Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.902exploits catalogados
34.597CVEs com exploração pública
24.695testados em laboratório
8.410 exploits
VulnCheck XDB
client-side
CVE-2018-20250HIGHsob ataqueransomware15 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHsob ataqueransomware15 mar 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHsob ataqueransomware11 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-19276CRITICAL11 mar 2019
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-019210 mar 2019
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-1724608 mar 2019
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with
60RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-100300006 mar 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHsob ataqueransomware05 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
VulnCheck XDB
local
CVE-2018-8639HIGHsob ataqueransomware05 mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHsob ataqueransomware05 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHsob ataqueransomware04 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHsob ataqueransomware28 fev 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-7238CRITICALsob ataque24 fev 2019
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-6340HIGHsob ataque23 fev 2019
Drupal core - Highly critical - Remote Code Execution
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHsob ataqueransomware23 fev 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHsob ataqueransomware22 fev 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
VulnCheck XDB
local
CVE-2019-573620 fev 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-100300015 fev 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISCO
abrir
VulnCheck XDB
local
CVE-2019-573614 fev 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
VulnCheck XDB
local
CVE-2019-573613 fev 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
VulnCheck XDB
local
CVE-2019-573612 fev 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-6961HIGHsob ataque08 fev 2019
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-1653HIGHsob ataque30 jan 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-999528 jan 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-1885226 jan 2019
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-in
35RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-8581HIGHsob ataqueransomware24 jan 2019
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
76RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-1653HIGHsob ataque24 jan 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-1652HIGHsob ataque24 jan 2019
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALsob ataqueransomware20 jan 2019
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-8174HIGHsob ataqueransomware20 jan 2019
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
anteriorpágina 264 / 281próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.