Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.858exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DBVexDay Proof
iMessage - Memory Corruption when Decoding NSKnownKeysDictionary1
CVE-2019-8660dosmultiple30 jul 2019
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10
28RISCO
abrir
Exploit-DBVexDay Proof
Amcrest Cameras 2.520.AC00.18.R - Unauthenticated Audio Streaming
CVE-2019-3948webappshardware30 jul 2019
The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0
28RISCO
abrir
Exploit-DB
WordPress Plugin Simple Membership 3.8.4 - Cross-Site Request Forgery
CVE-2019-14328webappsphp29 jul 2019
The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.
23RISCO
abrir
Exploit-DBVexDay Proof
Schneider Electric Pelco Endura NET55XX Encoder - Authentication Bypass (Metasploit)
CVE-2019-6814remoteunix29 jul 2019
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 wh
50RISCO
abrir
Exploit-DB
Microsoft Windows 7 build 7601 (x86) - Local Privilege Escalation
CVE-2019-1132HIGHsob ataquelocalwindows_x8626 jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISCO
abrir
Exploit-DB
Ahsay Backup 7.x - 8.1.1.50 - Authenticated Arbitrary File Upload / Remote Code Execution (Metasploit)
CVE-2019-10267webappsjsp26 jul 2019
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to
60RISCO
abrir
Exploit-DBVexDay Proof
Ahsay Backup 8.1.1.50 - Insecure File Upload and Code Execution (Authenticated)
CVE-2019-10267webappsjsp26 jul 2019
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to
60RISCO
abrir
Exploit-DBVexDay Proof
pdfresurrect 0.15 - Buffer Overflow
CVE-2019-14267doslinux26 jul 2019
PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is misha
23RISCO
abrir
Exploit-DB
Moodle Filepicker 3.5.2 - Server Side Request Forgery
CVE-2018-1042webappsphp26 jul 2019
Moodle 3.x has Server Side Request Forgery in the filepicker.
28RISCO
abrir
Exploit-DB
Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injection
CVE-2019-10266webappsjsp26 jul 2019
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL
28RISCO
abrir
Exploit-DB
Ovidentia 8.4.3 - Cross-Site Scripting
CVE-2019-13977webappsphp25 jul 2019
index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=crea
23RISCO
abrir
Exploit-DBVexDay Proof
WebKit - Universal Cross-Site Scripting due to Synchronous Page Loads
CVE-2019-8649dosmultiple25 jul 2019
A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management
23RISCO
abrir
Exploit-DB
Cisco Wireless Controller 3.6.10E - Cross-Site Request Forgery
CVE-2019-12624HIGHwebappshardware24 jul 2019
Cisco IOS XE NGWC Legacy Wireless Device Manager GUI Cross-Site Request Forgery Vulnerability
46RISCO
abrir
Exploit-DBVexDay Proof
Apple iMessage - DigitalTouch tap Message Processing Out-of-Bounds Read
CVE-2019-8624doswatchos24 jul 2019
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5.3. A remote attacke
23RISCO
abrir
Exploit-DB
Linux Kernel 4.10 < 5.1.17 - 'PTRACE_TRACEME' pkexec Local Privilege Escalation
CVE-2019-13272HIGHsob ataquelocallinux24 jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
Exploit-DB
Android 7 < 9 - Remote Code Execution
CVE-2019-2107remoteandroid24 jul 2019
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th
23RISCO
abrir
Exploit-DB
BACnet Stack 0.8.6 - Denial of Service
CVE-2019-12480doslinux22 jul 2019
BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a
35RISCO
abrir
Exploit-DB
MAPLE Computer WBT SNMP Administrator 2.0.195.15 - Remote Buffer Overflow (EggHunter)
CVE-2019-13577remotewindows_x8619 jul 2019
SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string
28RISCO
abrir
Exploit-DB
REDCap < 9.1.2 - Cross-Site Scripting
CVE-2019-13029webappsphp19 jul 2019
Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 before 8.10.20 and 9
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1903/1809 - RPCSS Activation Kernel Security Callback Privilege Escalation
CVE-2019-1089localwindows18 jul 2019
An elevation of privilege vulnerability exists in rpcss.dll when the RPC service Activation Kernel improperly handles an
23RISCO
abrir
Exploit-DB
MAPLE Computer WBT SNMP Administrator 2.0.195.15 - Remote Buffer Overflow
CVE-2019-13577remotewindows17 jul 2019
SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string
28RISCO
abrir
Exploit-DBVexDay Proof
Linux - Broken Permission and Object Lifetime Handling for PTRACE_TRACEME
CVE-2019-13272HIGHsob ataquelocallinux17 jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NtUserSetWindowFNID Win32k User Callback Privilege Escalation (Metasploit)
CVE-2018-8453HIGHsob ataqueransomwarelocalwindows17 jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
Exploit-DBVexDay Proof
PHP Laravel Framework 5.5.40 / 5.6.x < 5.6.30 - token Unserialize Remote Command Execution (Metasploit)
CVE-2018-15133HIGHsob ataqueremotelinux16 jul 2019
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISCO
abrir
Exploit-DB
CentOS Control Web Panel 0.9.8.838 - User Enumeration
CVE-2019-13383webappslinux16 jul 2019
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a usern
28RISCO
abrir
Exploit-DBVexDay Proof
PHP Laravel Framework 5.5.40 / 5.6.x < 5.6.30 - token Unserialize Remote Command Execution (Metasploit)
CVE-2017-16894remotelinux16 jul 2019
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwo
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 < build 17763 - AppXSvc Hard Link Privilege Escalation (Metasploit)
CVE-2019-0841HIGHsob ataqueransomwarelocalwindows16 jul 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RISCO
abrir
Exploit-DB
CentOS Control Web Panel 0.9.8.836 - Privilege Escalation
CVE-2019-13359webappslinux16 jul 2019
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and uploa
28RISCO
abrir
Exploit-DB
CentOS Control Web Panel 0.9.8.836 - Authentication Bypass
CVE-2019-13360webappslinux16 jul 2019
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login pro
28RISCO
abrir
Exploit-DB
DameWare Remote Support 12.0.0.509 - 'Host' Buffer Overflow (SEH)
CVE-2018-12897localwindows16 jul 2019
SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.
23RISCO
abrir
anteriorpágina 63 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.