Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DBVexDay Proof
Microsoft Windows - 'FSCTL_FIND_FILES_BY_SID' Information Disclosure
CVE-2018-8411doswindows16 out 2018
An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vuln
23RISCO
abrir
Exploit-DBVexDay Proof
Solaris - RSH Stack Clash Privilege Escalation (Metasploit)
CVE-2017-1000364localsolaris16 out 2018
An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficie
38RISCO
abrir
Exploit-DB
Centos Web Panel 0.9.8.480 - Multiple Vulnerabilities
CVE-2018-18324webappsphp15 out 2018
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter
23RISCO
abrir
Exploit-DB
Centos Web Panel 0.9.8.480 - Multiple Vulnerabilities
CVE-2018-18323webappsphp15 out 2018
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/
60RISCO
abrir
Exploit-DB
Centos Web Panel 0.9.8.480 - Multiple Vulnerabilities
CVE-2018-18322webappsphp15 out 2018
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/ind
28RISCO
abrir
Exploit-DB
NoMachine < 5.3.27 - Remote Code Execution
CVE-2018-17980remotewindows15 out 2018
NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file lo
23RISCO
abrir
Exploit-DB
D-Link Routers - Directory Traversal
CVE-2018-10822webappshardware12 out 2018
Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L t
50RISCO
abrir
Exploit-DB
D-Link Routers - Plaintext Password
CVE-2018-10824webappshardware12 out 2018
An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.
28RISCO
abrir
Exploit-DB
D-Link Routers - Command Injection
CVE-2018-10823webappshardware12 out 2018
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02
60RISCO
abrir
Exploit-DB
Phoenix Contact WebVisit 2985725 - Authentication Bypass
CVE-2016-8371webappswindows12 out 2018
The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism i
28RISCO
abrir
Exploit-DB
SugarCRM 6.5.26 - Cross-Site Scripting
CVE-2018-17784webappsphp12 out 2018
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthentic
23RISCO
abrir
Exploit-DB
Phoenix Contact WebVisit 2985725 - Authentication Bypass
CVE-2016-8380webappswindows12 out 2018
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft SQL Server Management Studio 17.9 - '.xmla' XML External Entity Injection
CVE-2018-8532localwindows11 out 2018
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious
28RISCO
abrir
Exploit-DB
Phoenix Contact WebVisit 6.40.00 - Password Disclosure
CVE-2016-8366webappshardware11 out 2018
Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coinciden
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft SQL Server Management Studio 17.9 - '.xel' XML External Entity Injection
CVE-2018-8527localwindows11 out 2018
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft SQL Server Management Studio 17.9 - XML External Entity Injection
CVE-2018-8533localwindows11 out 2018
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious X
28RISCO
abrir
Exploit-DBVexDay Proof
jQuery-File-Upload 9.22.0 - Arbitrary File Upload
CVE-2018-9206webappsphp11 out 2018
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISCO
abrir
Exploit-DB
Ektron CMS 9.20 SP2 - Improper Access Restrictions
CVE-2018-12596webappsaspx10 out 2018
Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote at
28RISCO
abrir
Exploit-DB
MicroTik RouterOS < 6.43rc3 - Remote Root
CVE-2018-14847CRITICALsob ataqueremotehardware10 out 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
Exploit-DB
Seqrite End Point Security 7.4 - Privilege Escalation
CVE-2018-17775localwindows09 out 2018
Seqrite End Point Security v7.4 has "Everyone: (F)" permission for %PROGRAMFILES%\Seqrite\Seqrite, which allows local us
23RISCO
abrir
Exploit-DBVexDay Proof
ifwatchd - Privilege Escalation (Metasploit)
CVE-2014-2533locallinux09 out 2018
/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arb
38RISCO
abrir
Exploit-DBVexDay Proof
ghostscript - executeonly Bypass with errorhandler Setup
CVE-2018-17961locallinux09 out 2018
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'BailOutOnInvalidatedArrayHeadSegment' Check Bypass
CVE-2018-8466doswindows09 out 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Type Confusion
CVE-2018-8467doswindows09 out 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISCO
abrir
Exploit-DBVexDay Proof
Delta Electronics Delta Industrial Automation COMMGR 1.08 - Stack Buffer Overflow (Metasploit)
CVE-2018-10594remotewindows09 out 2018
Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPS
50RISCO
abrir
Exploit-DBVexDay Proof
Navigate CMS - (Unauthenticated) Remote Code Execution (Metasploit)
CVE-2018-17552remotephp08 out 2018
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigat
60RISCO
abrir
Exploit-DBVexDay Proof
Zahir Enterprise Plus 6 - Stack Buffer Overflow (Metasploit)
CVE-2018-17408localwindows08 out 2018
Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute a
43RISCO
abrir
Exploit-DBVexDay Proof
Navigate CMS - (Unauthenticated) Remote Code Execution (Metasploit)
CVE-2018-17553remotephp08 out 2018
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs N
60RISCO
abrir
Exploit-DB
net-snmp 5.7.3 - (Authenticated) Denial of Service (PoC)
CVE-2015-5621HIGHdoslinux08 out 2018
The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnm
53RISCO
abrir
Exploit-DBVexDay Proof
Android - sdcardfs Changes current->fs Without Proper Locking
CVE-2018-9515dosandroid08 out 2018
In sdcardfs_create and sdcardfs_mkdir of inode.c, there is a possible memory corruption due to improper locking. This co
23RISCO
abrir
anteriorpágina 84 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.