Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.438exploits catalogados
36.583CVEs com exploração pública
24.695testados em laboratório
79.386 exploits
Exploit-DBVexDay Proof
WebKit JSC JIT - 'JSPropertyNameEnumerator' Type Confusion
CVE-2018-4416dosmultiple29 nov 2018
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
35RISCO
abrir
Exploit-DBVexDay Proof
PHP imap_open - Remote Code Execution (Metasploit)
CVE-2018-19518remotelinux29 nov 2018
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh c
60RISCO
abrir
Exploit-DBVexDay Proof
Unitrends Enterprise Backup - bpserverd Privilege Escalation (Metasploit)
CVE-2018-6329locallinux29 nov 2018
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL i
50RISCO
abrir
Exploit-DBVexDay Proof
Linux - Nested User Namespace idmap Limit Local Privilege Escalation (Metasploit)
CVE-2018-18955locallinux29 nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISCO
abrir
Exploit-DBVexDay Proof
Mac OS X - libxpc MITM Privilege Escalation (Metasploit)
CVE-2018-4237localmacos29 nov 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
43RISCO
abrir
Exploit-DBVexDay Proof
WebKit JIT - 'ByteCodeParser::handleIntrinsicCall' Type Confusion
CVE-2018-4382dosmultiple29 nov 2018
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISCO
abrir
GitHub PoC
lol-fi/cve-2011-4862
CVE-2011-486228 nov 2018
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISCO
abrir
GitHub PoC1
about CVE-2018-14667 from RichFaces Framework 3.3.4
CVE-2018-14667CRITICALsob ataque28 nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-1920727 nov 2018
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to exe
60RISCO
abrir
Exploit-DBVexDay Proof
Netgear Devices - (Unauthenticated) Remote Command Execution (Metasploit)
CVE-2016-1555CRITICALsob ataqueremotehardware27 nov 2018
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear
100RISCO
abrir
GitHub PoC1
The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10
CVE-2018-7690MEDIUM26 nov 2018
MFSBGN03835 rev.1 - Fortify Software Security Center (SSC), Remote Unauthorized Access
33RISCO
abrir
GitHub PoC1
The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10
CVE-2018-7691MEDIUM26 nov 2018
MFSBGN03835 rev.1 - Fortify Software Security Center (SSC), Remote Unauthorized Access
33RISCO
abrir
Exploit-DBVexDay Proof
Xorg X11 Server - SUID privilege escalation (Metasploit)
CVE-2018-14665localmultiple26 nov 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISCO
abrir
Exploit-DB
Ticketly 1.0 - 'kind_id' SQL Injection
CVE-2018-18923webappsphp26 nov 2018
AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and
23RISCO
abrir
GitHub PoC15
RTSPServer Code Execution Vulnerability CVE-2018-4013
CVE-2018-4013CRITICAL24 nov 2018
An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server l
48RISCO
abrir
GitHub PoC2
zeroto01/CVE-2018-14667
CVE-2018-14667CRITICALsob ataque23 nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALsob ataqueransomware22 nov 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC1
un4ckn0wl3z/CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware22 nov 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
Exploit-DB
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (ldpreload Method)
CVE-2018-18955locallinux21 nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISCO
abrir
GitHub PoC
libSSH bypass
CVE-2018-10933CRITICAL21 nov 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
Exploit-DB
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (cron Method)
CVE-2018-18955locallinux21 nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - DfMarshal Unsafe Unmarshaling Privilege Escalation
CVE-2018-8550localwindows20 nov 2018
An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerabili
23RISCO
abrir
Exploit-DB
ImageMagick - Memory Leak
CVE-2018-16323localmultiple19 nov 2018
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that ha
35RISCO
abrir
GitHub PoC
tafamace/CVE-2017-17485
CVE-2017-17485CRITICAL19 nov 2018
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o
60RISCO
abrir
GitHub PoC
tafamace/CVE-2016-0793
CVE-2016-079319 nov 2018
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Se
28RISCO
abrir
GitHub PoC
cve-2018-14667 demo
CVE-2018-14667CRITICALsob ataque18 nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISCO
abrir
GitHub PoC83
Tool for CVE-2018-16323
CVE-2018-1632318 nov 2018
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that ha
35RISCO
abrir
GitHub PoC3
CVE-2018-16509 (Ghostscript contains multiple -dSAFER sandbox bypass vulnerabilities)
CVE-2018-1650917 nov 2018
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISCO
abrir
GitHub PoC
Implementation of CVE-2018-10933 with CIDR block scanner
CVE-2018-10933CRITICAL16 nov 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
Exploit-DBVexDay Proof
Linux - Broken uid/gid Mapping for Nested User Namespaces
CVE-2018-18955locallinux16 nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISCO
abrir
anteriorpágina 864 / 2.647próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.