Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.646exploits catalogados
37.382CVEs com exploração pública
24.695testados em laboratório
9.029 exploits
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALsob ataqueransomware17 ago 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-16759CRITICALsob ataque16 ago 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-6286MEDIUM13 ago 2020
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuratio
38RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-16759CRITICALsob ataque13 ago 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2016-2386CRITICALsob ataque13 ago 2020
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2020-4463HIGH13 ago 2020
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when proc
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-5902CRITICALsob ataqueransomware13 ago 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-6287CRITICALsob ataque13 ago 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-3452HIGHsob ataque13 ago 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-16759CRITICALsob ataque12 ago 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
VulnCheck XDB
local
CVE-2020-1048HIGH11 ago 2020
Windows Print Spooler Elevation of Privilege Vulnerability
61RISCO
abrir
VulnCheck XDB
local
CVE-2020-0041HIGHsob ataque10 ago 2020
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALsob ataqueransomware10 ago 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2015-4852CRITICALsob ataque10 ago 2020
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISCO
abrir
VulnCheck XDB
local
CVE-2020-0787HIGHsob ataqueransomware09 ago 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISCO
abrir
VulnCheck XDB
local
CVE-2015-000309 ago 2020
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
23RISCO
abrir
VulnCheck XDB
local
CVE-2016-322509 ago 2020
The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
50RISCO
abrir
VulnCheck XDB
local
CVE-2011-2005HIGHsob ataque09 ago 2020
afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly valid
98RISCO
abrir
VulnCheck XDB
local
CVE-2019-1458HIGHsob ataqueransomware09 ago 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
VulnCheck XDB
local
CVE-2018-8120HIGHsob ataqueransomware09 ago 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
VulnCheck XDB
local
CVE-2019-062309 ago 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
23RISCO
abrir
VulnCheck XDB
local
CVE-2010-333809 ago 2020
The Windows Task Scheduler in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7
43RISCO
abrir
VulnCheck XDB
local
CVE-2014-407609 ago 2020
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RISCO
abrir
VulnCheck XDB
local
CVE-2015-2387HIGHsob ataque09 ago 2020
ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server
83RISCO
abrir
VulnCheck XDB
local
CVE-2011-124909 ago 2020
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vis
23RISCO
abrir
VulnCheck XDB
local
CVE-2019-1132HIGHsob ataque09 ago 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware09 ago 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-33739HIGHsob ataque09 ago 2020
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RISCO
abrir
VulnCheck XDB
local
CVE-2019-0808HIGHsob ataque09 ago 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISCO
abrir
VulnCheck XDB
local
CVE-2020-1054HIGHsob ataque09 ago 2020
Win32k Elevation of Privilege Vulnerability
98RISCO
abrir
anteriorpágina 264 / 301próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.