Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.697exploits catalogados
36.715CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DB
qdPM 9.1 - Remote Code Execution
CVE-2020-7246webappsphp23 jan 2020
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir
Exploit-DBVexDay Proof
Reliable Datagram Sockets (RDS) - rds_atomic_free_op NULL pointer dereference Privilege Escalation (Metasploit)
CVE-2018-5333locallinux23 jan 2020
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning
43RISCO
abrir
Exploit-DB
Citrix XenMobile Server 10.8 - XML External Entity Injection
CVE-2018-10653webappsxml22 jan 2020
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 befor
23RISCO
abrir
Exploit-DB
Ricoh Printer Drivers - Local Privilege Escalation
CVE-2019-19363localwindows22 jan 2020
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attacker
38RISCO
abrir
Exploit-DB
Microsoft SharePoint - Deserialization Remote Code Execution
CVE-2019-0604CRITICALsob ataqueransomwareremotewindows21 jan 2020
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISCO
abrir
Exploit-DB
Centreon 19.04 - Authenticated Remote Code Execution (Metasploit)
CVE-2019-16405webappsphp20 jan 2020
Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code
28RISCO
abrir
Exploit-DB
Easy XML Editor 1.7.8 - XML External Entity Injection
CVE-2019-19031localxml20 jan 2020
Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS
23RISCO
abrir
Exploit-DBVexDay Proof
Plantronics Hub 3.13.2 - SpokesUpdateService Privilege Escalation (Metasploit)
CVE-2019-15742localwindows17 jan 2020
A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application
38RISCO
abrir
Exploit-DB
Jenkins Gitlab Hook Plugin 1.4.2 - Reflected Cross-Site Scripting
CVE-2020-2096webappsjava16 jan 2020
Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a ref
60RISCO
abrir
Exploit-DB
Citrix Application Delivery Controller (ADC) and Gateway 13.0 - Path Traversal
CVE-2019-19781CRITICALsob ataqueransomwarewebappsmultiple16 jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
Exploit-DB
WordPress Plugin Postie 1.9.40 - Persistent Cross-Site Scripting
CVE-2019-20204webappsphp16 jan 2020
The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginn
23RISCO
abrir
Exploit-DBVexDay Proof
Barco WePresent - file_transfer.cgi Command Injection (Metasploit)
CVE-2019-3929CRITICALsob ataqueremotelinux15 jan 2020
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RISCO
abrir
Exploit-DB
Microsoft Windows - CryptoAPI (Crypt32.dll) Elliptic Curve Cryptography (ECC) Spoof Code-Signing Certificate
CVE-2020-0601HIGHsob ataquelocalwindows15 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
Exploit-DBVexDay Proof
Android - ashmem Readonly Bypasses via remap_file_pages() and ASHMEM_UNPIN
CVE-2020-0009dosandroid14 jan 2020
In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This
23RISCO
abrir
Exploit-DB
Digi AnywhereUSB 14 - Reflective Cross-Site Scripting
CVE-2019-18859webappsphp13 jan 2020
Digi AnywhereUSB 14 allows XSS via a link for the Digi Page.
23RISCO
abrir
Exploit-DB
Citrix Application Delivery Controller and Gateway 10.5 - Remote Code Execution (Metasploit)
CVE-2019-19781CRITICALsob ataqueransomwarewebappsmultiple13 jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
Exploit-DB
Citrix Application Delivery Controller and Citrix Gateway - Remote Code Execution (PoC)
CVE-2019-19781CRITICALsob ataqueransomwarewebappsmultiple11 jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
Exploit-DB
Citrix Application Delivery Controller and Citrix Gateway - Remote Code Execution
CVE-2019-1978MEDIUMwebappsmultiple11 jan 2020
Cisco Firepower Threat Defense Software Stream Reassembly Bypass Vulnerability
33RISCO
abrir
Exploit-DBVexDay Proof
TotalAV 2020 4.14.31 - Privilege Escalation
CVE-2019-18194localwindows10 jan 2020
TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junctio
23RISCO
abrir
Exploit-DB
PixelStor 5000 K:4.0.1580-20150629 - Remote Code Execution
CVE-2020-6756CRITICALwebappsphp10 jan 2020
languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to re
53RISCO
abrir
Exploit-DB
Oracle Weblogic 10.3.6.0.0 - Remote Command Execution
CVE-2019-2729CRITICALwebappsjava09 jan 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISCO
abrir
Exploit-DB
EBBISLAND EBBSHAVE 6100-09-04-1441 - Remote Buffer Overflow
CVE-2017-3623remotehardware08 jan 2020
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported ve
28RISCO
abrir
Exploit-DBVexDay Proof
JetBrains TeamCity 2018.2.4 - Remote Code Execution
CVE-2019-15039remotejava08 jan 2020
An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in
28RISCO
abrir
Exploit-DB
Cisco DCNM JBoss 10.4 - Credential Leakage
CVE-2019-15999MEDIUMremotejava08 jan 2020
Cisco Data Center Network Manager JBoss EAP Unauthorized Access Vulnerability
33RISCO
abrir
Exploit-DBVexDay Proof
piSignage 2.6.4 - Directory Traversal
CVE-2019-20354webappshardware07 jan 2020
The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user)
23RISCO
abrir
Exploit-DB
Microsoft Windows 10 (19H1 1901 x64) - 'ws2ifsl.sys' Use After Free Local Privilege Escalation (kASLR kCFG SMEP)
CVE-2019-1215HIGHsob ataqueransomwarelocalwindows_x86-6407 jan 2020
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Win
76RISCO
abrir
Exploit-DB
Microsoft Windows - Shell COM Server Registrar Local Privilege Escalation
CVE-2019-1184MEDIUMlocalwindows02 jan 2020
Windows Elevation of Privilege Vulnerability
55RISCO
abrir
Exploit-DBVexDay Proof
nostromo 1.9.6 - Remote Code Execution
CVE-2019-16278CRITICALsob ataqueremotemultiple01 jan 2020
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir
Exploit-DB
Sony Playstation 4 (PS4) < 6.72 - WebKit Code Execution (PoC)
CVE-2018-4386webappshardware31 dez 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISCO
abrir
Exploit-DBVexDay Proof
OpenBSD - Dynamic Loader chpass Privilege Escalation (Metasploit)
CVE-2019-19726localopenbsd30 dez 2019
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RISCO
abrir
anteriorpágina 54 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.