Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.902exploits catalogados
34.597CVEs com exploração pública
24.695testados em laboratório
8.410 exploits
VulnCheck XDB
local
CVE-2019-2215HIGHsob ataque24 nov 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2011-319224 nov 2019
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-17562HIGHsob ataque23 nov 2019
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2019-5825MEDIUMsob ataque23 nov 2019
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploi
90RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALsob ataque22 nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALsob ataqueransomware22 nov 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALsob ataqueransomware21 nov 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-11882HIGHsob ataqueransomware19 nov 2019
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHsob ataqueransomware19 nov 2019
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-5418HIGHsob ataque19 nov 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-289419 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Su
50RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-261819 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
35RISCO
abrir
VulnCheck XDB
local
CVE-2019-1322HIGHsob ataqueransomware13 nov 2019
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft W
91RISCO
abrir
VulnCheck XDB
local
CVE-2019-1405HIGHsob ataqueransomware13 nov 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-0708CRITICALsob ataqueransomware12 nov 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-11043HIGHsob ataqueransomware11 nov 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-1666210 nov 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISCO
abrir
VulnCheck XDB
local
CVE-2022-21882HIGHsob ataque10 nov 2019
Win32k Elevation of Privilege Vulnerability
98RISCO
abrir
VulnCheck XDB
infoleak
CVE-2018-14847CRITICALsob ataque08 nov 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-11043HIGHsob ataqueransomware06 nov 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-11043HIGHsob ataqueransomware06 nov 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-289305 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
60RISCO
abrir
VulnCheck XDB
local
CVE-2017-0005HIGHsob ataque05 nov 2019
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
76RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-261805 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
35RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-2725HIGHsob ataqueransomware05 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALsob ataqueransomware05 nov 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-1161002 nov 2019
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-019201 nov 2019
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-11043HIGHsob ataqueransomware30 out 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-11043HIGHsob ataqueransomware29 out 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
anteriorpágina 256 / 281próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.