Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
VulnCheck XDB
initial-access
CVE-2019-11581CRITICALsob ataque16 jul 2019
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 < build 17763 - AppXSvc Hard Link Privilege Escalation (Metasploit)
CVE-2019-0841HIGHsob ataqueransomwarelocalwindows16 jul 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RISCO
abrir
Exploit-DBVexDay Proof
PHP Laravel Framework 5.5.40 / 5.6.x < 5.6.30 - token Unserialize Remote Command Execution (Metasploit)
CVE-2018-15133HIGHsob ataqueremotelinux16 jul 2019
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISCO
abrir
Exploit-DB
DameWare Remote Support 12.0.0.509 - 'Host' Buffer Overflow (SEH)
CVE-2018-12897localwindows16 jul 2019
SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.
23RISCO
abrir
Exploit-DB
CentOS Control Web Panel 0.9.8.838 - User Enumeration
CVE-2019-13383webappslinux16 jul 2019
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a usern
28RISCO
abrir
Exploit-DB
CentOS Control Web Panel 0.9.8.836 - Privilege Escalation
CVE-2019-13359webappslinux16 jul 2019
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and uploa
28RISCO
abrir
GitHub PoC92
Atlassian JIRA Template injection vulnerability RCE
CVE-2019-11581CRITICALsob ataque16 jul 2019
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RISCO
abrir
Exploit-DB
CentOS Control Web Panel 0.9.8.836 - Authentication Bypass
CVE-2019-13360webappslinux16 jul 2019
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login pro
28RISCO
abrir
Exploit-DBVexDay Proof
PHP Laravel Framework 5.5.40 / 5.6.x < 5.6.30 - token Unserialize Remote Command Execution (Metasploit)
CVE-2017-16894remotelinux16 jul 2019
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwo
60RISCO
abrir
Exploit-DB
Android 7 - 9 VideoPlayer - 'ihevcd_parse_pps' Out-of-Bounds Write
CVE-2019-2107dosandroid15 jul 2019
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th
23RISCO
abrir
Exploit-DB
FlightPath < 4.8.2 / < 5.0-rc2 - Local File Inclusion
CVE-2019-13396webappsphp15 jul 2019
FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an in
50RISCO
abrir
Exploit-DB
CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilities
CVE-2019-1943MEDIUMwebappshardware15 jul 2019
Cisco Small Business Series Switches Open Redirect Vulnerability
48RISCO
abrir
GitHub PoC
Proof of concept tool to exploit the directory traversal and local file inclusion vulnerability that resides in the Sahi-pro web application CVE-2019-13063
CVE-2019-1306315 jul 2019
Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the sc
28RISCO
abrir
Exploit-DB
Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service (Metasploit)
CVE-2019-0708CRITICALsob ataqueransomwaredoswindows15 jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
Metasploit600
LibreNMS Collectd Command Injection
CVE-2019-1066915 jul 2019
An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/dev
60RISCO
abrir
GitHub PoC23
Metasploit module for massive Denial of Service using #Bluekeep vector.
CVE-2019-0708CRITICALsob ataqueransomware14 jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALsob ataqueransomware14 jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC1
CVE-2019-9766 React
CVE-2019-976614 jul 2019
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
Xymon 4.3.25 - useradm Command Execution (Metasploit)
CVE-2016-2056remotemultiple12 jul 2019
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via
50RISCO
abrir
GitHub PoC4
R/W
CVE-2019-053912 jul 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISCO
abrir
Exploit-DB
Jenkins Dependency Graph View Plugin 0.13 - Persistent Cross-Site Scripting
CVE-2019-10349webappsjava12 jul 2019
A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers
23RISCO
abrir
Exploit-DBVexDay Proof
Citrix SD-WAN Appliance 10.2.2 - Authentication Bypass / Remote Command Execution
CVE-2019-12989CRITICALsob ataquewebappscgi12 jul 2019
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10.0.17134.648 - HTTP -> SMB NTLM Reflection Leads to Privilege Elevation
CVE-2019-1019HIGHlocalwindows12 jul 2019
Microsoft Windows Security Feature Bypass Vulnerability
46RISCO
abrir
Exploit-DBVexDay Proof
Citrix SD-WAN Appliance 10.2.2 - Authentication Bypass / Remote Command Execution
CVE-2019-12991HIGHsob ataquewebappscgi12 jul 2019
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of
93RISCO
abrir
Exploit-DB
SNMPc Enterprise Edition 9/10 - Mapping Filename Buffer Overflow
CVE-2019-13494localwindows11 jul 2019
nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long var
23RISCO
abrir
Exploit-DB
Sitecore 9.0 rev 171002 - Persistent Cross-Site Scripting
CVE-2019-13493webappsaspx11 jul 2019
In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged u
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Heap-Based Out-of-Bounds Read/Write in OpenType Font Handling Due to Empty ROS Strings
CVE-2019-1124doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RISCO
abrir
Exploit-DB
FreeBSD 12.0 - 'fd' Local Privilege Escalation
CVE-2019-5596localfreebsd10 jul 2019
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Heap-Based Out-of-Bounds Read/Write in OpenType Font Handling Due to Unbounded iFD
CVE-2019-1121doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling due to Out-of-Bounds cubeStackDepth
CVE-2019-1117doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RISCO
abrir
anteriorpágina 826 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.