Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
GitHub PoC2
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Print Archive System v2015 release 2.6
CVE-2019-1068502 abr 2019
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
23RISCO
abrir
Exploit-DB
JioFi 4G M2S 1.0.2 - Cross-Site Request Forgery
CVE-2019-7440webappshardware02 abr 2019
JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_S
23RISCO
abrir
Exploit-DB
CMS Made Simple < 2.2.10 - SQL Injection
CVE-2019-9053webappsphp02 abr 2019
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
Metasploit300
WordPress Google Maps Plugin SQL Injection
CVE-2019-1069202 abr 2019
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize
40RISCO
abrir
Exploit-DB
WordPress Plugin PayPal Checkout Payment Gateway 1.6.8 - Parameter Tampering
CVE-2019-7441webappsphp02 abr 2019
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-0160HIGHsob ataque02 abr 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
Exploit-DB
LimeSurvey < 3.16 - Remote Code Execution
CVE-2018-17057webappsphp02 abr 2019
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar://
28RISCO
abrir
GitHub PoC4
Just a PoC tool to extract password using CVE-2019-1653.
CVE-2019-1653HIGHsob ataque01 abr 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-5418HIGHsob ataque01 abr 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-1653HIGHsob ataque01 abr 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir
GitHub PoC3
a demo for Ruby on Rails CVE-2019-5418
CVE-2019-5418HIGHsob ataque01 abr 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
GitHub PoC10
eps漏洞(CVE-2017-0261)漏洞分析
CVE-2017-0261HIGHsob ataque31 mar 2019
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the softwar
93RISCO
abrir
VulnCheck XDB
local
CVE-2017-0261HIGHsob ataque31 mar 2019
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the softwar
93RISCO
abrir
GitHub PoC36
CVE-2018-9276 PRTG < 18.2.39 Authenticated Command Injection (Reverse Shell)
CVE-2018-9276HIGHsob ataque31 mar 2019
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-9276HIGHsob ataque31 mar 2019
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISCO
abrir
GitHub PoC28
patches for SNYK-JS-JQUERY-174006, CVE-2019-11358, CVE-2019-5428
CVE-2019-1135830 mar 2019
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISCO
abrir
GitHub PoC23
ASUS SmartHome Exploit for CVE-2019-11061 and CVE-2019-11063
CVE-2019-11061CRITICAL29 mar 2019
HG100 has a broken access control vulnerability in its Web API Server
48RISCO
abrir
GitHub PoC3
IBM Lotus Domino <= R8 Password Hash Extraction Exploit
CVE-2005-242829 mar 2019
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hid
60RISCO
abrir
Exploit-DB
Thomson Reuters Concourse & Firm Central < 2.13.0097 - Directory Traversal / Local File Inclusion
CVE-2019-8385webappswindows28 mar 2019
An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and loca
28RISCO
abrir
Exploit-DB
Fat Free CRM 0.19.0 - HTML Injection
CVE-2019-10226webappsruby28 mar 2019
HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to th
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle Weblogic Server Deserialization RCE - Raw Object (Metasploit)
CVE-2015-4852CRITICALsob ataqueremotemultiple28 mar 2019
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISCO
abrir
Exploit-DBVexDay Proof
CMS Made Simple (CMSMS) Showtime2 - File Upload Remote Code Execution (Metasploit)
CVE-2019-9692remotephp28 mar 2019
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard
50RISCO
abrir
Exploit-DB
i-doit 1.12 - 'qr.php' Cross-Site Scripting
CVE-2019-6965webappsphp28 mar 2019
An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.
23RISCO
abrir
GitHub PoC
cve-2016-9838
CVE-2016-983827 mar 2019
An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of
28RISCO
abrir
Metasploit600
AIS logistics ESEL-Server Unauth SQL Injection RCE
CVE-2019-1012327 mar 2019
SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app)
50RISCO
abrir
Metasploit600
AwindInc SNMP Service Command Injection
CVE-2017-1670927 mar 2019
Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote
60RISCO
abrir
GitHub PoC
stillan00b/CVE-2019-5736
CVE-2019-573627 mar 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC
cve-2019-5420
CVE-2019-542027 mar 2019
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir
Metasploit300
CMS Made Simple Authenticated RCE via object injection
CVE-2019-905526 mar 2019
An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php an
23RISCO
abrir
Exploit-DB
Rukovoditel ERP & CRM 2.4.1 - 'path' Cross-Site Scripting
CVE-2019-7400webappsphp26 mar 2019
Rukovoditel before 2.4.1 allows XSS.
23RISCO
abrir
anteriorpágina 844 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.