Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.697exploits catalogados
36.715CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DB
Go SSH servers 0.0.2 - Denial of Service (PoC)
CVE-2020-9283doslinux24 fev 2020
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the
28RISCO
abrir
Exploit-DB
ManageEngine EventLog Analyzer 10.0 - Information Disclosure
CVE-2019-19774webappsjava24 fev 2020
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetai
28RISCO
abrir
Exploit-DB
Avaya IP Office Application Server 11.0.0.0 - Reflective Cross-Site Scripting
CVE-2019-7004MEDIUMwebappshardware24 fev 2020
Avaya IP Office XSS Vulnerability
33RISCO
abrir
Exploit-DBVexDay Proof
Android Binder - Use-After-Free (Metasploit)
CVE-2019-2215HIGHsob ataquelocalandroid24 fev 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
Exploit-DBVexDay Proof
Apache James Server 2.3.2 - Insecure User Creation Arbitrary File Write (Metasploit)
CVE-2015-7611remotelinux24 fev 2020
Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary syst
50RISCO
abrir
Exploit-DB
Apache Tomcat - AJP 'Ghostcat File Read/Inclusion
CVE-2020-1938CRITICALsob ataquewebappsmultiple20 fev 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
Exploit-DB
MSI Packages Symbolic Links Processing - Windows 10 Privilege Escalation
CVE-2020-0683HIGHsob ataquelocalwindows17 fev 2020
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
71RISCO
abrir
Exploit-DBVexDay Proof
Anviz CrossChex - Buffer Overflow (Metasploit)
CVE-2019-12518remotewindows17 fev 2020
Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.
50RISCO
abrir
Exploit-DB
PANDORAFMS 7.0 - Authenticated Remote Code Execution
CVE-2020-8947webappsphp13 fev 2020
functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metac
28RISCO
abrir
Exploit-DBVexDay Proof
HP System Event Utility - Local Privilege Escalation
CVE-2019-18915localwindows12 fev 2020
A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version
23RISCO
abrir
Exploit-DB
Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting
CVE-2020-8825webappsphp11 fev 2020
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
23RISCO
abrir
Exploit-DBVexDay Proof
OpenSMTPD 6.4.0 < 6.6.1 - Local Privilege Escalation + Remote Code Execution
CVE-2020-7247CRITICALsob ataqueremoteopenbsd11 fev 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISCO
abrir
Exploit-DB
CHIYU BF430 TCP IP Converter - Stored Cross-Site Scripting
CVE-2020-8839webappscgi11 fev 2020
Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cg
23RISCO
abrir
Exploit-DBVexDay Proof
Ricoh Driver - Privilege Escalation (Metasploit)
CVE-2019-19363localwindows10 fev 2020
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attacker
38RISCO
abrir
Exploit-DB
Dota 2 7.23f - Denial of Service (PoC)
CVE-2020-7949doswindows10 fev 2020
schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by
23RISCO
abrir
Exploit-DB
WordPress Plugin LearnDash LMS 3.1.2 - Reflective Cross-Site Scripting
CVE-2020-7108webappsphp10 fev 2020
The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.
23RISCO
abrir
Exploit-DBVexDay Proof
D-Link Devices - Unauthenticated Remote Command Execution in ssdpcgi (Metasploit)
CVE-2019-20215remotelinux_mips10 fev 2020
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the
60RISCO
abrir
Exploit-DB
Forcepoint WebSecurity 8.5 - Reflective Cross-Site Scripting
CVE-2019-6146webappsmultiple10 fev 2020
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host heade
23RISCO
abrir
Exploit-DBVexDay Proof
iOS/macOS - Out-of-Bounds Timestamp Write in IOAccelCommandQueue2::processSegmentKernelCommand()
CVE-2020-3837HIGHsob ataquedosmultiple10 fev 2020
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3
76RISCO
abrir
Exploit-DBVexDay Proof
OpenSMTPD - MAIL FROM Remote Code Execution (Metasploit)
CVE-2020-7247CRITICALsob ataqueremotelinux10 fev 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISCO
abrir
Exploit-DB
EyesOfNetwork 5.3 - Remote Code Execution
CVE-2020-8655HIGHsob ataquewebappsphp07 fev 2020
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability
98RISCO
abrir
Exploit-DB
EyesOfNetwork 5.3 - Remote Code Execution
CVE-2020-8656webappsphp07 fev 2020
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe
60RISCO
abrir
Exploit-DB
EyesOfNetwork 5.3 - Remote Code Execution
CVE-2020-8654webappsphp07 fev 2020
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoD
60RISCO
abrir
Exploit-DBVexDay Proof
Windscribe - WindscribeService Named Pipe Privilege Escalation (Metasploit)
CVE-2018-11479localwindows07 fev 2020
The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe s
43RISCO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager 11.2 - Remote Code Execution
CVE-2019-15975CRITICALwebappsjava06 fev 2020
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
85RISCO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager 11.2.1 - 'LanFabricImpl' Command Injection
CVE-2019-15978HIGHwebappsjava06 fev 2020
Cisco Data Center Network Manager Command Injection Vulnerabilities
53RISCO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager 11.2.1 - 'getVmHostData' SQL Injection
CVE-2019-15976CRITICALwebappsjava06 fev 2020
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
70RISCO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager 11.2.1 - 'LanFabricImpl' Command Injection
CVE-2019-15977CRITICALwebappsjava06 fev 2020
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
60RISCO
abrir
Exploit-DB
Sudo 1.8.25p - 'pwfeedback' Buffer Overflow
CVE-2019-18634locallinux06 fev 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager 11.2.1 - 'getVmHostData' SQL Injection
CVE-2019-15984HIGHwebappsjava06 fev 2020
Cisco Data Center Network Manager SQL Injection Vulnerabilities
53RISCO
abrir
anteriorpágina 52 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.