Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-070713 jul 2018
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
50RISCO
abrir
Exploit-DB
Microsoft Windows - POP/MOV SS Local Privilege Elevation (Metasploit)
CVE-2018-889713 jul 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RISCO
abrir
Exploit-DB
Zeta Producer Desktop CMS 14.2.0 - Remote Code Execution / Local File Disclosure
CVE-2018-1398013 jul 2018
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclos
38RISCO
abrir
Exploit-DB
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-070913 jul 2018
Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow auth
28RISCO
abrir
Exploit-DB
G DATA Total Security 25.4.0.3 - Activex Buffer Overflow
CVE-2018-1001813 jul 2018
The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a lo
23RISCO
abrir
Exploit-DB
phpMyAdmin - (Authenticated) Remote Code Execution (Metasploit)
CVE-2018-1261313 jul 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir
Exploit-DB
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-1297913 jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions
23RISCO
abrir
Exploit-DB
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-070813 jul 2018
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo
28RISCO
abrir
Exploit-DB
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-1298013 jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit
35RISCO
abrir
Exploit-DB
Apache CouchDB - Arbitrary Command Execution (Metasploit)
CVE-2017-1263613 jul 2018
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISCO
abrir
Exploit-DB
Zeta Producer Desktop CMS 14.2.0 - Remote Code Execution / Local File Disclosure
CVE-2018-1398113 jul 2018
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code
28RISCO
abrir
Exploit-DB
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-070613 jul 2018
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate
50RISCO
abrir
Exploit-DB
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-071013 jul 2018
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe
28RISCO
abrir
Exploit-DB
Cela Link CLR-M20 2.7.1.6 - Arbitrary File Upload
CVE-2018-1513713 jul 2018
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml)
28RISCO
abrir
Exploit-DB
Grundig Smart Inter@ctive 3.0 - Cross-Site Request Forgery
CVE-2018-1398913 jul 2018
Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable
23RISCO
abrir
Exploit-DB
Apache CouchDB - Arbitrary Command Execution (Metasploit)
CVE-2017-1263513 jul 2018
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISCO
abrir
Exploit-DB
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-1298113 jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit
23RISCO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - Out-of-Bounds Reads/Writes
CVE-2018-814512 jul 2018
An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could
35RISCO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - Type Confusion with Hoisted SetConcatStrMultiItemBE Instructions
CVE-2018-822912 jul 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISCO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - BoundFunction::NewInstance Out-of-Bounds Read
CVE-2018-813912 jul 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RISCO
abrir
Exploit-DB
JavaScript Core - Arbitrary Code Execution
CVE-2018-419211 jul 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
28RISCO
abrir
Exploit-DB
IBM QRadar SIEM - Remote Code Execution (Metasploit)
CVE-2016-972211 jul 2018
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be r
43RISCO
abrir
Exploit-DB
IBM QRadar SIEM - Remote Code Execution (Metasploit)
CVE-2018-1612MEDIUM11 jul 2018
IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and
60RISCO
abrir
Exploit-DB
IBM QRadar SIEM - Remote Code Execution (Metasploit)
CVE-2018-141811 jul 2018
IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM
50RISCO
abrir
Exploit-DB
Instagram-Clone Script 2.0 - Cross-Site Scripting
CVE-2018-1384911 jul 2018
edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequ
23RISCO
abrir
Exploit-DB
Linux Kernel < 4.13.9 (Ubuntu 16.04 / Fedora 27) - Local Privilege Escalation
CVE-2017-1699510 jul 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
Exploit-DB
Activision Infinity Ward Call of Duty Modern Warfare 2 - Buffer Overflow
CVE-2018-1071809 jul 2018
Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote at
35RISCO
abrir
Exploit-DB
Tor Browser < 0.3.2.10 - Use After Free (PoC)
CVE-2018-049109 jul 2018
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of se
28RISCO
abrir
Exploit-DB
Oracle WebLogic 12.1.2.0 - RMI Registry UnicastRef Object Java Deserialization Remote Code Execution
CVE-2017-324807 jul 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RISCO
abrir
Exploit-DB
Airties AIR5444TT - Cross-Site Scripting
CVE-2018-873806 jul 2018
Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS.
23RISCO
abrir
anteriorpágina 87 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.