Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
AsusWRT LAN - Remote Code Execution (Metasploit)
CVE-2018-600026 fev 2018
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpn
60RISCO
abrir
Exploit-DB
AsusWRT LAN - Remote Code Execution (Metasploit)
CVE-2018-599926 fev 2018
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, pro
60RISCO
abrir
Exploit-DB
CloudMe Sync 1.10.9 - Stack-Based Buffer Overflow (Metasploit)
CVE-2018-689226 fev 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RISCO
abrir
Exploit-DB
Joomla! Component Alexandria Book Library 3.1.2 - 'letter' SQL Injection
CVE-2018-731222 fev 2018
SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla! via the letter parameter.
23RISCO
abrir
Exploit-DB
Joomla! Component Proclaim 9.1.1 - Arbitrary File Upload
CVE-2018-731622 fev 2018
Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action.
23RISCO
abrir
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622422 fev 2018
A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could a
23RISCO
abrir
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-621922 fev 2018
An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdr
23RISCO
abrir
Exploit-DB
Joomla! Component CheckList 1.1.1 - SQL Injection
CVE-2018-731822 fev 2018
SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, descrip
23RISCO
abrir
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622122 fev 2018
An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle
23RISCO
abrir
Exploit-DB
Joomla! Component PrayerCenter 3.0.2 - 'sessionid' SQL Injection
CVE-2018-731422 fev 2018
SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerabil
50RISCO
abrir
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-623022 fev 2018
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an
23RISCO
abrir
Exploit-DB
Joomla! Component CW Tags 2.0.6 - SQL Injection
CVE-2018-731322 fev 2018
SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.
28RISCO
abrir
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622022 fev 2018
An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbi
28RISCO
abrir
Exploit-DB
NoMachine < 6.0.80 (x64) - 'nxfuse' Privilege Escalation
CVE-2018-694722 fev 2018
An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoM
23RISCO
abrir
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622622 fev 2018
Reflected cross-site scripting (XSS) vulnerabilities in two Trend Micro Email Encryption Gateway 5.5 configuration files
23RISCO
abrir
Exploit-DB
NoMachine < 6.0.80 (x86) - 'nxfuse' Privilege Escalation
CVE-2018-694722 fev 2018
An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoM
23RISCO
abrir
Exploit-DB
Joomla! Component Ek Rishta 2.9 - SQL Injection
CVE-2018-731522 fev 2018
SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, cast
23RISCO
abrir
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622522 fev 2018
An XML external entity injection (XXE) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an authenti
23RISCO
abrir
Exploit-DB
Joomla! Component Proclaim 9.1.1 - Backup File Download
CVE-2018-731722 fev 2018
Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/.
23RISCO
abrir
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622822 fev 2018
A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to exe
28RISCO
abrir
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622922 fev 2018
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker
28RISCO
abrir
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622322 fev 2018
A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allo
28RISCO
abrir
Exploit-DB
Armadito Antivirus 0.12.7.2 - Detection Bypass
CVE-2018-728922 fev 2018
An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames cont
23RISCO
abrir
Exploit-DB
Joomla! Component OS Property Real Estate 3.12.7 - SQL Injection
CVE-2018-731922 fev 2018
SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system
23RISCO
abrir
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622722 fev 2018
A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to
23RISCO
abrir
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622222 fev 2018
Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log fi
23RISCO
abrir
Exploit-DB
Disk Savvy Enterprise 10.4.18 - Buffer Overflow (SEH)
CVE-2018-648121 fev 2018
A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to exe
28RISCO
abrir
Exploit-DB
Wavpack 5.1.0 - Denial of Service
CVE-2018-725421 fev 2018
The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of
23RISCO
abrir
Exploit-DB
Disk Pulse Enterprise 10.4.18 - 'Import Command' Buffer Overflow (SEH)
CVE-2017-731021 fev 2018
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9
50RISCO
abrir
Exploit-DB
Microsoft Windows - StorSvc SvcMoveFileInheritSecurity Arbitrary File Creation Privilege Escalation
CVE-2018-082620 fev 2018
Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, versi
23RISCO
abrir
anteriorpágina 102 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.