Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DB
DLink DIR-601 - Admin Password Disclosure
CVE-2018-5708webappshardware02 abr 2018
An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticat
23RISCO
abrir
Exploit-DB
OpenCMS 10.5.3 - Cross-Site Scripting
CVE-2018-8815webappsphp02 abr 2018
Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to in
23RISCO
abrir
Exploit-DBVexDay Proof
WampServer 3.1.1 - Cross-Site Scripting / Cross-Site Request Forgery
CVE-2018-8732webappsphp02 abr 2018
Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or H
23RISCO
abrir
Exploit-DBVexDay Proof
WampServer 3.1.2 - Cross-Site Request Forgery
CVE-2018-8817webappsphp02 abr 2018
Wampserver before 3.1.3 has CSRF in add_vhost.php.
23RISCO
abrir
Exploit-DB
Frog CMS 0.9.5 - Cross-Site Request Forgery (Add User)
CVE-2018-8908webappsphp02 abr 2018
An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CS
23RISCO
abrir
Exploit-DB
OpenCMS 10.5.3 - Cross-Site Request Forgery
CVE-2018-8811webappsphp02 abr 2018
Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allow
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Acymailing Starter 5.9.5 - CSV Macro Injection
CVE-2018-9107webappsphp30 mar 2018
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing exte
23RISCO
abrir
Exploit-DB
Homematic CCU2 2.29.23 - Arbitrary File Write
CVE-2018-7300webappscgi30 mar 2018
Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic C
35RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component AcySMS 3.5.0 - CSV Macro Injection
CVE-2018-9106webappsphp30 mar 2018
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extensio
23RISCO
abrir
Exploit-DB
WordPress Plugin Contact Form 7 to Database Extension 2.10.32 - CSV Injection
CVE-2018-9035webappsphp30 mar 2018
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPr
23RISCO
abrir
Exploit-DB
Homematic CCU2 2.29.23 - Remote Command Execution
CVE-2018-7297webappscgi30 mar 2018
Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers
35RISCO
abrir
Exploit-DB
MiniCMS 1.10 - Cross-Site Request Forgery
CVE-2018-9092webappsphp30 mar 2018
There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.
23RISCO
abrir
Exploit-DB
WordPress Plugin WP Security Audit Log 3.1.1 - Sensitive Information Disclosure
CVE-2018-8719webappsphp30 mar 2018
An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-securit
43RISCO
abrir
Exploit-DB
Open-AuditIT Professional 2.1 - Cross-Site Request Forgery
CVE-2018-8979webappsmultiple30 mar 2018
Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the cre
23RISCO
abrir
Exploit-DB
Systematic SitAware - NVG Denial of Service
CVE-2018-9115dosxml30 mar 2018
Systematic SitaWare 6.4 SP2 does not validate input from other sources sufficiently. e.g., information utilizing the NVG
23RISCO
abrir
Exploit-DB
WordPress Plugin Relevanssi 4.0.4 - Reflected Cross-Site Scripting
CVE-2018-9034webappsphp30 mar 2018
Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote
23RISCO
abrir
Exploit-DB
D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router - Authentication Bypass
CVE-2018-9032webappsphp30 mar 2018
An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Versi
28RISCO
abrir
Exploit-DB
Vtiger CRM 6.3.0 - (Authenticated) Arbitrary File Upload (Metasploit)
CVE-2016-1713webappsphp30 mar 2018
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
43RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Fields - SQLi Remote Code Execution (Metasploit)
CVE-2017-8917webappsphp29 mar 2018
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISCO
abrir
Exploit-DBVexDay Proof
Exodus Wallet (ElectronJS Framework) - Remote Code Execution (Metasploit)
CVE-2018-1000006remotewindows29 mar 2018
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro
60RISCO
abrir
Exploit-DBVexDay Proof
GitStack - Unsanitized Argument Remote Code Execution (Metasploit)
CVE-2018-5955remotewindows29 mar 2018
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RISCO
abrir
Exploit-DB
Cisco Smart Install - Crash (PoC)
CVE-2018-0171HIGHsob ataquedoshardware29 mar 2018
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentica
100RISCO
abrir
Exploit-DB
TwonkyMedia Server 7.0.11-8.5 - Persistent Cross-Site Scripting
CVE-2018-7203webappsmultiple28 mar 2018
Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Remote Assistance - XML External Entity Injection
CVE-2018-0878LOWwebappswindows28 mar 2018
Windows Remote Assistance in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Window
33RISCO
abrir
Exploit-DB
Open-AuditIT Professional 2.1 - Cross-Site Scripting
CVE-2018-8903webappsphp28 mar 2018
Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.
23RISCO
abrir
Exploit-DB
TwonkyMedia Server 7.0.11-8.5 - Directory Traversal
CVE-2018-7171webappsmultiple28 mar 2018
Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of a
28RISCO
abrir
Exploit-DB
DLINK DCS-5020L - Remote Code Execution (PoC)
CVE-2017-17020webappshardware27 mar 2018
On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DC
28RISCO
abrir
Exploit-DB
Microsoft Windows Manager (7 x86) - Menu Management Component UAF Privilege Elevation
CVE-2017-0263HIGHsob ataquelocalwindows_x8626 mar 2018
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
76RISCO
abrir
Exploit-DB
Laravel Log Viewer < 0.13.0 - Local File Download
CVE-2018-8947webappsphp26 mar 2018
rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easi
28RISCO
abrir
Exploit-DB
Acrolinx Server < 5.2.5 - Directory Traversal
CVE-2018-7719remotewindows26 mar 2018
Acrolinx Server before 5.2.5 on Windows allows Directory Traversal.
50RISCO
abrir
anteriorpágina 104 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.