Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
Metasploit600
Shopware createInstanceFromNamedArguments PHP Object Instantiation RCE
CVE-2019-12799MEDIUM09 mai 2019
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiat
40RISCO
abrir
Metasploit600
Shopware createInstanceFromNamedArguments PHP Object Instantiation RCE
CVE-2017-1835709 mai 2019
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of t
43RISCO
abrir
GitHub PoC1
Docker runc CVE-2019-5736 exploit Dockerfile. Credits : https://github.com/Frichetten/CVE-2019-5736-PoC.git
CVE-2019-573609 mai 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
Exploit-DB
Zoho ManageEngine ADSelfService Plus 5.7 < 5702 build - Cross-Site Scripting
CVE-2018-20485webappsphp09 mai 2019
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
23RISCO
abrir
Exploit-DB
Zoho ManageEngine ADSelfService Plus 5.7 < 5702 build - Cross-Site Scripting
CVE-2018-20484webappsphp09 mai 2019
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.
23RISCO
abrir
Exploit-DB
Lotus Domino 8.5.3 - 'EXAMINE' Stack Buffer Overflow DEP/ASLR Bypass (NSA's EMPHASISMINE)
CVE-2017-1274remotewindows08 mai 2019
IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle Weblogic Server - 'AsyncResponseService' Deserialization Remote Code Execution (Metasploit)
CVE-2019-2725HIGHsob ataqueransomwareremotemultiple08 mai 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
Exploit-DBVexDay Proof
Google Chrome 72.0.3626.119 - 'FileReader' Use-After-Free (Metasploit)
CVE-2019-5786MEDIUMsob ataqueremotewindows_x8608 mai 2019
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISCO
abrir
Exploit-DBVexDay Proof
PostgreSQL 9.3 - COPY FROM PROGRAM Command Execution (Metasploit)
CVE-2019-9193remotemultiple08 mai 2019
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
GitHub PoC
sasqwatch/CVE-2017-8570
CVE-2017-8570HIGHsob ataque08 mai 2019
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-8570HIGHsob ataque08 mai 2019
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISCO
abrir
Exploit-DB
Prinect Archive System 2015 Release 2.6 - Cross-Site Scripting
CVE-2019-10685webappsmultiple07 mai 2019
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-9621HIGHsob ataque06 mai 2019
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-9978MEDIUMsob ataque06 mai 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
Exploit-DB
LG Supersign EZ CMS - Remote Code Execution (Metasploit)
CVE-2018-17173remotehardware06 mai 2019
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getT
50RISCO
abrir
Exploit-DB
ReadyAPI 2.5.0 / 2.6.0 - Remote Code Execution
CVE-2018-20580webappsmultiple06 mai 2019
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java co
23RISCO
abrir
GitHub PoC79
Zimbra邮件系统漏洞 XXE/RCE/SSRF/Upload GetShell Exploit 1. (CVE-2019-9621 Zimbra<8.8.11 XXE GetShell Exploit)
CVE-2019-9621HIGHsob ataque06 mai 2019
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b
100RISCO
abrir
GitHub PoC6
Wordpress Social Warfare Remote Code Execution (AUTO UPLOAD SHELL)
CVE-2019-9978MEDIUMsob ataque06 mai 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
Exploit-DB
iOS 12.1.3 - 'cfprefsd' Memory Corruption
CVE-2019-7286HIGHsob ataquedosios06 mai 2019
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave
76RISCO
abrir
GitHub PoC1
cve-2019-10678
CVE-2019-1067806 mai 2019
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
28RISCO
abrir
GitHub PoC
cve-2019-9978
CVE-2019-9978MEDIUMsob ataque06 mai 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
GitHub PoC2
leerina/CVE-2019-2725
CVE-2019-2725HIGHsob ataqueransomware05 mai 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2019-981005 mai 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALsob ataque05 mai 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
GitHub PoC227
Exploit for CVE-2019-9810 Firefox on Windows 64-bit.
CVE-2019-981005 mai 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISCO
abrir
GitHub PoC2
A proof of concept for ReadyAPI 2.5.0/2.6.0 Remote Code Execution Vulnerability.
CVE-2018-2058003 mai 2019
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java co
23RISCO
abrir
Exploit-DB
SolarWinds DameWare Mini Remote Control 10.0 - Denial of Service
CVE-2019-9017doswindows03 mai 2019
DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the m
28RISCO
abrir
GitHub PoC22
CVE-2019-9978 - (PoC) RCE in Social WarFare Plugin (<=3.5.2)
CVE-2019-9978MEDIUMsob ataque03 mai 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
Exploit-DB
Crestron AM/Barco wePresent WiPG/Extron ShareLink/Teq AV IT/SHARP PN-L703WA/Optoma WPS-Pro/Blackbox HD WPS/InFocus LiteShow - Remote Command Injection
CVE-2019-3929CRITICALsob ataquewebappshardware03 mai 2019
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RISCO
abrir
Exploit-DB
Zotonic < 0.47.0 mod_admin - Cross-Site Scripting
CVE-2019-11504webappsmultiple03 mai 2019
Zotonic before version 0.47 has mod_admin XSS.
23RISCO
abrir
anteriorpágina 838 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.