Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.781exploits catalogados
36.771CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DB
CBAS-Web 19.0.0 - Username Enumeration
CVE-2019-10848webappshardware12 nov 2019
Computrols CBAS 18.0.0 allows Username Enumeration.
23RISCO
abrir
Exploit-DB
Optergy 2.3.0a - Remote Code Execution (Backdoor)
CVE-2019-7276webappshardware12 nov 2019
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
60RISCO
abrir
Exploit-DB
Adrenalin Core HCM 5.4.0 - 'prntDDLCntrlName' Reflected Cross-Site Scripting
CVE-2018-12650webappsaspx12 nov 2019
Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSe
23RISCO
abrir
Exploit-DB
CBAS-Web 19.0.0 - Cross-Site Request Forgery (Add Super Admin)
CVE-2019-10847webappshardware12 nov 2019
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
23RISCO
abrir
Exploit-DB
Optergy 2.3.0a - Cross-Site Request Forgery (Add Admin)
CVE-2019-7273webappshardware12 nov 2019
Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
23RISCO
abrir
Exploit-DB
Adrenalin Core HCM 5.4.0 - 'strAction' Reflected Cross-Site Scripting
CVE-2018-12234webappsaspx12 nov 2019
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied
23RISCO
abrir
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
CVE-2019-8662dosmultiple11 nov 2019
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RISCO
abrir
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
CVE-2019-8641dosmultiple11 nov 2019
An out-of-bounds read was addressed with improved input validation.
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream
CVE-2019-8195doswindows11 nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed OTF Font (CFF Table)
CVE-2019-8196doswindows11 nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISCO
abrir
Exploit-DBVexDay Proof
rConfig - install Command Execution (Metasploit)
CVE-2019-16662remotelinux08 nov 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISCO
abrir
Exploit-DB
Adive Framework 2.0.7 - Privilege Escalation
CVE-2019-14347webappsphp08 nov 2019
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an ad
23RISCO
abrir
Exploit-DBVexDay Proof
Android Janus - APK Signature Bypass (Metasploit)
CVE-2017-13156localandroid08 nov 2019
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RISCO
abrir
Exploit-DB
Jenkins build-metrics plugin 1.3 - 'label' Cross-Site Scripting
CVE-2019-10475webappsjava08 nov 2019
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML
50RISCO
abrir
Exploit-DBVexDay Proof
JavaScriptCore - Type Confusion During Bailout when Reconstructing Arguments Objects
CVE-2019-8820dosmultiple05 nov 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPad
23RISCO
abrir
Exploit-DBVexDay Proof
Micro Focus (HPE) Data Protector - SUID Privilege Escalation (Metasploit)
CVE-2019-11660locallinux04 nov 2019
Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30,
38RISCO
abrir
Exploit-DB
Apache Solr 8.2.0 - Remote Code Execution
CVE-2019-17558HIGHsob ataquewebappsjava01 nov 2019
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RISCO
abrir
Exploit-DBVexDay Proof
Nostromo - Directory Traversal Remote Command Execution (Metasploit)
CVE-2019-16278CRITICALsob ataqueremotemultiple01 nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir
Exploit-DB
MikroTik RouterOS 6.45.6 - DNS Cache Poisoning
CVE-2019-3978remotehardware31 out 2019
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queri
28RISCO
abrir
Exploit-DBVexDay Proof
JavaScriptCore - GetterSetter Type Confusion During DFG Compilation
CVE-2019-8765dosmultiple30 out 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Proc
23RISCO
abrir
Exploit-DB
Microsoft Windows Server 2012 - 'Group Policy' Remote Code Execution (MS15-011)
CVE-2015-0008remotewindows29 out 2019
The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Wind
28RISCO
abrir
Exploit-DB
rConfig 3.9.2 - Remote Code Execution
CVE-2019-16662webappsphp29 out 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISCO
abrir
Exploit-DB
Microsoft Windows Server 2012 - 'Group Policy' Security Feature Bypass (MS15-014)
CVE-2015-0009remotewindows29 out 2019
The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, W
23RISCO
abrir
Exploit-DB
PHP-FPM + Nginx - Remote Code Execution
CVE-2019-11043HIGHsob ataqueransomwarewebappsphp28 out 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
Exploit-DB
ClonOs WEB UI 19.09 - Improper Access Control
CVE-2019-18418webappsphp25 out 2019
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests be
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Polkit - pkexec helper PTRACE_TRACEME local root (Metasploit)
CVE-2019-13272HIGHsob ataquelocallinux24 out 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
Exploit-DB
Rocket.Chat 2.1.0 - Cross-Site Scripting
CVE-2019-17220webappslinux23 out 2019
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
23RISCO
abrir
Exploit-DB
Moxa EDR-810 - Command Injection / Information Disclosure
CVE-2019-10969remotehardware22 out 2019
Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthor
28RISCO
abrir
Exploit-DBVexDay Proof
Total.js CMS 12 - Widget JavaScript Code Injection (Metasploit)
CVE-2019-15954remotemultiple22 out 2019
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote
60RISCO
abrir
Exploit-DB
Moxa EDR-810 - Command Injection / Information Disclosure
CVE-2019-10963remotehardware22 out 2019
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from
23RISCO
abrir
anteriorpágina 57 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.