Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
79.386 exploits
Exploit-DB
Pydio / AjaXplorer < 5.0.4 - (Unauthenticated) Arbitrary File Upload
CVE-2013-6227webappsphp18 jan 2019
Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle Reports Developer Component 12.2.1.3 - Cross-site Scripting
CVE-2019-2413webappsmultiple17 jan 2019
Vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware (subcomponent: Valid Session). The s
23RISCO
abrir
GitHub PoC
cve-2017-1000117
CVE-2017-100011717 jan 2019
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RISCO
abrir
GitHub PoC1
cve-2017-8046
CVE-2017-804617 jan 2019
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISCO
abrir
GitHub PoC
cve-2017-12615
CVE-2017-12615HIGHsob ataqueransomware17 jan 2019
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
GitHub PoC
cve-2016-10033
CVE-2016-10033CRITICALsob ataque17 jan 2019
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
GitHub PoC
cve-2018-1273
CVE-2018-1273CRITICALsob ataqueransomware17 jan 2019
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISCO
abrir
Metasploit600
BMC Patrol Agent Privilege Escalation Cmd Execution
CVE-2018-2073517 jan 2019
An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for l
38RISCO
abrir
Metasploit600
Webmin Upload Authenticated RCE
CVE-2019-962417 jan 2019
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Dow
43RISCO
abrir
Exploit-DB
GL-AR300M-Lite 2.27 - (Authenticated) Command Injection / Arbitrary File Download / Directory Traversal
CVE-2019-6275webappshardware16 jan 2019
Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attac
28RISCO
abrir
Metasploit300
ES File Explorer Open Port
CVE-2019-644716 jan 2019
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISCO
abrir
Exploit-DB
GL-AR300M-Lite 2.27 - (Authenticated) Command Injection / Arbitrary File Download / Directory Traversal
CVE-2019-6272webappshardware16 jan 2019
Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attacker
28RISCO
abrir
Exploit-DB
ShoreTel / Mitel Connect ONSITE 19.49.5200.0 - Remote Code Execution
CVE-2018-5782webappsphp16 jan 2019
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.
28RISCO
abrir
Exploit-DBVexDay Proof
NTPsec 1.1.2 - 'ntp_control' Out-of-Bounds Read (PoC)
CVE-2019-6444doslinux16 jan 2019
An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read be
35RISCO
abrir
Exploit-DBVexDay Proof
NTPsec 1.1.2 - 'ntp_control' (Authenticated) NULL Pointer Dereference (PoC)
CVE-2019-6445doslinux16 jan 2019
An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can cause a NULL pointer dereference and ntpd
28RISCO
abrir
Exploit-DB
GL-AR300M-Lite 2.27 - (Authenticated) Command Injection / Arbitrary File Download / Directory Traversal
CVE-2019-6273webappshardware16 jan 2019
download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files.
28RISCO
abrir
Exploit-DBVexDay Proof
NTPsec 1.1.2 - 'ctl_getitem' Out-of-Bounds Read (PoC)
CVE-2019-6443doslinux16 jan 2019
An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - 'RestrictedErrorInfo' Unmarshal Section Handle Use-After-Free
CVE-2019-0570doswindows16 jan 2019
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka "Windo
23RISCO
abrir
Exploit-DB
GL-AR300M-Lite 2.27 - (Authenticated) Command Injection / Arbitrary File Download / Directory Traversal
CVE-2019-6274webappshardware16 jan 2019
Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote atta
28RISCO
abrir
Exploit-DBVexDay Proof
Fortinet FortiGate FortiOS < 6.0.3 - LDAP Credential Disclosure
CVE-2018-13374MEDIUMsob ataqueransomwarewebappshardware16 jan 2019
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 al
75RISCO
abrir
Exploit-DB
Blueimp's jQuery File Upload 9.22.0 - Arbitrary File Upload Exploit
CVE-2018-9206webappsphp16 jan 2019
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - XmlDocument Insecure Sharing Privilege Escalation
CVE-2019-0555localwindows16 jan 2019
An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape
23RISCO
abrir
Exploit-DBVexDay Proof
blueman - set_dhcp_handler D-Bus Privilege Escalation (Metasploit)
CVE-2015-8612locallinux16 jan 2019
The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users
38RISCO
abrir
Exploit-DBVexDay Proof
NTPsec 1.1.2 - 'config' (Authenticated) Out-of-Bounds Write Denial of Service (PoC)
CVE-2019-6442doslinux16 jan 2019
An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a
28RISCO
abrir
Exploit-DBVexDay Proof
WebKit JSC JIT - GetIndexedPropertyStorage Use-After-Free
CVE-2018-4442dosmultiple16 jan 2019
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1,
23RISCO
abrir
Exploit-DB
1Password < 7.0 - Denial of Service
CVE-2018-13042dosandroid15 jan 2019
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - DSSVC CanonicalAndValidateFilePath Security Feature Bypass
CVE-2019-0571localwindows14 jan 2019
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations,
28RISCO
abrir
Exploit-DB
xorg-x11-server < 1.20.3 (Solaris 11) - 'inittab Local Privilege Escalation
CVE-2018-14665localsolaris14 jan 2019
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - SSPI Network Authentication Session 0 Privilege Escalation
CVE-2019-0543HIGHsob ataqueransomwarelocalwindows14 jan 2019
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft W
71RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - COM Desktop Broker Privilege Escalation
CVE-2019-0552localwindows14 jan 2019
An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability."
23RISCO
abrir
anteriorpágina 856 / 2.647próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.