Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
Exploit-DB
WordPress Plugin Wisechat 2.6.3 - Reverse Tabnabbing
CVE-2019-6780webappsphp25 jan 2019
The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPost
23RISCO
abrir
Exploit-DB
Zyxel NBG-418N v2 Modem 1.00(AAXM.6)C0 - Cross-Site Request Forgery
CVE-2019-6710webappshardware24 jan 2019
Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.
23RISCO
abrir
Exploit-DBVexDay Proof
Ghostscript 9.26 - Pseudo-Operator Remote Code Execution
CVE-2019-6116remotelinux24 jan 2019
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to
35RISCO
abrir
Exploit-DB
SirsiDynix e-Library 3.5.x - Cross-Site Scripting
CVE-2018-20503webappscgi24 jan 2019
Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter.
23RISCO
abrir
GitHub PoC228
CVE-2019-1652 /CVE-2019-1653 Exploits For Dumping Cisco RV320 Configurations & Debugging Data AND Remote Root Exploit!
CVE-2019-1652HIGHsob ataque24 jan 2019
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RISCO
abrir
Metasploit300
Cisco RV320/RV326 Configuration Disclosure
CVE-2019-1653HIGHsob ataque24 jan 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir
GitHub PoC370
CVE-2018-8581
CVE-2018-8581HIGHsob ataqueransomware24 jan 2019
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
76RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-1653HIGHsob ataque24 jan 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-1652HIGHsob ataque24 jan 2019
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-8581HIGHsob ataqueransomware24 jan 2019
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
76RISCO
abrir
GitHub PoC1
This is a exp of CVE-2018-15473
CVE-2018-15473MEDIUM23 jan 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
Exploit-DB
Nagios XI 5.5.6 - Remote Code Execution / Privilege Escalation
CVE-2018-15710webappslinux23 jan 2019
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
50RISCO
abrir
Exploit-DB
Nagios XI 5.5.6 - Remote Code Execution / Privilege Escalation
CVE-2018-15708webappslinux23 jan 2019
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RISCO
abrir
GitHub PoC1
Writeup for CVE-2017-16995 Linux BPF Local Privilege Escalation
CVE-2017-1699522 jan 2019
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
Exploit-DB
Linux Kernel 4.13 - 'compat_get_timex()' Leak Kernel Pointer
CVE-2018-11508doslinux21 jan 2019
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitiv
23RISCO
abrir
GitHub PoC1
cve-2018-15961
CVE-2018-15961CRITICALsob ataque21 jan 2019
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISCO
abrir
Metasploit300
Microsoft Exchange Privilege Escalation Exploit
CVE-2019-072421 jan 2019
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of
23RISCO
abrir
Exploit-DB
GattLib 0.2 - Stack Buffer Overflow
CVE-2019-6498remotelinux21 jan 2019
GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused.
23RISCO
abrir
GitHub PoC
CVE-2015-2794 auto finder
CVE-2015-279420 jan 2019
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain S
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-4878HIGHsob ataqueransomware20 jan 2019
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-10562CRITICALsob ataqueransomware20 jan 2019
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-8174HIGHsob ataqueransomware20 jan 2019
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALsob ataqueransomware20 jan 2019
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'NewScObjectNoCtor' or 'InitProto' Type Confusion
CVE-2019-0539doswindows18 jan 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISCO
abrir
GitHub PoC2
cve-2018-8453 exp
CVE-2018-8453HIGHsob ataqueransomware18 jan 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC119
cve-2018-8453 exp
CVE-2018-8453HIGHsob ataqueransomware18 jan 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'InitClass' Type Confusion
CVE-2019-0539doswindows18 jan 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISCO
abrir
Exploit-DB
Joomla! Core 3.9.1 - Persistent Cross-Site Scripting in Global Configuration Textfilter Settings
CVE-2019-6263webappsphp18 jan 2019
An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allo
23RISCO
abrir
Exploit-DB
Pydio / AjaXplorer < 5.0.4 - (Unauthenticated) Arbitrary File Upload
CVE-2013-6227webappsphp18 jan 2019
Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly
23RISCO
abrir
GitHub PoC6
praveensutar/CVE-2019-6263-Joomla-POC
CVE-2019-626318 jan 2019
An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allo
23RISCO
abrir
anteriorpágina 854 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.