Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.697exploits catalogados
36.715CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DB
xglance-bin 11.00 - Privilege Escalation
CVE-2014-2630locallinux05 fev 2020
Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via u
38RISCO
abrir
Exploit-DB
Kronos WebTA 4.0 - Authenticated Remote Privilege Escalation
CVE-2020-8495HIGHwebappsjava05 fev 2020
In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate se
41RISCO
abrir
Exploit-DB
Kronos WebTA 4.0 - Authenticated Remote Privilege Escalation
CVE-2020-8493MEDIUMwebappsjava05 fev 2020
A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via
33RISCO
abrir
Exploit-DB
Verodin Director Web Console 3.5.4.0 - Remote Authenticated Password Disclosure (PoC)
CVE-2019-10716webappsjson05 fev 2020
An Information Disclosure issue in Verodin Director 3.5.3.1 and earlier reveals usernames and passwords of integrated se
23RISCO
abrir
Exploit-DB
Sudo 1.8.25p - 'pwfeedback' Buffer Overflow (PoC)
CVE-2019-18634doslinux04 fev 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir
Exploit-DB
School ERP System 1.0 - Cross Site Request Forgery (Add Admin)
CVE-2020-8505webappsphp03 fev 2020
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.
23RISCO
abrir
Exploit-DB
IceWarp WebMail 11.4.4.1 - Reflective Cross-Site Scripting
CVE-2020-8512webappsphp03 fev 2020
In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.
43RISCO
abrir
Exploit-DB
BearFTP 0.1.0 - 'PASV' Denial of Service
CVE-2020-8416doslinux03 fev 2020
IKTeam BearFTP before 0.2.0 allows remote attackers to achieve denial of service via a large volume of connections to th
28RISCO
abrir
Exploit-DB
Jira 8.3.4 - Information Disclosure (Username Enumeration)
CVE-2019-8449webappsjava03 fev 2020
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate username
60RISCO
abrir
Exploit-DB
School ERP System 1.0 - Cross Site Request Forgery (Add Admin)
CVE-2020-8504webappsphp03 fev 2020
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrati
23RISCO
abrir
Exploit-DB
Cacti 1.2.8 - Authenticated Remote Code Execution
CVE-2020-8813webappsmultiple03 fev 2020
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISCO
abrir
Exploit-DB
Cacti 1.2.8 - Unauthenticated Remote Code Execution
CVE-2020-8813webappsmultiple03 fev 2020
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISCO
abrir
Exploit-DB
Schneider Electric U.Motion Builder 1.3.4 - Authenticated Command Injection
CVE-2018-7777webappshardware03 fev 2020
The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Ele
28RISCO
abrir
Exploit-DBVexDay Proof
OpenSMTPD 6.6.1 - Remote Code Execution
CVE-2020-7247CRITICALsob ataqueremotelinux30 jan 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISCO
abrir
Exploit-DBVexDay Proof
rConfig 3.9.3 - Authenticated Remote Code Execution
CVE-2019-19509webappsphp30 jan 2020
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a
60RISCO
abrir
Exploit-DB
Satellian 1.12 - Remote Code Execution
CVE-2020-7980webappshardware29 jan 2020
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RISCO
abrir
Exploit-DB
Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)
CVE-2020-8424webappsphp29 jan 2020
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php
23RISCO
abrir
Exploit-DB
Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)
CVE-2020-8425webappsphp29 jan 2020
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
23RISCO
abrir
Exploit-DB
Microsoft Windows 10 - Theme API 'ThemePack' File Parsing
CVE-2018-8413localwindows29 jan 2020
A remote code execution vulnerability exists when "Windows Theme API" does not properly decompress files, aka "Windows T
35RISCO
abrir
Exploit-DB
XMLBlueprint 16.191112 - XML External Entity Injection
CVE-2019-19032localwindows29 jan 2020
XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an
23RISCO
abrir
Exploit-DBVexDay Proof
Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password)
CVE-2020-7991webappsphp28 jan 2020
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
23RISCO
abrir
Exploit-DB
Octeth Oempro 4.8 - 'CampaignID' SQL Injection
CVE-2019-19740webappsphp28 jan 2020
Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
23RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - Information Disclosure
CVE-2019-1125MEDIUMlocalwindows27 jan 2020
Windows Kernel Information Disclosure Vulnerability
33RISCO
abrir
Exploit-DB
TP-Link TP-SG105E 1.0.0 - Unauthenticated Remote Reboot
CVE-2019-16893webappshardware24 jan 2020
The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the
35RISCO
abrir
Exploit-DB
Genexis Platinum-4410 2.1 - Authentication Bypass
CVE-2020-6170webappshardware24 jan 2020
An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cl
23RISCO
abrir
Exploit-DB
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
CVE-2020-0610doswindows23 jan 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
35RISCO
abrir
Exploit-DB
qdPM 9.1 - Remote Code Execution
CVE-2020-7246webappsphp23 jan 2020
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir
Exploit-DB
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
CVE-2020-0610doswindows23 jan 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
35RISCO
abrir
Exploit-DBVexDay Proof
Reliable Datagram Sockets (RDS) - rds_atomic_free_op NULL pointer dereference Privilege Escalation (Metasploit)
CVE-2018-5333locallinux23 jan 2020
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning
43RISCO
abrir
Exploit-DB
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
CVE-2020-0609doswindows23 jan 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISCO
abrir
anteriorpágina 53 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.