Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.452exploits catalogados
36.587CVEs com exploração pública
24.695testados em laboratório
79.452 exploits
GitHub PoC1
The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10
CVE-2018-7690MEDIUM26 nov 2018
MFSBGN03835 rev.1 - Fortify Software Security Center (SSC), Remote Unauthorized Access
33RISCO
abrir
GitHub PoC1
The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10
CVE-2018-7691MEDIUM26 nov 2018
MFSBGN03835 rev.1 - Fortify Software Security Center (SSC), Remote Unauthorized Access
33RISCO
abrir
GitHub PoC15
RTSPServer Code Execution Vulnerability CVE-2018-4013
CVE-2018-4013CRITICAL24 nov 2018
An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server l
48RISCO
abrir
GitHub PoC2
zeroto01/CVE-2018-14667
CVE-2018-14667CRITICALsob ataque23 nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALsob ataqueransomware22 nov 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC1
un4ckn0wl3z/CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware22 nov 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
Exploit-DB
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (cron Method)
CVE-2018-18955locallinux21 nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
43RISCO
abrir
Exploit-DB
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (ldpreload Method)
CVE-2018-18955locallinux21 nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
43RISCO
abrir
GitHub PoC
libSSH bypass
CVE-2018-10933CRITICAL21 nov 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - DfMarshal Unsafe Unmarshaling Privilege Escalation
CVE-2018-8550localwindows20 nov 2018
An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerabili
23RISCO
abrir
Exploit-DB
ImageMagick - Memory Leak
CVE-2018-16323localmultiple19 nov 2018
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that ha
35RISCO
abrir
GitHub PoC
tafamace/CVE-2017-17485
CVE-2017-17485CRITICAL19 nov 2018
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o
60RISCO
abrir
GitHub PoC
tafamace/CVE-2016-0793
CVE-2016-079319 nov 2018
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Se
28RISCO
abrir
GitHub PoC
cve-2018-14667 demo
CVE-2018-14667CRITICALsob ataque18 nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISCO
abrir
GitHub PoC83
Tool for CVE-2018-16323
CVE-2018-1632318 nov 2018
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that ha
35RISCO
abrir
GitHub PoC3
CVE-2018-16509 (Ghostscript contains multiple -dSAFER sandbox bypass vulnerabilities)
CVE-2018-1650917 nov 2018
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISCO
abrir
Exploit-DBVexDay Proof
Linux - Broken uid/gid Mapping for Nested User Namespaces
CVE-2018-18955locallinux16 nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
43RISCO
abrir
GitHub PoC
Implementation of CVE-2018-10933 with CIDR block scanner
CVE-2018-10933CRITICAL16 nov 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
Exploit-DB
DomainMOD 4.11.01 - 'raid' Cross-Site Scripting
CVE-2018-19136webappsphp16 nov 2018
DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.
38RISCO
abrir
Exploit-DB
WordPress Plugin Ninja Forms 3.3.17 - Cross-Site Scripting
CVE-2018-19287webappsphp15 nov 2018
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes
43RISCO
abrir
Metasploit500
Linux Nested User Namespace idmap Limit Local Privilege Escalation
CVE-2018-1895515 nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
43RISCO
abrir
Exploit-DB
PHP-Proxy 5.1.0 - Local File Inclusion
CVE-2018-19246webappsphp15 nov 2018
PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users w
28RISCO
abrir
Exploit-DB
Advanced Comment System 1.0 - SQL Injection
CVE-2018-18619webappsphp14 nov 2018
internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability bec
23RISCO
abrir
Exploit-DBVexDay Proof
Dell OpenManage Network Manager 6.2.0.51 SP3 - Multiple Vulnerabilities
CVE-2018-15767webappslinux14 nov 2018
Improper Authorization Vulnerability
23RISCO
abrir
Exploit-DBVexDay Proof
Dell OpenManage Network Manager 6.2.0.51 SP3 - Multiple Vulnerabilities
CVE-2018-15768webappslinux14 nov 2018
Insecure MySQL Configuration Vulnerability
23RISCO
abrir
Metasploit600
Nagios XI Magpie_debug.php Root Remote Code Execution
CVE-2018-1570814 nov 2018
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RISCO
abrir
Metasploit600
Nagios XI Magpie_debug.php Root Remote Code Execution
CVE-2018-1571014 nov 2018
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
50RISCO
abrir
Exploit-DB
ntpd 4.2.8p10 - Out-of-Bounds Read (PoC)
CVE-2018-7182locallinux14 nov 2018
The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-
28RISCO
abrir
Exploit-DB
SwitchVPN for macOS 2.1012.03 - Privilege Escalation
CVE-2018-18860localmacos14 nov 2018
A local privilege escalation vulnerability has been identified in the SwitchVPN client 2.1012.03 for macOS. Due to over-
23RISCO
abrir
Exploit-DB
ClipperCMS 1.3.3 - Cross-Site Request Forgery (File Upload)
CVE-2018-19135webappsphp13 nov 2018
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an
23RISCO
abrir
anteriorpágina 865 / 2.649próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.