Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DB
Oracle Weblogic 10.3.6.0.0 / 12.1.3.0.0 - Remote Code Execution
CVE-2019-2725HIGHsob ataqueransomwarewebappswindows30 abr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
Exploit-DBVexDay Proof
AIS logistics ESEL-Server - Unauthenticated SQL Injection Remote Code Execution (Metasploit)
CVE-2019-10123remotewindows30 abr 2019
SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app)
50RISCO
abrir
Exploit-DB
Intelbras IWR 3000N 1.5.0 - Cross-Site Request Forgery
CVE-2019-11416webappshardware30 abr 2019
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstr
23RISCO
abrir
Exploit-DB
Spring Cloud Config 2.1.x - Path Traversal (Metasploit)
CVE-2019-3799webappsjava30 abr 2019
Directory Traversal with spring-cloud-config-server
60RISCO
abrir
Exploit-DB
HumHub 1.3.12 - Cross-Site Scripting
CVE-2019-11564webappsphp30 abr 2019
A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HT
23RISCO
abrir
Exploit-DBVexDay Proof
systemd - DynamicUser can Create setuid Binaries when Assisted by Another Process
CVE-2019-3844MEDIUMdoslinux26 abr 2019
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of
33RISCO
abrir
Exploit-DBVexDay Proof
systemd - DynamicUser can Create setuid Binaries when Assisted by Another Process
CVE-2019-3843MEDIUMdoslinux26 abr 2019
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allo
33RISCO
abrir
Exploit-DB
Apache Pluto 3.0.0 / 3.0.1 - Persistent Cross-Site Scripting
CVE-2019-0186webappsjava26 abr 2019
The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XS
28RISCO
abrir
Exploit-DBVexDay Proof
RARLAB WinRAR 5.61 - ACE Format Input Validation Remote Code Execution (Metasploit)
CVE-2018-20250HIGHsob ataqueransomwarelocalwindows25 abr 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
Exploit-DB
JioFi 4G M2S 1.0.2 - Denial of Service
CVE-2019-7439doshardware25 abr 2019
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter.
23RISCO
abrir
Exploit-DB
JioFi 4G M2S 1.0.2 - 'mask' Cross-Site Scripting
CVE-2019-7438webappshardware25 abr 2019
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
VirtualBox 6.0.4 r128413 - COM RPC Interface Code Injection Host Privilege Escalation
CVE-2019-2721localwindows24 abr 2019
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISCO
abrir
Exploit-DBVexDay Proof
systemd - Lack of Seat Verification in PAM Module Permits Spoofing Active Session to polkit
CVE-2019-3842MEDIUMdoslinux23 abr 2019
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using t
33RISCO
abrir
Exploit-DB
UliCMS 2019.2 / 2019.1 - Multiple Cross-Site Scripting
CVE-2019-11398webappsphp22 abr 2019
Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitra
23RISCO
abrir
Exploit-DB
Msvod 10 - Cross-Site Request Forgery (Change User Information)
CVE-2019-11375webappsphp22 abr 2019
Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.
23RISCO
abrir
Exploit-DB
74CMS 5.0.1 - Cross-Site Request Forgery (Add New Admin User)
CVE-2019-11374webappsphp22 abr 2019
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
23RISCO
abrir
Exploit-DB
QNAP myQNAPcloud Connect 1.3.4.0317 - 'Username/Password' Denial of Service
CVE-2019-7181doshardware22 abr 2019
Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the pr
23RISCO
abrir
Exploit-DBVexDay Proof
SystemTap 1.3 - MODPROBE_OPTIONS Privilege Escalation (Metasploit)
CVE-2010-4170locallinux19 abr 2019
The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allow
38RISCO
abrir
Exploit-DBVexDay Proof
Atlassian Confluence Widget Connector Macro - Velocity Template Injection (Metasploit)
CVE-2019-3396CRITICALsob ataqueransomwareremotemultiple19 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
Exploit-DBVexDay Proof
Oracle Business Intelligence 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - Directory Traversal
CVE-2019-2588webappswindows19 abr 2019
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publi
50RISCO
abrir
Exploit-DBVexDay Proof
Oracle Business Intelligence / XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - XML External Entity Injection
CVE-2019-2616HIGHsob ataquewebappswindows19 abr 2019
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publi
100RISCO
abrir
Exploit-DBVexDay Proof
LibreOffice < 6.0.7 / 6.1.3 - Macro Code Execution (Metasploit)
CVE-2018-16858HIGHlocalmultiple18 abr 2019
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RISCO
abrir
Exploit-DB
Netwide Assembler (NASM) 2.14rc15 - NULL Pointer Dereference (PoC)
CVE-2018-16517dosmultiple18 abr 2019
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a deni
23RISCO
abrir
Exploit-DB
Evernote 7.9 - Code Execution via Path Traversal
CVE-2019-10038localmacos18 abr 2019
Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle Java Runtime Environment - Heap Corruption During TTF font Rendering in sc_FindExtrema4
CVE-2019-2697dosmultiple17 abr 2019
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Ja
28RISCO
abrir
Exploit-DB
ASUS HG100 - Denial of Service
CVE-2018-11492doshardware17 abr 2019
ASUS HG100 devices allow denial of service via an IPv4 packet flood.
28RISCO
abrir
Exploit-DBVexDay Proof
Oracle Java Runtime Environment - Heap Corruption During TTF font Rendering in GlyphIterator::setCurrGlyphID
CVE-2019-2698dosmultiple17 abr 2019
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Ja
28RISCO
abrir
Exploit-DB
Zoho ManageEngine ADManager Plus 6.6 (Build < 6659) - Privilege Escalation
CVE-2018-19374localwindows16 abr 2019
Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Troj
23RISCO
abrir
Exploit-DB
Zyxel ZyWall 310 / ZyWall 110 / USG1900 / ATP500 / USG40 - Login Page Cross-Site Scripting
CVE-2019-9955webappshardware16 abr 2019
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, U
43RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1809 - LUAFV Delayed Virtualization Cache Manager Poisoning Privilege Escalation
CVE-2019-0805localwindows16 abr 2019
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RISCO
abrir
anteriorpágina 69 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.