Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
GitHub PoC5
Exploiting CVE-2016-10277 for Secure Boot and Device Locking bypass
CVE-2016-1027704 fev 2019
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute
23RISCO
abrir
GitHub PoC
cve-2018-3811
CVE-2018-381102 fev 2019
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthentica
35RISCO
abrir
GitHub PoC
cve-2018-3810
CVE-2018-381002 fev 2019
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RISCO
abrir
Exploit-DB
SureMDM < 2018-11 Patch - Local / Remote File Inclusion
CVE-2018-15657webappswindows01 fev 2019
An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
macOS XNU - Copy-on-Write Behaviour Bypass via Partial-Page Truncation of File
CVE-2019-6208dosmacos31 jan 2019
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Moja
23RISCO
abrir
Exploit-DBVexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Kernel Heap Overflow in PF_KEY due to Lack of Bounds Checking when Retrieving Statistics
CVE-2019-6213dosmultiple31 jan 2019
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3,
23RISCO
abrir
Exploit-DBVexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Arbitrary mach Port Name Deallocation in XPC Services due to Invalid mach Message Parsing in _xpc_serializer_unpack
CVE-2019-6218dosmultiple31 jan 2019
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave
23RISCO
abrir
Exploit-DBVexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 XNU - 'vm_map_copy' Optimization which Requires Atomicity isn't Atomic
CVE-2019-6205dosmultiple31 jan 2019
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Moja
23RISCO
abrir
Exploit-DBVexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Sandbox Escapes due to Type Confusions and Memory Safety Issues in iohideventsystem
CVE-2019-6214dosmultiple31 jan 2019
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.1
23RISCO
abrir
GitHub PoC16
iOS 12.0 -> 12.1.2 Incomplete Osiris Jailbreak with CVE-2019-6225 by GeoSn0w (FCE365)
CVE-2019-622531 jan 2019
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
28RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-1653HIGHsob ataque30 jan 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir
Exploit-DBVexDay Proof
iOS/macOS 10.13.6 - 'if_ports_used_update_wakeuuid()' 16-byte Uninitialized Kernel Stack Disclosure
CVE-2019-6209dosmultiple30 jan 2019
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input
23RISCO
abrir
GitHub PoC1
NSE script to scan for Cisco routers vulnerable to CVE-2019-1653
CVE-2019-1653HIGHsob ataque30 jan 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir
GitHub PoC1
Python 3 implementation of an existing CVE-2011-3556 proof of concept (PoC).
CVE-2011-355629 jan 2019
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RISCO
abrir
GitHub PoC
Exploit script for Crossfire 1.9.0
CVE-2006-123629 jan 2019
Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrar
28RISCO
abrir
Exploit-DBVexDay Proof
Cisco Firepower Management Center 6.2.2.2 / 6.2.3 - Cross-Site Scripting
CVE-2019-1642MEDIUMwebappshardware28 jan 2019
Cisco Firepower Management Center Cross-Site Scripting Vulnerability
33RISCO
abrir
Exploit-DB
Rundeck Community Edition < 3.0.13 - Persistent Cross-Site Scripting
CVE-2019-6804webappsjava28 jan 2019
An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascrip
23RISCO
abrir
Exploit-DB
CloudMe Sync 1.11.2 Buffer Overflow - WoW64 (DEP Bypass)
CVE-2018-6892remotewindows_x86-6428 jan 2019
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RISCO
abrir
Exploit-DB
AirTies Air5341 Modem 1.0.0.12 - Cross-Site Request Forgery
CVE-2019-6967webappshardware28 jan 2019
AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.
28RISCO
abrir
GitHub PoC2
DVR username password recovery.
CVE-2018-999528 jan 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
Exploit-DB
MyBB IP History Logs Plugin 1.0.2 - Cross-Site Scripting
CVE-2019-6979webappsphp28 jan 2019
An issue was discovered in the User IP History Logs (aka IP_History_Logs) plugin 1.0.2 for MyBB. There is XSS via the ad
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-999528 jan 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
Exploit-DB
Sricam gSOAP 2.8 - Denial of Service
CVE-2019-6973doshardware28 jan 2019
Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server
28RISCO
abrir
Exploit-DB
LogonBox Limited / Hypersocket Nervepoint Access Manager - (Unauthenticated) Insecure Direct Object Reference
CVE-2019-6716webappsmultiple28 jan 2019
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 thr
23RISCO
abrir
Exploit-DB
Cisco RV300 / RV320 - Information Disclosure
CVE-2019-1653HIGHsob ataquewebappshardware28 jan 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-1885226 jan 2019
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-in
35RISCO
abrir
Metasploit600
Schneider Electric Pelco Endura NET55XX Encoder
CVE-2019-681425 jan 2019
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 wh
50RISCO
abrir
Exploit-DBVexDay Proof
Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 - Command Injection
CVE-2019-1652HIGHsob ataquewebappshardware25 jan 2019
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RISCO
abrir
Exploit-DBVexDay Proof
iOS/macOS - 'task_swap_mach_voucher()' Use-After-Free
CVE-2019-6225dosmultiple25 jan 2019
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
28RISCO
abrir
Exploit-DB
Lua 5.3.5 - 'debug.upvaluejoin' Use After Free
CVE-2019-6706dosmultiple25 jan 2019
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attack
28RISCO
abrir
anteriorpágina 853 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.