Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DBVexDay Proof
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit)
CVE-2018-7600CRITICALsob ataqueransomwareremotephp17 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
Exploit-DB
Joomla! Component jDownloads 3.2.58 - Cross Site Scripting
CVE-2018-10068webappsphp17 abr 2018
The jDownloads extension before 3.2.59 for Joomla! has XSS.
23RISCO
abrir
Exploit-DB
Brave Browser < 0.13.0 - 'long alert() argument' Denial of Service
CVE-2017-18256doswindows17 abr 2018
Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert
23RISCO
abrir
Exploit-DBVexDay Proof
Ultra MiniHTTPd 1.2 - 'GET' Remote Stack Buffer Overflow (PoC)
CVE-2013-5019localwindows_x8617 abr 2018
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQuerySystemInformation (SystemPageFileInformation(Ex))' Kernel 64-bit Stack Memory Disclosure
CVE-2018-0971doswindows16 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryAttributesFile' Kernel Stack Memory Disclosure
CVE-2018-0969doswindows16 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryInformationProcess (ProcessImageFileName)' Kernel 64-bit Pool/Stack Memory Disclosure
CVE-2018-0973doswindows16 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryVolumeInformationFile' Kernel Stack Memory Disclosure
CVE-2018-0970doswindows16 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryVirtualMemory (MemoryImageInformation)' Kernel 64-bit Stack Memory Disclosure
CVE-2018-0968doswindows16 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir
Exploit-DB
Sophos Cyberoam UTM CR25iNG - 10.6.3 MR-5 - Direct Object Reference
CVE-2016-7786webappsjsp16 abr 2018
Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via dir
23RISCO
abrir
Exploit-DB
CloudMe Sync 1.11.0 - Local Buffer Overflow
CVE-2018-7886localwindows16 abr 2018
An issue was discovered in CloudMe 1.11.0. An unauthenticated local attacker that can connect to the "CloudMe Sync" clie
23RISCO
abrir
Exploit-DB
Cobub Razor 0.8.0 - SQL injection
CVE-2018-8057webappsphp16 abr 2018
A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryFullAttributesFile' Kernel Stack Memory Disclosure
CVE-2018-0975doswindows16 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryVirtualMemory (Memory(Privileged)BasicInformation)' Kernel 64-bit Stack Memory Disclosure
CVE-2018-0974doswindows16 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'CiSetFileCache' TOCTOU Incomplete Fix
CVE-2018-0966doswindows16 abr 2018
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryInformationTransactionManager (TransactionManagerRecoveryInformation)' Kernel Pool Memory Disclosure
CVE-2018-0972doswindows16 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir
Exploit-DB
AMD Plays.tv 1.27.5.0 - 'plays_service.exe' Arbitrary File Execution
CVE-2018-6546localwindows15 abr 2018
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming
28RISCO
abrir
Exploit-DBVexDay Proof
Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution
CVE-2018-7600CRITICALsob ataqueransomwarewebappsphp13 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
Exploit-DBVexDay Proof
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC)
CVE-2018-7600CRITICALsob ataqueransomwarewebappsphp13 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
Exploit-DB
Microsoft Credential Security Support Provider - Remote Code Execution
CVE-2018-0886remotewindows13 abr 2018
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 S
45RISCO
abrir
Exploit-DB
MikroTik 6.41.4 - FTP daemon Denial of Service (PoC)
CVE-2018-10070doslinux13 abr 2018
A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU a
28RISCO
abrir
Exploit-DB
Joomla! Convert Forms version 2.0.3 - Formula Injection (CSV Injection)
CVE-2018-10063webappsphp12 abr 2018
The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that
23RISCO
abrir
Exploit-DB
WordPress Plugin File Upload 4.3.2 - Stored Cross-Site Scripting
CVE-2018-9172webappsphp10 abr 2018
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
23RISCO
abrir
Exploit-DB
DVD X Player Standard 5.5.3.9 - Buffer Overflow
CVE-2018-9128localwindows_x8610 abr 2018
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RISCO
abrir
Exploit-DB
iScripts Easycreate 3.2.1 - Stored Cross-Site Scripting
CVE-2018-9236webappsphp10 abr 2018
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field.
23RISCO
abrir
Exploit-DB
Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Control
CVE-2018-1217webappslinux10 abr 2018
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection A
50RISCO
abrir
Exploit-DB
WordPress Plugin Activity Log 2.4.0 - Stored Cross-Site Scripting
CVE-2018-8729webappsphp10 abr 2018
Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote a
23RISCO
abrir
Exploit-DB
iScripts Easycreate 3.2.1 - Stored Cross-Site Scripting
CVE-2018-9237webappsphp10 abr 2018
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.
23RISCO
abrir
Exploit-DB
WUZHI CMS 4.1.0 - Cross-Site Request Forgery (Add Admin)
CVE-2018-9926webappsphp10 abr 2018
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=
23RISCO
abrir
Exploit-DB
WordPress Plugin File Upload 4.3.3 - Stored Cross-Site Scripting (PoC)
CVE-2018-9844webappsphp10 abr 2018
The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
23RISCO
abrir
anteriorpágina 102 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.