Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.858exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DB
SAP Crystal Reports - Information Disclosure
CVE-2019-0285webappsmultiple01 jul 2019
The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive databas
23RISCO
abrir
Exploit-DBVexDay Proof
LibreNMS 1.46 - 'addhost' Remote Code Execution
CVE-2018-20434webappsphp28 jun 2019
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to htm
60RISCO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.5.6 - Magpie_debug.php Root Remote Code Execution (Metasploit)
CVE-2018-15710remotelinux26 jun 2019
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
50RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Spidermonkey - IonMonkey 'Array.prototype.pop' Type Confusion
CVE-2019-11707HIGHsob ataquedosmultiple26 jun 2019
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RISCO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.5.6 - Magpie_debug.php Root Remote Code Execution (Metasploit)
CVE-2018-15708remotelinux26 jun 2019
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RISCO
abrir
Exploit-DB
SeedDMS < 5.1.11 - 'out.UsrMgr.php' Cross-Site Scripting
CVE-2019-12745webappsphp24 jun 2019
out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field.
23RISCO
abrir
Exploit-DB
SeedDMS < 5.1.11 - 'out.GroupMgr.php' Cross-Site Scripting
CVE-2019-12801webappsphp24 jun 2019
out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Nam
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Font Cache Service - Insecure Sections Privilege Escalation
CVE-2019-0943doswindows24 jun 2019
Windows ALPC Elevation of Privilege Vulnerability
23RISCO
abrir
Exploit-DB
dotProject 2.1.9 - SQL Injection
CVE-2019-11354webappsphp24 jun 2019
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Ori
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'CmpAddRemoveContainerToCLFSLog' Arbitrary File/Directory Creation
CVE-2019-0959HIGHdoswindows24 jun 2019
Windows Common Log File System Driver Elevation of Privilege Vulnerability
41RISCO
abrir
Exploit-DB
SeedDMS versions < 5.1.11 - Remote Command Execution
CVE-2019-12744webappsphp24 jun 2019
SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a differe
28RISCO
abrir
Exploit-DB
GrandNode 4.40 - Path Traversal / Arbitrary File Download
CVE-2019-12276webappsmultiple24 jun 2019
A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows
50RISCO
abrir
Exploit-DB
EA Origin < 10.5.38 - Remote Code Execution
CVE-2019-12828remotewindows21 jun 2019
An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and orig
28RISCO
abrir
Exploit-DBVexDay Proof
Cisco Prime Infrastructure Health Monitor - TarArchive Directory Traversal (Metasploit)
CVE-2019-1821HIGHremotelinux20 jun 2019
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
78RISCO
abrir
Exploit-DBVexDay Proof
Serv-U FTP Server < 15.1.7 - Local Privilege Escalation (1)
CVE-2019-12181locallinux18 jun 2019
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RISCO
abrir
Exploit-DB
Sahi pro 7.x/8.x - Directory Traversal
CVE-2018-20470webappsmultiple18 jun 2019
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerab
50RISCO
abrir
Exploit-DB
Sahi pro 8.x - Cross-Site Scripting
CVE-2018-20472webappsmultiple18 jun 2019
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS.
23RISCO
abrir
Exploit-DB
Sahi pro 8.x - SQL Injection
CVE-2018-20469webappsmultiple18 jun 2019
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to
28RISCO
abrir
Exploit-DB
Thunderbird ESR < 60.7.XXX - Type Confusion
CVE-2019-11706dosmultiple17 jun 2019
A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when pro
23RISCO
abrir
Exploit-DB
Thunderbird ESR < 60.7.XXX - 'parser_get_next_char' Heap-Based Buffer Overflow
CVE-2019-11703dosmultiple17 jun 2019
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing cer
28RISCO
abrir
Exploit-DB
Thunderbird ESR < 60.7.XXX - 'icalmemorystrdupanddequote' Heap-Based Buffer Overflow
CVE-2019-11704dosmultiple17 jun 2019
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when proce
28RISCO
abrir
Exploit-DB
Thunderbird ESR < 60.7.XXX - 'icalrecur_add_bydayrules' Stack-Based Buffer Overflow
CVE-2019-11705dosmultiple17 jun 2019
A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processin
23RISCO
abrir
Exploit-DBVexDay Proof
Exim 4.87 - 4.91 - Local Privilege Escalation
CVE-2019-10149CRITICALsob ataquelocallinux17 jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir
Exploit-DB
HC10 HC.Server Service 10.14 - Remote Invalid Pointer Write
CVE-2019-12323doswindows17 jun 2019
The HC.Server service in Hosting Controller HC10 10.14 allows an Invalid Pointer Write DoS.
23RISCO
abrir
Exploit-DB
Spring Security OAuth - Open Redirector
CVE-2019-11269MEDIUMwebappsjava17 jun 2019
Open Redirector in spring-security-oauth2
33RISCO
abrir
Exploit-DB
Spring Security OAuth - Open Redirector
CVE-2019-3778webappsjava17 jun 2019
Open Redirect in spring-security-oauth2
28RISCO
abrir
Exploit-DB
Sitecore 8.x - Deserialization Remote Code Execution
CVE-2019-11080webappsaspx13 jun 2019
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 2
28RISCO
abrir
Exploit-DB
Pronestor Health Monitoring < 8.1.11.0 - Privilege Escalation
CVE-2018-19113localwindows13 jun 2019
The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)
23RISCO
abrir
Exploit-DB
Liferay Portal 7.1 CE GA=3 / SimpleCaptcha API - Cross-Site Scripting
CVE-2019-6588webappsjsp11 jun 2019
In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsani
23RISCO
abrir
Exploit-DB
ProShow 9.0.3797 - Local Privilege Escalation
CVE-2019-12788localwindows11 jun 2019
An issue was discovered in Photodex ProShow Producer v9.0.3797 (an application that runs with Administrator privileges).
23RISCO
abrir
anteriorpágina 65 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.