Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
GitHub PoC90
Apache Solr DataImport Handler RCE
CVE-2019-0193HIGHsob ataque09 ago 2019
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISCO
abrir
GitHub PoC
ThanHuuTuan/CVE-2017-7269
CVE-2017-7269CRITICALsob ataque09 ago 2019
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
Exploit-DB
Open-School 3.0 / Community Edition 2.3 - Cross-Site Scripting
CVE-2019-14696webappsphp08 ago 2019
Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.
43RISCO
abrir
Exploit-DB
Adive Framework 2.0.7 - Cross-Site Request Forgery
CVE-2019-14346webappsphp08 ago 2019
Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.
23RISCO
abrir
Exploit-DB
Aptana Jaxer 1.0.3.4547 - Local File inclusion
CVE-2019-14312webappsmultiple08 ago 2019
Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer. This v
43RISCO
abrir
Exploit-DB
WordPress Plugin JoomSport 3.3 - SQL Injection
CVE-2019-14348webappsphp07 ago 2019
The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via
28RISCO
abrir
GitHub PoC4
linux 提权
CVE-2019-13272HIGHsob ataque07 ago 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
VulnCheck XDB
local
CVE-2019-13272HIGHsob ataque07 ago 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
Exploit-DBVexDay Proof
Apache Tika 1.15 - 1.17 - Header Command Injection (Metasploit)
CVE-2018-1335remotewindows05 ago 2019
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISCO
abrir
Exploit-DBVexDay Proof
macOS iMessage - Heap Overflow when Deserializing
CVE-2019-8661dosmacos05 ago 2019
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.6. A rem
28RISCO
abrir
GitHub PoC
Aquí está mi nuevo y primer exploit web, este exploit ataca a la vulnerabilidad de HeartBleed (CVE-2014-0160) espero que os guste.
CVE-2014-0160HIGHsob ataque05 ago 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
Lee-SungYoung/cve-2019-5736-study
CVE-2019-573605 ago 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC1
提权漏洞
CVE-2019-13272HIGHsob ataque04 ago 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
GitHub PoC1
CVE-2018-16509 Docker Playground - Ghostscript command execution
CVE-2018-1650904 ago 2019
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISCO
abrir
VulnCheck XDB
local
CVE-2018-8639HIGHsob ataqueransomware03 ago 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RISCO
abrir
GitHub PoC3
this is not stable
CVE-2013-202803 ago 2019
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RISCO
abrir
GitHub PoC1
SSH account enumeration verification script(CVE-2018-15473)
CVE-2018-15473MEDIUM02 ago 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
Exploit-DB
SilverSHielD 6.x - Local Privilege Escalation
CVE-2019-13069localmultiple01 ago 2019
extenua SilverSHielD 6.x fails to secure its ProgramData folder, leading to a Local Privilege Escalation to SYSTEM. The
23RISCO
abrir
GitHub PoC3
CVE-2019-1132
CVE-2019-1132HIGHsob ataque31 jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISCO
abrir
Exploit-DBVexDay Proof
Oracle Hyperion Planning 11.1.2.3 - XML External Entity
CVE-2019-2861webappsmultiple31 jul 2019
Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported versi
23RISCO
abrir
GitHub PoC332
Linux 4.10 < 5.1.17 PTRACE_TRACEME local root
CVE-2019-13272HIGHsob ataque31 jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
VulnCheck XDB
local
CVE-2019-13272HIGHsob ataque31 jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
GitHub PoC5
The exploit for CVE-2019-13272
CVE-2019-13272HIGHsob ataque31 jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
VulnCheck XDB
local
CVE-2019-1132HIGHsob ataque31 jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISCO
abrir
VulnCheck XDB
local
CVE-2019-13272HIGHsob ataque31 jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
Exploit-DBVexDay Proof
macOS / iOS NSKeyedUnarchiver - Use-After-Free of ObjC Objects when Unarchiving OITSUIntDictionary Instances
CVE-2019-8662dosmultiple30 jul 2019
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RISCO
abrir
Exploit-DBVexDay Proof
iMessage - NSArray Deserialization can Invoke Subclass that does not Retain References
CVE-2019-8647dosmultiple30 jul 2019
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.4, tvOS 12.4, watchO
28RISCO
abrir
Exploit-DBVexDay Proof
iMessage - NSKeyedUnarchiver Deserialization Allows file Backed NSData Objects
CVE-2019-8646dosmultiple30 jul 2019
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.
28RISCO
abrir
Exploit-DBVexDay Proof
Amcrest Cameras 2.520.AC00.18.R - Unauthenticated Audio Streaming
CVE-2019-3948webappshardware30 jul 2019
The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0
28RISCO
abrir
Exploit-DBVexDay Proof
macOS / iOS JavaScriptCore - JSValue Use-After-Free in ValueProfiles
CVE-2019-8672dosmultiple30 jul 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS M
28RISCO
abrir
anteriorpágina 823 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.