Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
79.386 exploits
GitHub PoC11
Script and metasploit module for CVE-2018-15982
CVE-2018-15982HIGHsob ataqueransomware11 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
Exploit-DBVexDay Proof
McAfee True Key - McAfee.TrueKey.Service Privilege Escalation
CVE-2018-6755HIGHlocalwindows11 dez 2018
True Key (TK) Windows Client - Weak Directory Permission Vulnerability
41RISCO
abrir
Exploit-DB
Adobe ColdFusion 2018 - Arbitrary File Upload
CVE-2018-15961CRITICALsob ataquewebappsmultiple11 dez 2018
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISCO
abrir
Exploit-DBVexDay Proof
McAfee True Key - McAfee.TrueKey.Service Privilege Escalation
CVE-2018-6757HIGHlocalwindows11 dez 2018
True Key (TK) Windows Client - Privilege Escalation vulnerability
41RISCO
abrir
GitHub PoC4
个人整理的Centos7.x + Kubernetes-1.12.3 + Dashboard-1.8.3 无 CVE-2018-1002105 漏洞的master节点全自动快速一键安装部署文件,适用于测试环境,生产环境的快速安装部署
CVE-2018-1002105CRITICAL10 dez 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISCO
abrir
GitHub PoC1
CVE-2014-0160
CVE-2014-0160HIGHsob ataque10 dez 2018
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-15982HIGHsob ataqueransomware10 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
GitHub PoC
Microsoft Equation 3.0/Convert python2 to python3
CVE-2017-11882HIGHsob ataqueransomware10 dez 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
Exploit-DB
Kubernetes - (Unauthenticated) Arbitrary Requests
CVE-2018-1002105CRITICALremotemultiple10 dez 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISCO
abrir
Exploit-DB
Kubernetes - (Authenticated) Arbitrary Requests
CVE-2018-1002105CRITICALremotemultiple10 dez 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHsob ataqueransomware10 dez 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
Metasploit600
ThinkPHP Multiple PHP Injection RCEs
CVE-2018-20062CRITICALsob ataque10 dez 2018
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISCO
abrir
Metasploit600
ThinkPHP Multiple PHP Injection RCEs
CVE-2019-9082HIGHsob ataque10 dez 2018
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RISCO
abrir
GitHub PoC179
exp of CVE-2018-15982
CVE-2018-15982HIGHsob ataqueransomware10 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
Exploit-DB
Adiscon LogAnalyzer < 4.1.7 - Cross-Site Scripting
CVE-2018-19877webappsphp09 dez 2018
login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field.
43RISCO
abrir
Metasploit600
Cisco Prime Infrastructure Runrshell Privilege Escalation
CVE-2018-15439CRITICAL08 dez 2018
Cisco Small Business Switches Privileged Access Vulnerability
55RISCO
abrir
GitHub PoC2
Proof of consept for CVE-2018-17431
CVE-2018-1743108 dez 2018
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-1743108 dez 2018
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RISCO
abrir
GitHub PoC9
Unrestricted file upload in Adobe ColdFusion
CVE-2018-15961CRITICALsob ataque06 dez 2018
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-15961CRITICALsob ataque06 dez 2018
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISCO
abrir
GitHub PoC13
CVE-2018-15982_PoC
CVE-2018-15982HIGHsob ataqueransomware06 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
GitHub PoC223
PoC for CVE-2018-1002105.
CVE-2018-1002105CRITICAL06 dez 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISCO
abrir
GitHub PoC191
Test utility for cve-2018-1002105
CVE-2018-1002105CRITICAL05 dez 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISCO
abrir
GitHub PoC
uzzzval/cve-2004-2167
CVE-2004-216705 dez 2018
Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary
28RISCO
abrir
GitHub PoC
Flash sources for CVE-2018-15982 used by NK
CVE-2018-15982HIGHsob ataqueransomware05 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
Exploit-DB
DomainMOD 4.11.01 - Custom Domain Fields Cross-Site Scripting
CVE-2018-19750webappsphp04 dez 2018
DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Doma
23RISCO
abrir
GitHub PoC
CVE-2014-8682
CVE-2014-868204 dez 2018
Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow r
50RISCO
abrir
Exploit-DB
DomainMOD 4.11.01 - Registrar Cross-Site Scripting
CVE-2018-19752webappsphp04 dez 2018
DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.
38RISCO
abrir
Exploit-DB
FreshRSS 1.11.1 - Cross-Site Scripting
CVE-2018-19782webappsphp04 dez 2018
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject
23RISCO
abrir
Exploit-DB
NEC Univerge Sv9100 WebPro - 6.00 - Predictable Session ID / Clear Text Password Storage
CVE-2018-11741webappshardware04 dez 2018
NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure vi
28RISCO
abrir
anteriorpágina 862 / 2.647próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.