Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6220webappsjsp22 fev 2018
An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbi
23RISCO
abrir
Exploit-DB
Joomla! Component Ek Rishta 2.9 - SQL Injection
CVE-2018-7315webappsphp22 fev 2018
SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, cast
23RISCO
abrir
Exploit-DB
Joomla! Component OS Property Real Estate 3.12.7 - SQL Injection
CVE-2018-7319webappsphp22 fev 2018
SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system
23RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6221webappsjsp22 fev 2018
An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle
23RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6228webappsjsp22 fev 2018
A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to exe
28RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6229webappsjsp22 fev 2018
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker
28RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6222webappsjsp22 fev 2018
Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log fi
23RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6219webappsjsp22 fev 2018
An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdr
23RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6225webappsjsp22 fev 2018
An XML external entity injection (XXE) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an authenti
23RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6223webappsjsp22 fev 2018
A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allo
28RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6230webappsjsp22 fev 2018
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an
23RISCO
abrir
Exploit-DB
Wavpack 5.1.0 - Denial of Service
CVE-2018-7254dosmultiple21 fev 2018
The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of
23RISCO
abrir
Exploit-DB
Disk Savvy Enterprise 10.4.18 - Buffer Overflow (SEH)
CVE-2018-6481remotewindows21 fev 2018
A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to exe
28RISCO
abrir
Exploit-DB
Disk Pulse Enterprise 10.4.18 - 'Import Command' Buffer Overflow (SEH)
CVE-2017-7310remotewindows21 fev 2018
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 - 'Js::RegexHelper::RegexReplace' Use-After-Free
CVE-2018-0866doswindows20 fev 2018
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NPFS Symlink Security Feature Bypass/Elevation of Privilege/Dangerous Behavior
CVE-2018-0823localwindows20 fev 2018
The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'nt!RtlpCopyLegacyContextX86' Stack Memory Disclosure
CVE-2018-0832doswindows20 fev 2018
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Window
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Global Reparse Point Security Feature Bypass/Elevation of Privilege
CVE-2018-0822localwindows20 fev 2018
NTFS in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an eleva
23RISCO
abrir
Exploit-DBVexDay Proof
MagniComp SysInfo - mcsiwrapper Privilege Escalation (Metasploit)
CVE-2017-6516localmultiple20 fev 2018
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow
38RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - StorSvc SvcMoveFileInheritSecurity Arbitrary File Creation Privilege Escalation
CVE-2018-0826localwindows20 fev 2018
Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, versi
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Constrained Impersonation Capability Privilege Escalation
CVE-2018-0821localwindows20 fev 2018
AppContainer in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows
23RISCO
abrir
Exploit-DB
October CMS < 1.0.431 - Cross-Site Scripting
CVE-2018-7198webappsphp19 fev 2018
October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Gallery WD 1.3.6 - SQL Injection
CVE-2018-5981webappsphp16 fev 2018
SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component NeoRecruit 4.1 - SQL Injection
CVE-2018-6370webappsphp16 fev 2018
SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle Primavera P6 Enterprise Project Portfolio Management - HTTP Response Splitting
CVE-2017-10046webappsmultiple16 fev 2018
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (
23RISCO
abrir
Exploit-DB
Joomla! Component Solidres 2.5.1 - SQL Injection
CVE-2018-5980webappsphp16 fev 2018
SQL Injection exists in the Solidres 2.5.1 component for Joomla! via the direction parameter in a hub.search action.
23RISCO
abrir
Exploit-DB
JBoss Remoting 6.14.18 - Denial of Service
CVE-2018-1041dosmultiple16 fev 2018
A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an e
28RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component JB Bus 2.3 - 'order_number' SQL Injection
CVE-2018-6372webappsphp16 fev 2018
SQL Injection exists in the JB Bus 2.3 component for Joomla! via the order_number parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Fastball 2.5 - 'season' SQL Injection
CVE-2018-6373webappsphp16 fev 2018
SQL Injection exists in the Fastball 2.5 component for Joomla! via the season parameter in a view=player action.
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Timetable Responsive Schedule For Joomla! 1.5 - 'alias' SQL Injection
CVE-2018-6583webappsphp16 fev 2018
SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request.
28RISCO
abrir
anteriorpágina 108 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.