Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
Exploit-DB
Cisco WebEx Meetings < 33.6.6 / < 33.9.1 - Privilege Escalation
CVE-2019-1674HIGHlocalwindows01 mar 2019
Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools Update Service Command Injection Vulnerability
46RISCO
abrir
Exploit-DB
WebKitGTK 2.23.90 / WebKitGTK+ 2.22.6 - Denial of Service
CVE-2019-8375doslinux28 fev 2019
The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products
28RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component J2Store < 3.3.7 - SQL Injection
CVE-2019-9184webappsphp28 fev 2019
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitr
23RISCO
abrir
GitHub PoC2
STP5940/CVE-2018-20250
CVE-2018-20250HIGHsob ataqueransomware28 fev 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHsob ataqueransomware28 fev 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
Exploit-DB
Alcatel-Lucent (Nokia) GPON I-240W-Q - Buffer Overflow
CVE-2019-3921remotehardware28 fev 2019
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via
28RISCO
abrir
GitHub PoC
yyqs2008/CVE-2019-5736-PoC-2
CVE-2019-573628 fev 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
Metasploit400
Cisco RV110W/RV130(W)/RV215W Routers Management Interface Remote Command Execution
CVE-2019-1663CRITICAL27 fev 2019
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RISCO
abrir
Exploit-DB
PHP 7.2 - 'imagecolormatch()' Out of Band Heap Write
CVE-2019-6977remotephp27 fev 2019
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch funct
45RISCO
abrir
GitHub PoC2
Demonstration of the Heartbleed Bug CVE-2014-0160
CVE-2014-0160HIGHsob ataque27 fev 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
cve-2019-6340
CVE-2019-6340HIGHsob ataque26 fev 2019
Drupal core - Highly critical - Remote Code Execution
100RISCO
abrir
Metasploit600
elFinder PHP Connector exiftran Command Injection
CVE-2019-919426 fev 2019
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISCO
abrir
Exploit-DB
Jenkins Plugin Script Security 1.49/Declarative 1.3.4/Groovy 2.60 - Remote Code Execution
CVE-2018-1999002webappsjava25 fev 2019
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framewor
45RISCO
abrir
Exploit-DB
Jenkins Plugin Script Security 1.49/Declarative 1.3.4/Groovy 2.60 - Remote Code Execution
CVE-2019-1003000webappsjava25 fev 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISCO
abrir
GitHub PoC12
CVE-2019-6340 POC Drupal rce
CVE-2019-6340HIGHsob ataque25 fev 2019
Drupal core - Highly critical - Remote Code Execution
100RISCO
abrir
GitHub PoC2
CVE-2019-6340 Drupal 8.6.9 REST Auth Bypass examples
CVE-2019-6340HIGHsob ataque25 fev 2019
Drupal core - Highly critical - Remote Code Execution
100RISCO
abrir
Exploit-DB
Drupal < 8.6.9 - REST Module Remote Code Execution
CVE-2019-6340HIGHsob ataquewebappsphp25 fev 2019
Drupal core - Highly critical - Remote Code Execution
100RISCO
abrir
GitHub PoC73
A simple PoC for WordPress RCE (author priviledge), refer to CVE-2019-8942 and CVE-2019-8943.
CVE-2019-894225 fev 2019
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISCO
abrir
Exploit-DB
zzzphp CMS 1.6.1 - Remote Code Execution
CVE-2019-9041webappsphp25 fev 2019
An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filter
50RISCO
abrir
GitHub PoC153
🐱‍💻 Poc of CVE-2019-7238 - Nexus Repository Manager 3 Remote Code Execution 🐱‍💻
CVE-2019-7238CRITICALsob ataque24 fev 2019
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-7238CRITICALsob ataque24 fev 2019
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-6340HIGHsob ataque23 fev 2019
Drupal core - Highly critical - Remote Code Execution
100RISCO
abrir
GitHub PoC42
Environment for CVE-2019-6340 (Drupal)
CVE-2019-6340HIGHsob ataque23 fev 2019
Drupal core - Highly critical - Remote Code Execution
100RISCO
abrir
GitHub PoC21
Proof of concept code in C# to exploit the WinRAR ACE file extraction path (CVE-2018-20250).
CVE-2018-20250HIGHsob ataqueransomware23 fev 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHsob ataqueransomware23 fev 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
Exploit-DB
Drupal < 8.6.10 / < 8.5.11 - REST Module Remote Code Execution
CVE-2019-6340HIGHsob ataquewebappsphp23 fev 2019
Drupal core - Highly critical - Remote Code Execution
100RISCO
abrir
Exploit-DBVexDay Proof
Nuuo Central Management - (Authenticated) SQL Server SQL Injection (Metasploit)
CVE-2018-18982remotewindows22 fev 2019
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can b
50RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHsob ataqueransomware22 fev 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
Exploit-DB
WebKit JSC - reifyStaticProperty Needs to set the PropertyAttribute::CustomAccessor flag for CustomGetterSetter
CVE-2019-6215dosmultiple22 fev 2019
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safa
23RISCO
abrir
GitHub PoC26
010 Editor template for ACE archive format & CVE-2018-2025[0-3]
CVE-2018-20250HIGHsob ataqueransomware22 fev 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
anteriorpágina 849 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.