Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
Exploit-DBVexDay Proof
systemd - DynamicUser can Create setuid Binaries when Assisted by Another Process
CVE-2019-3843MEDIUMdoslinux26 abr 2019
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allo
33RISCO
abrir
Exploit-DBVexDay Proof
systemd - DynamicUser can Create setuid Binaries when Assisted by Another Process
CVE-2019-3844MEDIUMdoslinux26 abr 2019
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of
33RISCO
abrir
Exploit-DB
Apache Pluto 3.0.0 / 3.0.1 - Persistent Cross-Site Scripting
CVE-2019-0186webappsjava26 abr 2019
The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XS
28RISCO
abrir
GitHub PoC9
The official exploit code for LibreNMS v1.46 Remote Code Execution CVE-2018-20434
CVE-2018-2043425 abr 2019
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to htm
60RISCO
abrir
GitHub PoC
likekabin/CVE-2018-20250
CVE-2018-20250HIGHsob ataqueransomware25 abr 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
Exploit-DBVexDay Proof
RARLAB WinRAR 5.61 - ACE Format Input Validation Remote Code Execution (Metasploit)
CVE-2018-20250HIGHsob ataqueransomwarelocalwindows25 abr 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
GitHub PoC1
WebLogic CNVD-C-2019_48814 CVE-2017-10271
CVE-2017-10271HIGHsob ataqueransomware25 abr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC105
CVE-2019-2725poc汇总 更新绕过CVE-2017-10271补丁POC
CVE-2017-10271HIGHsob ataqueransomware25 abr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
Exploit-DB
JioFi 4G M2S 1.0.2 - 'mask' Cross-Site Scripting
CVE-2019-7438webappshardware25 abr 2019
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter.
23RISCO
abrir
Exploit-DB
JioFi 4G M2S 1.0.2 - Denial of Service
CVE-2019-7439doshardware25 abr 2019
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter.
23RISCO
abrir
GitHub PoC114
WebLogic CNVD-C-2019_48814 CVE-2017-10271 Scan By 7kbstorm
CVE-2017-10271HIGHsob ataqueransomware25 abr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC105
CVE-2019-2725poc汇总 更新绕过CVE-2017-10271补丁POC
CVE-2019-2725HIGHsob ataqueransomware25 abr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHsob ataqueransomware25 abr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC4
A C# module to detect if a Jenkins server is vulnerable to the RCE vulnerability found in CVE-2019-1003000 (chained with CVE-2018-1000861 for pre-auth RCE)
CVE-2019-100300024 abr 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISCO
abrir
Exploit-DBVexDay Proof
VirtualBox 6.0.4 r128413 - COM RPC Interface Code Injection Host Privilege Escalation
CVE-2019-2721localwindows24 abr 2019
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISCO
abrir
Metasploit600
WP Database Backup RCE
CVE-2019-25224CRITICAL24 abr 2019
WP Database Backup < 5.2 - Unauthenticated OS Command Injection
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-1000861CRITICALsob ataque24 abr 2019
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISCO
abrir
GitHub PoC
KeyStrOke95/nfsen_1.3.7_CVE-2017-6971
CVE-2017-697124 abr 2019
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary comma
28RISCO
abrir
Metasploit600
Pulse Secure VPN Arbitrary Command Execution
CVE-2019-11539HIGHsob ataqueransomware24 abr 2019
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISCO
abrir
GitHub PoC4
A C# module to detect if a Jenkins server is vulnerable to the RCE vulnerability found in CVE-2019-1003000 (chained with CVE-2018-1000861 for pre-auth RCE)
CVE-2018-1000861CRITICALsob ataque24 abr 2019
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISCO
abrir
Metasploit300
Pulse Secure VPN Arbitrary File Disclosure
CVE-2019-11510CRITICALsob ataqueransomware24 abr 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-100300024 abr 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISCO
abrir
Exploit-DBVexDay Proof
systemd - Lack of Seat Verification in PAM Module Permits Spoofing Active Session to polkit
CVE-2019-3842MEDIUMdoslinux23 abr 2019
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using t
33RISCO
abrir
Metasploit600
Oracle Weblogic Server Deserialization RCE - AsyncResponseService
CVE-2019-2725HIGHsob ataqueransomware23 abr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
Exploit-DB
74CMS 5.0.1 - Cross-Site Request Forgery (Add New Admin User)
CVE-2019-11374webappsphp22 abr 2019
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
23RISCO
abrir
Exploit-DB
UliCMS 2019.2 / 2019.1 - Multiple Cross-Site Scripting
CVE-2019-11398webappsphp22 abr 2019
Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitra
23RISCO
abrir
Exploit-DB
Msvod 10 - Cross-Site Request Forgery (Change User Information)
CVE-2019-11375webappsphp22 abr 2019
Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.
23RISCO
abrir
Exploit-DB
QNAP myQNAPcloud Connect 1.3.4.0317 - 'Username/Password' Denial of Service
CVE-2019-7181doshardware22 abr 2019
Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the pr
23RISCO
abrir
GitHub PoC1
rakesh143/CVE-2019-0808
CVE-2019-0808HIGHsob ataque21 abr 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISCO
abrir
GitHub PoC
cve-2017-17485 PoC
CVE-2017-17485CRITICAL21 abr 2019
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o
60RISCO
abrir
anteriorpágina 840 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.