Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.842exploits catalogados
36.821CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DB
WordPress Plugin WooCommerce Product Feed 2.2.18 - Cross-Site Scripting
CVE-2019-1010124webappsphp30 ago 2019
WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to
23RISCO
abrir
Exploit-DBVexDay Proof
Webkit JSC: JIT - Uninitialized Variable Access in ArgumentsEliminationPhase::transform
CVE-2019-8689dosmultiple29 ago 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS M
28RISCO
abrir
Exploit-DB
SQLiteManager 1.2.0 / 1.2.4 - Blind SQL Injection
CVE-2019-9083webappsphp28 ago 2019
SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. NOTE: This product is
28RISCO
abrir
Exploit-DBVexDay Proof
Tableau - XML External Entity
CVE-2019-15637HIGHwebappsmultiple27 ago 2019
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to informat
46RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - SET_REPARSE_POINT_EX Mount Point Security Feature Bypass
CVE-2019-1170HIGHlocalwindows26 ago 2019
Windows NTFS Elevation of Privilege Vulnerability
41RISCO
abrir
Exploit-DBVexDay Proof
Exim 4.87 / 4.91 - Local Privilege Escalation (Metasploit)
CVE-2019-10149CRITICALsob ataquelocallinux26 ago 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir
Exploit-DB
openITCOCKPIT 3.6.1-2 - Cross-Site Request Forgery
CVE-2019-10227webappsphp26 ago 2019
openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.
23RISCO
abrir
Exploit-DB
WordPress Plugin Import Export WordPress Users 1.3.1 - CSV Injection
CVE-2019-15092webappsphp26 ago 2019
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in
23RISCO
abrir
Exploit-DB
Nimble Streamer 3.0.2-2 < 3.5.4-9 - Directory Traversal
CVE-2019-11013webappsmultiple23 ago 2019
Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow
43RISCO
abrir
Exploit-DB
LibreOffice < 6.2.6 Macro - Python Code Execution (Metasploit)
CVE-2019-9851remotemultiple21 ago 2019
LibreLogo global-event script execution
60RISCO
abrir
Exploit-DB
Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure (Metasploit)
CVE-2019-11510CRITICALsob ataqueransomwarewebappsmultiple21 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISCO
abrir
Exploit-DB
QEMU - Denial of Service
CVE-2019-14378doslinux20 ago 2019
ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a cas
28RISCO
abrir
Exploit-DB
Fortinet FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure (Metasploit)
CVE-2018-13379CRITICALsob ataqueransomwarewebappshardware19 ago 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
Exploit-DB
Fortinet FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure
CVE-2018-13379CRITICALsob ataqueransomwarewebappshardware19 ago 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
Exploit-DB
Webmin 1.920 - Remote Code Execution
CVE-2019-15107CRITICALsob ataqueransomwarewebappslinux19 ago 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap Corruption in ReadTableIntoStructure
CVE-2019-1150HIGHdoswindows15 ago 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use-After-Free due to Malformed JP2 Stream
CVE-2019-8024doswindows15 ago 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat CoolType (AFDKO) - Call from Uninitialized Memory due to Empty FDArray in Type 1 Fonts
CVE-2019-8017doswindows15 ago 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - free() of Uninitialized Pointer due to Malformed JBIG2Globals Stream
CVE-2019-8045doswindows15 ago 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Returning a Dangling Pointer via MergeFontPackage
CVE-2019-1145HIGHdoswindows15 ago 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in GetGlyphIdx
CVE-2019-1148MEDIUMdoswindows15 ago 2019
Microsoft Graphics Component Information Disclosure Vulnerability
33RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow While Processing Malformed PDF
CVE-2019-8050doswindows15 ago 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
35RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Out-of-Bounds read due to Malformed JP2 Stream
CVE-2019-8043doswindows15 ago 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Memory Corruption due to Malformed TTF Font
CVE-2019-8042doswindows15 ago 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat CoolType (AFDKO) - Memory Corruption in the Handling of Type 1 Font load/store Operators
CVE-2019-8016doswindows15 ago 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap Corruption in FixSbitSubTables
CVE-2019-1149HIGHdoswindows15 ago 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Static Buffer Overflow due to Malformed Font Stream
CVE-2019-8048doswindows15 ago 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in FixSbitSubTableFormat1
CVE-2019-1153MEDIUMdoswindows15 ago 2019
Microsoft Graphics Component Information Disclosure Vulnerability
33RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow in CoolType.dll
CVE-2019-8041doswindows15 ago 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow due to Malformed Font Stream
CVE-2019-8049doswindows15 ago 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISCO
abrir
anteriorpágina 61 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.