Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DB
Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery
CVE-2018-9302webappsphp02 mai 2018
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to r
23RISCO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::jsElementScrollHeightGetter' Use-After-Free
CVE-2018-4200dosmultiple02 mai 2018
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud
23RISCO
abrir
Exploit-DB
WordPress Plugin Responsive Cookie Consent 1.7 / 1.6 / 1.5 - (Authenticated) Persistent Cross-Site Scripting
CVE-2018-10309webappsphp01 mai 2018
The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS.
23RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Form Maker 1.12.20 - CSV Injection
CVE-2018-10504webappsphp30 abr 2018
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
23RISCO
abrir
Exploit-DBVexDay Proof
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit)
CVE-2018-7602CRITICALsob ataqueransomwarewebappsphp30 abr 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISCO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-8736webappsphp30 abr 2018
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC
50RISCO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-8734webappsphp30 abr 2018
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS - ReportCrash mach port Replacement due to Failure to Respect MIG Ownership Rules
CVE-2018-4206dosmultiple30 abr 2018
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2
23RISCO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-8735webappsphp30 abr 2018
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut
50RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.13.2 - Double mach_port_deallocate in kextd due to Failure to Comply with MIG Ownership Rules
CVE-2018-4139dosmacos30 abr 2018
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools"
23RISCO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-8733webappsphp30 abr 2018
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an
43RISCO
abrir
Exploit-DB
October CMS User Plugin 1.4.5 - Persistent Cross-Site Scripting
CVE-2018-10366webappsphp26 abr 2018
An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the nam
23RISCO
abrir
Exploit-DB
MyBB Threads to Link Plugin 1.3 - Cross-Site Scripting
CVE-2018-10365webappsphp26 abr 2018
An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the opt
23RISCO
abrir
Exploit-DB
Frog CMS 0.9.5 - Persistent Cross-Site Scripting
CVE-2018-10321webappsphp26 abr 2018
Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.
23RISCO
abrir
Exploit-DB
SickRage < v2018.03.09 - Clear-Text Credentials HTTP Response
CVE-2018-9160webappslinux26 abr 2018
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RISCO
abrir
Exploit-DB
Jfrog Artifactory < 4.16 - Arbitrary File Upload / Remote Command Execution
CVE-2016-10036webappslinux26 abr 2018
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to
28RISCO
abrir
Exploit-DB
Blog Master Pro 1.0 - CSV Injection
CVE-2018-10255webappsphp25 abr 2018
A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level pri
23RISCO
abrir
Exploit-DBVexDay Proof
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code Execution (PoC)
CVE-2018-7602CRITICALsob ataqueransomwarewebappsphp25 abr 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISCO
abrir
Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - Local File Inclusion
CVE-2018-10260webappsphp25 abr 2018
A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.
23RISCO
abrir
Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - (Authenticated) Cross-Site Scripting
CVE-2018-10259webappsphp25 abr 2018
An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged u
23RISCO
abrir
Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - CSV Injection
CVE-2018-10257webappsphp25 abr 2018
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RISCO
abrir
Exploit-DB
Shopy Point of Sale 1.0 - CSV Injection
CVE-2018-10258webappsphp25 abr 2018
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to
23RISCO
abrir
Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - 'award_id' SQL Injection
CVE-2018-10256webappsphp25 abr 2018
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RISCO
abrir
Exploit-DB
WSO2 Carbon / WSO2 Dashboard Server 5.3.0 - Persistent Cross-Site Scripting
CVE-2018-8716webappsjava24 abr 2018
WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
35RISCO
abrir
Exploit-DB
Open-AudIT 2.1 - CSV Macro Injection
CVE-2018-9137webappswindows24 abr 2018
Open-AudIT before 2.2 has CSV Injection.
23RISCO
abrir
Exploit-DB
VLC Media Player/Kodi/PopcornTime 'Red Chimera' < 2.2.5 - Memory Corruption (PoC)
CVE-2017-8311doswindows24 abr 2018
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an inpu
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Info Leak in Image Inflation
CVE-2018-4934dosmultiple24 abr 2018
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful expl
28RISCO
abrir
Exploit-DB
WUZHI CMS 4.1.0 - Cross-Site Request Forgery
CVE-2018-10312webappsphp24 abr 2018
index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.
23RISCO
abrir
Exploit-DB
UK Cookie Consent - Persistent Cross-Site Scripting
CVE-2018-10310webappsphp24 abr 2018
A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Conse
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Overflow when Playing Sound
CVE-2018-4936dosmultiple24 abr 2018
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Successful exploitat
28RISCO
abrir
anteriorpágina 100 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.