Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.526exploits catalogados
36.593CVEs com exploração pública
24.695testados em laboratório
79.526 exploits
GitHub PoC1
Wordpress plugin Site-Editor v1.1.1 LFI exploit
CVE-2018-742209 nov 2018
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISCO
abrir
GitHub PoC
matlink/CVE-2018-17456
CVE-2018-1745608 nov 2018
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISCO
abrir
Metasploit300
WordPress WP GDPR Compliance Plugin Privilege Escalation
CVE-2018-1920708 nov 2018
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to exe
60RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2014-0160HIGHsob ataque08 nov 2018
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-6789CRITICALsob ataqueransomware08 nov 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir
GitHub PoC3
beraphin/CVE-2018-6789
CVE-2018-6789CRITICALsob ataqueransomware08 nov 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir
GitHub PoC
来自:https://www.freebuf.com/articles/web/31700.html
CVE-2014-0160HIGHsob ataque08 nov 2018
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
Exploit-DB
OpenSLP 2.0.0 - Multiple Vulnerabilities
CVE-2016-7567locallinux07 nov 2018
Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have
28RISCO
abrir
Exploit-DBVexDay Proof
FaceTime - RTP Video Processing Heap Corruption
CVE-2018-4384dosios06 nov 2018
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1,
23RISCO
abrir
Exploit-DBVexDay Proof
FaceTime - 'VCPDecompressionDecodeFrame' Memory Corruption
CVE-2018-4366dosmacos06 nov 2018
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.
23RISCO
abrir
Exploit-DBVexDay Proof
FaceTime - 'readSPSandGetDecoderParams' Stack Corruption
CVE-2018-4367dosmacos06 nov 2018
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.
23RISCO
abrir
GitHub PoC21
an RCE (remote command execution) approach of CVE-2018-7750
CVE-2018-775006 nov 2018
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x
28RISCO
abrir
Exploit-DBVexDay Proof
blueimp's jQuery 9.22.0 - (Arbitrary) File Upload (Metasploit)
CVE-2018-9206remotephp06 nov 2018
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISCO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque06 nov 2018
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
VulnCheck XDB
local
CVE-2020-3950HIGHsob ataque06 nov 2018
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for
86RISCO
abrir
Exploit-DB
libiec61850 1.3 - Stack Based Buffer Overflow
CVE-2018-18957locallinux06 nov 2018
An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_pu
23RISCO
abrir
GitHub PoC14
Exploit for PlaySMS 1.4 authenticated RCE
CVE-2017-910106 nov 2018
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
50RISCO
abrir
Exploit-DB
CMS Made Simple 2.2.7 - (Authenticated) Remote Code Execution
CVE-2018-10517webappsphp06 nov 2018
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code ex
23RISCO
abrir
Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
CVE-2018-18858localmacos05 nov 2018
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RISCO
abrir
Exploit-DB
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
CVE-2018-15707webappsasp05 nov 2018
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could
23RISCO
abrir
Exploit-DB
PHP Proxy 3.0.3 - Local File Inclusion
CVE-2018-19458webappsphp05 nov 2018
In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI UR
43RISCO
abrir
Exploit-DB
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
CVE-2018-15705webappsasp05 nov 2018
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any f
28RISCO
abrir
Exploit-DB
Royal TS/X - Information Disclosure
CVE-2018-18865webappsjson05 nov 2018
The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13
23RISCO
abrir
Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
CVE-2018-18859localmacos05 nov 2018
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RISCO
abrir
Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
CVE-2018-18857localmacos05 nov 2018
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RISCO
abrir
Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
CVE-2018-18856localmacos05 nov 2018
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RISCO
abrir
Metasploit500
VyOS restricted-shell Escape and Privilege Escalation
CVE-2018-1855605 nov 2018
A privilege escalation issue was discovered in VyOS 1.1.8. The default configuration also allows operator users to execu
23RISCO
abrir
Metasploit600
Intelliants Subrion CMS 4.2.1 - Authenticated File Upload Bypass to RCE
CVE-2018-1942204 nov 2018
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RISCO
abrir
Exploit-DB
Intel (Skylake / Kaby Lake) - 'PortSmash' CPU SMT Side-Channel
CVE-2018-5407localhardware02 nov 2018
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks
23RISCO
abrir
GitHub PoC
bolonobolo/CVE-2018-14665
CVE-2018-1466502 nov 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
50RISCO
abrir
anteriorpágina 869 / 2.651próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.