Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.781exploits catalogados
36.771CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DBVexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
CVE-2017-0145HIGHsob ataqueransomwareremotewindows02 out 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DBVexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
CVE-2017-0144HIGHsob ataqueransomwareremotewindows02 out 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DBVexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
CVE-2017-0146HIGHsob ataqueransomwareremotewindows02 out 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DB
DotNetNuke < 9.4.0 - Cross-Site Scripting
CVE-2019-12562webappsmultiple01 out 2019
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the mali
23RISCO
abrir
Exploit-DB
WordPress Plugin ARforms 3.7.1 - Arbitrary File Deletion
CVE-2019-16902webappsphp30 set 2019
In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an
23RISCO
abrir
Exploit-DB
Cisco Small Business 220 Series - Multiple Vulnerabilities
CVE-2019-1912CRITICALremotehardware30 set 2019
Cisco Small Business 220 Series Smart Switches Authentication Bypass Vulnerability
53RISCO
abrir
Exploit-DB
GoAhead 2.5.0 - Host Header Injection
CVE-2019-16645remotemultiple30 set 2019
An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) cre
23RISCO
abrir
Exploit-DB
phpIPAM 1.4 - SQL Injection
CVE-2019-16692webappsphp30 set 2019
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is us
28RISCO
abrir
Exploit-DB
Cisco Small Business 220 Series - Multiple Vulnerabilities
CVE-2019-1913CRITICALremotehardware30 set 2019
Cisco Small Business 220 Series Smart Switches Remote Code Execution Vulnerabilities
53RISCO
abrir
Exploit-DB
Cisco Small Business 220 Series - Multiple Vulnerabilities
CVE-2019-1914HIGHremotehardware30 set 2019
Cisco Small Business 220 Series Smart Switches Command Injection Vulnerability
46RISCO
abrir
Exploit-DB
vBulletin 5.x - Remote Command Execution (Metasploit)
CVE-2019-16759CRITICALsob ataquewebappsphp30 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
Exploit-DB
NPMJS gitlabhook 0.0.17 - 'repository' Remote Command Execution
CVE-2019-5485webappsjson25 set 2019
NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be inje
35RISCO
abrir
Exploit-DB
Microsoft SharePoint 2013 SP1 - 'DestinationFolder' Persistant Cross-Site Scripting
CVE-2019-1262webappsaspx25 set 2019
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall
23RISCO
abrir
Exploit-DBVexDay Proof
ABRT - sosreport Privilege Escalation (Metasploit)
CVE-2015-5287HIGHsob ataquelocallinux25 set 2019
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - BlueKeep RDP Remote Windows Kernel Use After Free (Metasploit)
CVE-2019-0708CRITICALsob ataqueransomwareremotewindows24 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary Can Read Object Out of Bounds
CVE-2019-8641dosios24 set 2019
An out-of-bounds read was addressed with improved input validation.
28RISCO
abrir
Exploit-DB
Pfsense 2.3.4 / 2.4.4-p3 - Remote Code Injection
CVE-2019-16701webappsphp24 set 2019
pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_ph
28RISCO
abrir
Exploit-DB
Gila CMS < 1.11.1 - Local File Inclusion
CVE-2019-16679webappsmultiple23 set 2019
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
23RISCO
abrir
Exploit-DB
vBulletin 5.0 < 5.5.4 - 'widget_php ' Unauthenticated Remote Code Execution
CVE-2019-16759CRITICALsob ataquewebappsphp23 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
Exploit-DB
iOS < 12.4.1 - 'Jailbreak' Local Privilege Escalation
CVE-2019-8605HIGHsob ataquelocalios23 set 2019
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RISCO
abrir
Exploit-DB
HPE Intelligent Management Center < 7.3 E0506P09 - Information Disclosure
CVE-2019-5392remotewatchos23 set 2019
A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than ve
23RISCO
abrir
Exploit-DB
LayerBB < 1.1.4 - Cross-Site Request Forgery
CVE-2019-16531webappsphp20 set 2019
LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
23RISCO
abrir
Exploit-DB
Western Digital My Book World II NAS 1.02.12 - Authentication Bypass / Command Execution
CVE-2019-16399webappshardware19 set 2019
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to acce
23RISCO
abrir
Exploit-DB
Counter-Strike Global Offensive 1.37.1.1 - 'vphysics.dll' Denial of Service (PoC)
CVE-2019-15943doswindows18 set 2019
vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or de
23RISCO
abrir
Exploit-DB
Notepad++ < 7.7 (x64) - Denial of Service
CVE-2019-16294doswindows_x86-6416 set 2019
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode ch
23RISCO
abrir
Exploit-DB
AppXSvc - Privilege Escalation
CVE-2019-1253HIGHsob ataqueransomwarelocalwindows16 set 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISCO
abrir
Exploit-DB
Symantec Advanced Secure Gateway (ASG) / ProxySG - Unrestricted File Upload
CVE-2016-10258webappscfm16 set 2019
Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A
23RISCO
abrir
Exploit-DB
Dolibarr ERP-CRM 10.0.1 - 'User-Agent' Cross-Site Scripting
CVE-2019-16197webappsphp13 set 2019
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document
23RISCO
abrir
Exploit-DBVexDay Proof
LimeSurvey 3.17.13 - Cross-Site Scripting
CVE-2019-16172webappsphp13 set 2019
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
23RISCO
abrir
Exploit-DBVexDay Proof
LimeSurvey 3.17.13 - Cross-Site Scripting
CVE-2019-16173webappsphp13 set 2019
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example,
23RISCO
abrir
anteriorpágina 59 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.