Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.781exploits catalogados
36.771CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DBVexDay Proof
Trend Micro Anti-Threat Toolkit 1.62.0.1218 - Remote Code Execution
CVE-2019-9491localwindows21 out 2019
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow due to Malformed JP2 Stream (2)
CVE-2019-8197doswindows21 out 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISCO
abrir
Exploit-DB
Solaris 11.4 - xscreensaver Privilege Escalation
CVE-2019-3010HIGHsob ataquelocalsolaris21 out 2019
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RISCO
abrir
Exploit-DBVexDay Proof
ThinVNC 1.0b1 - Authentication Bypass
CVE-2019-17662remotewindows17 out 2019
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISCO
abrir
Exploit-DB
Whatsapp 2.19.216 - Remote Code Execution
CVE-2019-11932remoteandroid16 out 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
Exploit-DB
sudo 1.8.27 - Security Bypass
CVE-2019-14287locallinux15 out 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
Exploit-DB
WordPress Core < 5.2.3 - Viewing Unauthenticated/Password/Private Posts
CVE-2019-17671webappsmultiple14 out 2019
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is m
50RISCO
abrir
Exploit-DB
Apache Httpd mod_proxy - Error Page Cross-Site Scripting
CVE-2019-10092webappsmultiple14 out 2019
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page
60RISCO
abrir
Exploit-DB
Kirona-DRS 5.5.3.5 - Information Disclosure
CVE-2019-17503webappsphp14 out 2019
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REG
50RISCO
abrir
Exploit-DB
Kirona-DRS 5.5.3.5 - Information Disclosure
CVE-2019-17504webappsphp14 out 2019
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vuln
23RISCO
abrir
Exploit-DB
Apache Httpd mod_rewrite - Open Redirects
CVE-2019-10098webappsmultiple14 out 2019
In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential m
60RISCO
abrir
Exploit-DB
SMA Solar Technology AG Sunny WebBox device - 1.6 - Cross-Site Request Forgery
CVE-2019-13529HIGHwebappshardware10 out 2019
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action
41RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - NULL Pointer Dereference in nt!MiOffsetToProtos While Parsing Malformed PE File
CVE-2019-1343doswindows10 out 2019
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in nt!MiParseImageLoadConfig While Parsing Malformed PE File
CVE-2019-1345doswindows10 out 2019
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in CI!HashKComputeFirstPageHash While Parsing Malformed PE File
CVE-2019-1346doswindows10 out 2019
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - win32k.sys TTF Font Processing Pool Corruption in win32k!ulClearTypeFilter
CVE-2019-1364doswindows10 out 2019
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in nt!MiRelocateImage While Parsing Malformed PE File
CVE-2019-1347doswindows10 out 2019
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RISCO
abrir
Exploit-DB
TP-Link TL-WR1043ND 2 - Authentication Bypass
CVE-2019-6971webappshardware10 out 2019
An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packe
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in CI!CipFixImageType While Parsing Malformed PE File
CVE-2019-1344doswindows10 out 2019
An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memo
23RISCO
abrir
Exploit-DBVexDay Proof
XNU - Remote Double-Free via Data Race in IPComp Input Path
CVE-2019-8717dosmacos09 out 2019
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15, tvOS
23RISCO
abrir
Exploit-DB
vBulletin 5.0 < 5.5.4 - 'updateAvatar' Authenticated Remote Code Execution
CVE-2019-17132webappsphp07 out 2019
vBulletin through 5.5.4 mishandles custom avatars.
28RISCO
abrir
Exploit-DB
IBM Bigfix Platform 9.5.9.62 - Arbitrary File Upload
CVE-2019-4013CRITICALwebappsjava07 out 2019
IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root pr
53RISCO
abrir
Exploit-DB
Subrion 4.2.1 - 'Email' Persistant Cross-Site Scripting
CVE-2019-17225webappsphp07 out 2019
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" i
23RISCO
abrir
Exploit-DB
CheckPoint Endpoint Security Client/ZoneAlarm 15.4.062.17802 - Privilege Escalation
CVE-2019-8452localwindows07 out 2019
A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security clien
23RISCO
abrir
Exploit-DBVexDay Proof
Android - Binder Driver Use-After-Free
CVE-2019-2215HIGHsob ataquelocalandroid04 out 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
Exploit-DB
AnchorCMS < 0.12.3a - Information Disclosure
CVE-2018-7251webappsmultiple03 out 2019
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contain
60RISCO
abrir
Exploit-DB
mintinstall 7.9.9 - Code Execution
CVE-2019-17080webappslinux03 out 2019
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by a
23RISCO
abrir
Exploit-DBVexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
CVE-2017-0145HIGHsob ataqueransomwareremotewindows02 out 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DBVexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
CVE-2017-0148HIGHsob ataqueransomwareremotewindows02 out 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DBVexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
CVE-2017-0144HIGHsob ataqueransomwareremotewindows02 out 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
anteriorpágina 58 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.