Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
VulnCheck XDB
initial-access
CVE-2017-10271HIGHsob ataqueransomware20 mar 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC255
FileReader Exploit
CVE-2019-5786MEDIUMsob ataque20 mar 2019
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISCO
abrir
Exploit-DB
PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Request Forgery
CVE-2019-6282webappshardware20 mar 2019
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpag
23RISCO
abrir
GitHub PoC6
CVE-2018-11686 - FlexPaper PHP Publish Service RCE <= 2.3.6
CVE-2018-1168620 mar 2019
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_c
50RISCO
abrir
Metasploit600
PostgreSQL COPY FROM PROGRAM Command Execution
CVE-2019-919320 mar 2019
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
GitHub PoC14
GUI版 EXP
CVE-2018-133520 mar 2019
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISCO
abrir
Exploit-DBVexDay Proof
Google Chrome < M73 - FileSystemOperationRunner Use-After-Free
CVE-2019-5788dosmultiple19 mar 2019
An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allo
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft VBScript - VbsErase Memory Corruption
CVE-2019-0667doswindows19 mar 2019
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - Flash click2play Bypass with CObjectElement::FinalCreateObject
CVE-2019-0612doswindows19 mar 2019
A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash obj
28RISCO
abrir
Exploit-DBVexDay Proof
Google Chrome < M73 - MidiManagerWin Use-After-Free
CVE-2019-5789dosmultiple19 mar 2019
An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 - VBScript Execution Policy Bypass in MSHTML
CVE-2019-0768doswindows19 mar 2019
A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restri
35RISCO
abrir
Exploit-DB
Gila CMS 1.9.1 - Cross-Site Scripting
CVE-2019-9647webappsphp19 mar 2019
Gila CMS 1.9.1 has XSS.
23RISCO
abrir
Exploit-DBVexDay Proof
Google Chrome < M73 - Data Race in ExtensionsGuestViewMessageFilter
CVE-2019-5796dosmultiple19 mar 2019
Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially explo
23RISCO
abrir
Exploit-DBVexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
CVE-2019-1003000remotejava19 mar 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISCO
abrir
Exploit-DBVexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
CVE-2019-1003002remotejava19 mar 2019
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RISCO
abrir
Exploit-DBVexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
CVE-2019-1003001remotejava19 mar 2019
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RISCO
abrir
GitHub PoC36
A multi-threaded Golang scanner to identify Ruby endpoints vulnerable to CVE-2019-5418
CVE-2019-5418HIGHsob ataque19 mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
Exploit-DBVexDay Proof
Google Chrome < M73 - Double-Destruction Race in StoragePartitionService
CVE-2019-5797HIGHdosmultiple19 mar 2019
Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap c
41RISCO
abrir
Exploit-DB
MyBB Upcoming Events Plugin 1.32 - Cross-Site Scripting
CVE-2019-9650webappsphp19 mar 2019
An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name
23RISCO
abrir
GitHub PoC
Herramienta para revisar si es que un payload tiene componente malicioso de acuerdo a CVE-2018-20250
CVE-2018-20250HIGHsob ataqueransomware19 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
Metasploit300
IBM BigFix Relay Server Sites and Package Enum
CVE-2019-4061MEDIUM18 mar 2019
IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the upd
33RISCO
abrir
GitHub PoC5
File Content Disclosure on Rails Test Case - CVE-2019-5418
CVE-2019-5418HIGHsob ataque18 mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
GitHub PoC7
xConsoIe/CVE-2019-0193
CVE-2019-0193HIGHsob ataque18 mar 2019
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISCO
abrir
Exploit-DBVexDay Proof
BMC Patrol Agent - Privilege Escalation Code Execution Execution (Metasploit)
CVE-2018-20735remotemultiple18 mar 2019
An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for l
38RISCO
abrir
GitHub PoC6
thinkphp5.*Rce CVE-2018-20062
CVE-2018-20062CRITICALsob ataque17 mar 2019
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-20062CRITICALsob ataque17 mar 2019
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-5418HIGHsob ataque16 mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
GitHub PoC201
CVE-2019-5418 - File Content Disclosure on Ruby on Rails
CVE-2019-5418HIGHsob ataque16 mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
GitHub PoC
cve-2018-16283
CVE-2018-1628315 mar 2019
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
50RISCO
abrir
GitHub PoC10
Noodle [Moodle RCE] (v3.4.1) - CVE-2018-1133
CVE-2018-113315 mar 2019
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code exec
35RISCO
abrir
anteriorpágina 846 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.