Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DB
PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Scripting
CVE-2018-20326webappscgi07 jan 2019
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage
23RISCO
abrir
Exploit-DB
MyBB OUGC Awards Plugin 1.8.3 - Persistent Cross-Site Scripting
CVE-2019-3501webappsphp07 jan 2019
The OUGC Awards plugin before 1.8.19 for MyBB allows XSS via a crafted award reason that is mishandled on the awards pag
23RISCO
abrir
Exploit-DB
Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal
CVE-2018-20525webappsphp07 jan 2019
Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
28RISCO
abrir
Exploit-DB
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (dbus Method)
CVE-2018-18955locallinux04 jan 2019
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISCO
abrir
Exploit-DB
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (polkit Method)
CVE-2018-18955locallinux04 jan 2019
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISCO
abrir
Exploit-DB
Frog CMS 0.9.5 - Cross-Site Scripting
CVE-2018-20448webappsphp02 jan 2019
Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI.
23RISCO
abrir
Exploit-DB
Ayukov NFTP FTP Client 2.0 - Buffer Overflow
CVE-2017-15222localwindows_x8602 jan 2019
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RISCO
abrir
Exploit-DBVexDay Proof
WebKit JSC - 'JSArray::shiftCountWithArrayStorage' Out-of-Bounds Read/Write
CVE-2018-4441dosmultiple02 jan 2019
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1,
28RISCO
abrir
Exploit-DBVexDay Proof
WebKit JSC - 'AbstractValue::set' Use-After-Free
CVE-2018-4443dosmultiple02 jan 2019
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1,
23RISCO
abrir
Exploit-DB
VMware Workstation/Player < 12.5.5 - Local Privilege Escalation
CVE-2017-4915localmultiple30 dez 2018
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration fil
38RISCO
abrir
Exploit-DB
Linux Kernel 4.8.0-34 < 4.8.0-45 (Ubuntu / Linux Mint) - Packet Socket Local Privilege Escalation
CVE-2017-7308locallinux29 dez 2018
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer
43RISCO
abrir
Exploit-DB
Linux Kernel 4.4.0-21 < 4.4.0-51 (Ubuntu 14.04/16.04 x64) - 'AF_PACKET' Race Condition Privilege Escalation
CVE-2016-8655localwindows_x86-6429 dez 2018
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RISCO
abrir
Exploit-DB
Linux Kernel < 4.4.0/ < 4.8.0 (Ubuntu 14.04/16.04 / Linux Mint 17/18 / Zorin) - Local Privilege Escalation (KASLR / SMEP)
CVE-2017-1000112locallinux29 dez 2018
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISCO
abrir
Exploit-DB
bludit Pages Editor 3.0.0 - Arbitrary File Upload
CVE-2018-1000811webappsphp27 dez 2018
bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages
35RISCO
abrir
Exploit-DB
Craft CMS 3.0.25 - Cross-Site Scripting
CVE-2018-20418webappsphp27 dez 2018
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
23RISCO
abrir
Exploit-DB
WSTMart 2.0.8 - Cross-Site Request Forgery (Add Admin)
CVE-2018-19138webappsphp24 dez 2018
WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI.
23RISCO
abrir
Exploit-DB
Adobe Flash ActiveX Plugin 28.0.0.137 - Remote Code Execution (PoC)
CVE-2018-15982HIGHsob ataqueransomwarelocalwindows24 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
Exploit-DBVexDay Proof
Netatalk 3.1.12 - Authentication Bypass
CVE-2018-1160CRITICALremotemultiple21 dez 2018
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RISCO
abrir
Exploit-DBVexDay Proof
Netatalk 3.1.12 - Authentication Bypass (PoC)
CVE-2018-1160CRITICALdosmultiple21 dez 2018
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RISCO
abrir
Exploit-DBVexDay Proof
VBScript - VbsErase Reference Leak Use-After-Free
CVE-2018-8625doswindows20 dez 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
35RISCO
abrir
Exploit-DBVexDay Proof
VBScript - MSXML Execution Policy Bypass
CVE-2018-8619doswindows20 dez 2018
A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly rest
35RISCO
abrir
Exploit-DB
Linux Kernel 4.4 - 'rtnetlink' Stack Memory Disclosure
CVE-2016-4486locallinux19 dez 2018
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain
23RISCO
abrir
Exploit-DB
Integria IMS 5.0.83 - Cross-Site Request Forgery
CVE-2018-19829webappsphp19 dez 2018
Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
IBM Operational Decision Manager 8.x - XML External Entity Injection
CVE-2018-1821HIGHwebappsmultiple19 dez 2018
IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) a
46RISCO
abrir
Exploit-DB
Yeswiki Cercopitheque - 'id' SQL Injection
CVE-2018-13045webappsphp19 dez 2018
SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to ex
23RISCO
abrir
Exploit-DB
Bolt CMS < 3.6.2 - Cross-Site Scripting
CVE-2018-19933webappsphp19 dez 2018
Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and Ne
23RISCO
abrir
Exploit-DB
Integria IMS 5.0.83 - 'search_string' Cross-Site Scripting
CVE-2018-19828webappsphp19 dez 2018
Artica Integria IMS 5.0.83 has XSS via the search_string parameter.
23RISCO
abrir
Exploit-DB
MiniShare 1.4.1 - 'HEAD/POST' Remote Buffer Overflow
CVE-2018-19861remotewindows18 dez 2018
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD re
28RISCO
abrir
Exploit-DB
MiniShare 1.4.1 - 'HEAD/POST' Remote Buffer Overflow
CVE-2018-19862remotewindows18 dez 2018
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST re
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'jscript!JsArrayFunctionHeapSort' Out-of-Bounds Write
CVE-2018-8631doswindows18 dez 2018
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet
35RISCO
abrir
anteriorpágina 78 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.