Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
79.386 exploits
Exploit-DB
ZTE MF65 BD_HDV6MF65V1.0.0B05 - Cross-Site Scripting
CVE-2018-7355webappshardware09 jan 2019
All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scrip
23RISCO
abrir
GitHub PoC678
ES File Explorer Open Port Vulnerability - CVE-2019-6447
CVE-2019-644709 jan 2019
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISCO
abrir
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2019-100300208 jan 2019
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RISCO
abrir
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2019-100300508 jan 2019
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.50 and earlier in src/main/java/org/jenkinsci/
23RISCO
abrir
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2018-1000861CRITICALsob ataque08 jan 2019
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISCO
abrir
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2019-100300108 jan 2019
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RISCO
abrir
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2019-1003029CRITICALsob ataque08 jan 2019
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/
100RISCO
abrir
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2019-100300008 jan 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISCO
abrir
Exploit-DB
Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal
CVE-2018-20526webappsphp07 jan 2019
Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
60RISCO
abrir
GitHub PoC
poc for 0263
CVE-2017-0263HIGHsob ataque07 jan 2019
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
76RISCO
abrir
Exploit-DB
MyBB OUGC Awards Plugin 1.8.3 - Persistent Cross-Site Scripting
CVE-2019-3501webappsphp07 jan 2019
The OUGC Awards plugin before 1.8.19 for MyBB allows XSS via a crafted award reason that is mishandled on the awards pag
23RISCO
abrir
Exploit-DB
Ajera Timesheets 9.10.16 - Deserialization of Untrusted Data
CVE-2018-20221webappswindows07 jan 2019
Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserializ
28RISCO
abrir
Exploit-DB
Huawei E5330 21.210.09.00.158 - Cross-Site Request Forgery (Send SMS)
CVE-2014-5395webappshardware07 jan 2019
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13S
23RISCO
abrir
GitHub PoC12
漏洞利用工具
CVE-2018-2628CRITICALsob ataque07 jan 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALsob ataque07 jan 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
Exploit-DB
Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal
CVE-2018-20525webappsphp07 jan 2019
Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
28RISCO
abrir
Exploit-DB
PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Scripting
CVE-2018-20326webappscgi07 jan 2019
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage
23RISCO
abrir
Exploit-DB
KioWare Server Version 4.9.6 - Weak Folder Permissions Privilege Escalation
CVE-2018-18435localwindows07 jan 2019
KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any
23RISCO
abrir
Exploit-DB
LayerBB 1.1.1 - Persistent Cross-Site Scripting
CVE-2018-17997webappsphp07 jan 2019
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
23RISCO
abrir
GitHub PoC
cve-2014-6271
CVE-2014-6271CRITICALsob ataque06 jan 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC1
cve-2018-11776
CVE-2018-11776HIGHsob ataque06 jan 2019
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC
cve-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware06 jan 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC
cve-2015-5602
CVE-2015-560206 jan 2019
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is d
23RISCO
abrir
GitHub PoC
CVE-2018-6389 PoC node js multisite with proxy
CVE-2018-638906 jan 2019
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
GitHub PoC
cve-2015-1427
CVE-2015-1427CRITICALsob ataque06 jan 2019
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISCO
abrir
GitHub PoC
cve-2016-7434
CVE-2016-743406 jan 2019
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a craf
35RISCO
abrir
GitHub PoC
cve-2016-6515
CVE-2016-651506 jan 2019
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a
35RISCO
abrir
GitHub PoC
CVE-2009-1324 - ASX to MP3 Converter Local Buffer Overflow. Tested on Windows XP Professional SP3
CVE-2009-132406 jan 2019
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RISCO
abrir
GitHub PoC
cve-2015-3306
CVE-2015-330606 jan 2019
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir
GitHub PoC
cve-2014-0160
CVE-2014-0160HIGHsob ataque06 jan 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
anteriorpágina 858 / 2.647próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.