有蓝屏。
CVE-2019-0708CRITICALsob ataqueransomware03 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALsob ataqueransomware03 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-0193HIGHsob ataque03 set 2019
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISCO
abrir
Exploit-DBVexDay Proof
ktsuss 1.4 - suid Privilege Escalation (Metasploit)
CVE-2011-2921locallinux03 set 2019
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified com
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2015-750103 set 2019
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-9805HIGHsob ataque02 set 2019
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
Exploit-DB
Alkacon OpenCMS 10.5.x - Cross-Site Scripting
CVE-2019-13234webappsmultiple02 set 2019
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.
23RISCO
abrir
Exploit-DB
Craft CMS 2.7.9/3.2.5 - Information Disclosure
CVE-2019-14280webappsphp02 set 2019
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images whe
23RISCO
abrir
GitHub PoC
A script to Fuzz and and exploit Apache struts CVE-2017-9805
CVE-2017-9805HIGHsob ataque02 set 2019
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
Exploit-DB
Alkacon OpenCMS 10.5.x - Local File inclusion
CVE-2019-13237webappsmultiple02 set 2019
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an atta
23RISCO
abrir
Exploit-DB
Alkacon OpenCMS 10.5.x - Cross-Site Scripting (2)
CVE-2019-13236webappsmultiple02 set 2019
In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the man
23RISCO
abrir
Exploit-DB
Opencart 3.x - Cross-Site Scripting
CVE-2019-15081webappsphp02 set 2019
OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing fe
23RISCO
abrir
Exploit-DB
Alkacon OpenCMS 10.5.x - Cross-Site Scripting
CVE-2019-13235webappsmultiple02 set 2019
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
23RISCO
abrir
GitHub PoC
simplified version of https://github.com/shauntdergrigorian/cve-2006-6184
CVE-2006-618401 set 2019
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-1564201 set 2019
rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise
50RISCO
abrir
VulnCheck XDB
infoleak
CVE-2017-9805HIGHsob ataque31 ago 2019
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC1
Simple python script to fuzz site for CVE-2017-9805
CVE-2017-9805HIGHsob ataque31 ago 2019
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
Exploit-DB
WordPress Plugin WooCommerce Product Feed 2.2.18 - Cross-Site Scripting
CVE-2019-1010124webappsphp30 ago 2019
WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to
23RISCO
abrir
Exploit-DB
Canon PRINT 2.5.5 - Information Disclosure
CVE-2019-14339localandroid30 ago 2019
The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly res
23RISCO
abrir
Metasploit600
Plantronics Hub SpokesUpdateService Privilege Escalation
CVE-2019-1574230 ago 2019
A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application
38RISCO
abrir
anteriorpágina 818 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.