Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
Exploit-DB
Rukovoditel ERP & CRM 2.4.1 - 'path' Cross-Site Scripting
CVE-2019-7400webappsphp26 mar 2019
Rukovoditel before 2.4.1 allows XSS.
23RISCO
abrir
Metasploit300
CMS Made Simple Authenticated RCE via object injection
CVE-2019-905526 mar 2019
An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php an
23RISCO
abrir
Exploit-DB
Firefox < 66.0.1 - 'Array.prototype.slice' Buffer Overflow
CVE-2019-9810dosmultiple26 mar 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISCO
abrir
GitHub PoC67
Array.prototype.slice wrong alias information.
CVE-2019-981025 mar 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISCO
abrir
Metasploit600
Atlassian Confluence Widget Connector Macro Velocity Template Injection
CVE-2019-3396CRITICALsob ataqueransomware25 mar 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2019-0808HIGHsob ataque25 mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISCO
abrir
GitHub PoC47
cve-2019-0808-poc
CVE-2019-0808HIGHsob ataque25 mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISCO
abrir
VulnCheck XDB
client-side
CVE-2019-9978MEDIUMsob ataque25 mar 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
Exploit-DBVexDay Proof
VMware Workstation 14.1.5 / VMware Player 15.0.2 - Host VMX Process Impersonation Hijack Privilege Escalation
CVE-2018-5511localwindows25 mar 2019
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Manageme
28RISCO
abrir
Exploit-DBVexDay Proof
VMware Workstation 14.1.5 / VMware Player 15 - Host VMX Process COM Class Hijack Privilege Escalation
CVE-2019-5512localwindows25 mar 2019
VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately
23RISCO
abrir
GitHub PoC8
CVE-2019-9978 - RCE on a Wordpress plugin: Social Warfare < 3.5.3
CVE-2019-9978MEDIUMsob ataque25 mar 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALsob ataqueransomware24 mar 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
Metasploit600
Horde Form File Upload Vulnerability
CVE-2019-985824 mar 2019
Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulner
23RISCO
abrir
GitHub PoC1
CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware24 mar 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-5418HIGHsob ataque23 mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
GitHub PoC132
RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)
CVE-2019-5418HIGHsob ataque23 mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
GitHub PoC129
CVE-2019-0604
CVE-2019-0604CRITICALsob ataqueransomware23 mar 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISCO
abrir
GitHub PoC
PoC Scan. (cve-2011-3368)
CVE-2011-336822 mar 2019
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does
60RISCO
abrir
GitHub PoC
CVE-2017-5638 (PoC Exploits)
CVE-2017-5638CRITICALsob ataqueransomware22 mar 2019
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALsob ataqueransomware22 mar 2019
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
Exploit-DB
Canarytokens 2019-03-01 - Detection Bypass
CVE-2019-9768doswindows21 mar 2019
Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timesta
28RISCO
abrir
VulnCheck XDB
initial-access
CVE-2016-009521 mar 2019
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RISCO
abrir
Exploit-DB
DVD X Player 5.5.3 - '.plf' Buffer Overflow
CVE-2018-9128localwindows21 mar 2019
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RISCO
abrir
GitHub PoC8
CVE-2019-5420 (Ruby on Rails)
CVE-2019-542021 mar 2019
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir
Metasploit0
Chrome 72.0.3626.119 FileReader UaF exploit for Windows 7 x86
CVE-2019-5786MEDIUMsob ataque21 mar 2019
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISCO
abrir
Exploit-DB
Rails 5.2.1 - Arbitrary File Content Disclosure
CVE-2019-5418HIGHsob ataquewebappsmultiple21 mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
Exploit-DB
PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Request Forgery
CVE-2019-6282webappshardware20 mar 2019
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpag
23RISCO
abrir
GitHub PoC6
CVE-2018-11686 - FlexPaper PHP Publish Service RCE <= 2.3.6
CVE-2018-1168620 mar 2019
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_c
50RISCO
abrir
Metasploit600
PostgreSQL COPY FROM PROGRAM Command Execution
CVE-2019-919320 mar 2019
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
GitHub PoC255
FileReader Exploit
CVE-2019-5786MEDIUMsob ataque20 mar 2019
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISCO
abrir
anteriorpágina 845 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.