Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.457exploits catalogados
36.589CVEs com exploração pública
24.695testados em laboratório
79.457 exploits
VulnCheck XDB
initial-access
CVE-2018-6789CRITICALsob ataqueransomware08 nov 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir
Exploit-DB
OpenSLP 2.0.0 - Multiple Vulnerabilities
CVE-2016-7567locallinux07 nov 2018
Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have
28RISCO
abrir
Exploit-DB
libiec61850 1.3 - Stack Based Buffer Overflow
CVE-2018-18957locallinux06 nov 2018
An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_pu
23RISCO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque06 nov 2018
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
Exploit-DB
CMS Made Simple 2.2.7 - (Authenticated) Remote Code Execution
CVE-2018-10517webappsphp06 nov 2018
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code ex
23RISCO
abrir
GitHub PoC14
Exploit for PlaySMS 1.4 authenticated RCE
CVE-2017-910106 nov 2018
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
50RISCO
abrir
Exploit-DBVexDay Proof
FaceTime - 'readSPSandGetDecoderParams' Stack Corruption
CVE-2018-4367dosmacos06 nov 2018
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.
23RISCO
abrir
Exploit-DBVexDay Proof
FaceTime - 'VCPDecompressionDecodeFrame' Memory Corruption
CVE-2018-4366dosmacos06 nov 2018
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.
23RISCO
abrir
Exploit-DBVexDay Proof
blueimp's jQuery 9.22.0 - (Arbitrary) File Upload (Metasploit)
CVE-2018-9206remotephp06 nov 2018
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISCO
abrir
GitHub PoC21
an RCE (remote command execution) approach of CVE-2018-7750
CVE-2018-775006 nov 2018
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x
28RISCO
abrir
VulnCheck XDB
local
CVE-2020-3950HIGHsob ataque06 nov 2018
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for
86RISCO
abrir
Exploit-DBVexDay Proof
FaceTime - RTP Video Processing Heap Corruption
CVE-2018-4384dosios06 nov 2018
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1,
23RISCO
abrir
Metasploit500
VyOS restricted-shell Escape and Privilege Escalation
CVE-2018-1855605 nov 2018
A privilege escalation issue was discovered in VyOS 1.1.8. The default configuration also allows operator users to execu
23RISCO
abrir
Exploit-DB
PHP Proxy 3.0.3 - Local File Inclusion
CVE-2018-19458webappsphp05 nov 2018
In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI UR
43RISCO
abrir
Exploit-DB
Royal TS/X - Information Disclosure
CVE-2018-18865webappsjson05 nov 2018
The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13
23RISCO
abrir
Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
CVE-2018-18858localmacos05 nov 2018
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RISCO
abrir
Exploit-DB
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
CVE-2018-15705webappsasp05 nov 2018
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any f
28RISCO
abrir
Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
CVE-2018-18859localmacos05 nov 2018
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RISCO
abrir
Exploit-DB
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
CVE-2018-15707webappsasp05 nov 2018
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could
23RISCO
abrir
Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
CVE-2018-18857localmacos05 nov 2018
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RISCO
abrir
Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
CVE-2018-18856localmacos05 nov 2018
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RISCO
abrir
Metasploit600
Intelliants Subrion CMS 4.2.1 - Authenticated File Upload Bypass to RCE
CVE-2018-1942204 nov 2018
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RISCO
abrir
Exploit-DB
Intel (Skylake / Kaby Lake) - 'PortSmash' CPU SMT Side-Channel
CVE-2018-5407localhardware02 nov 2018
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks
23RISCO
abrir
GitHub PoC
bolonobolo/CVE-2018-14665
CVE-2018-1466502 nov 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
50RISCO
abrir
GitHub PoC2
matlink/CVE-2018-17961
CVE-2018-1796101 nov 2018
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err
28RISCO
abrir
Metasploit400
Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation
CVE-2018-533301 nov 2018
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning
43RISCO
abrir
Metasploit400
Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation
CVE-2019-921301 nov 2018
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RISCO
abrir
GitHub PoC80
CVE-2018-8440 standalone exploit
CVE-2018-8440HIGHsob ataqueransomware31 out 2018
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
91RISCO
abrir
GitHub PoC2
Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473
CVE-2018-15473MEDIUM31 out 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
VulnCheck XDB
local
CVE-2018-8440HIGHsob ataqueransomware31 out 2018
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
91RISCO
abrir
anteriorpágina 867 / 2.649próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.