Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
Cloudme 1.9 - Buffer Overflow (DEP) (Metasploit)
CVE-2018-689214 ago 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RISCO
abrir
Exploit-DB
Oracle GlassFish Server Open Source Edition 4.1 - Path Traversal (Metasploit)
CVE-2017-100002814 ago 2018
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RISCO
abrir
Exploit-DB
Oracle Glassfish OSE 4.1 - Path Traversal (Metasploit)
CVE-2017-100002814 ago 2018
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RISCO
abrir
Exploit-DB
Oracle Weblogic Server - Deserialization Remote Code Execution (Metasploit)
CVE-2018-2628CRITICALsob ataque13 ago 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
Exploit-DB
IBM Sterling B2B Integrator 5.2.0.1/5.2.6.3 - Cross-Site Scripting
CVE-2018-1563MEDIUM13 ago 2018
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site
33RISCO
abrir
Exploit-DB
IBM Sterling B2B Integrator 5.2.0.1/5.2.6.3 - Cross-Site Scripting
CVE-2018-1513MEDIUM13 ago 2018
IBM Sterling B2B Integrator Standard Edition 5.2.0 through 5.2.6 is vulnerable to cross-site scripting. This vulnerabili
33RISCO
abrir
Exploit-DB
MyBB Thank You/Like Plugin 3.0.0 - Cross-Site Scripting
CVE-2018-1488810 ago 2018
inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or threa
23RISCO
abrir
Exploit-DB
Zimbra 8.6.0_GA_1153 - Cross-Site Scripting
CVE-2016-341110 ago 2018
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to inject arbitrar
23RISCO
abrir
Exploit-DB
reSIProcate 1.10.2 - Heap Overflow
CVE-2018-1258409 ago 2018
The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows rem
28RISCO
abrir
Exploit-DB
Linux Kernel 4.14.7 (Ubuntu 16.04 / CentOS 7) - (KASLR & SMEP Bypass) Arbitrary File Read
CVE-2017-1834409 ago 2018
The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly
23RISCO
abrir
Exploit-DB
osTicket 1.10.1 - Arbitrary File Upload
CVE-2017-1558008 ago 2018
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly v
28RISCO
abrir
Exploit-DB
Subrion CMS 4.2.1 - Cross-Site Scripting
CVE-2018-1484006 ago 2018
uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for exam
23RISCO
abrir
Exploit-DB
Sitecore.Net 8.1 - Directory Traversal
CVE-2018-766906 ago 2018
An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application
28RISCO
abrir
Exploit-DB
Open-AudIT Community 2.2.6 - Cross-Site Scripting
CVE-2018-1449306 ago 2018
Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inj
35RISCO
abrir
Exploit-DB
LAMS < 3.1 - Cross-Site Scripting
CVE-2018-1209006 ago 2018
There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introd
23RISCO
abrir
Exploit-DB
Fortinet FortiClient 5.2.3 (Windows 10 x64 Creators) - Local Privilege Escalation
CVE-2015-573605 ago 2018
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel
23RISCO
abrir
Exploit-DB
Fortinet FortiClient 5.2.3 (Windows 10 x64 Creators) - Local Privilege Escalation
CVE-2015-407705 ago 2018
The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient b
23RISCO
abrir
Exploit-DB
PHP Template Store Script 3.0.6 - Cross-Site Scripting
CVE-2018-1486903 ago 2018
PHP Template Store Script 3.0.6 allows XSS via the Address line 1, Address Line 2, Bank name, or A/C Holder name field i
23RISCO
abrir
Exploit-DB
Linux Kernel - UDP Fragmentation Offset 'UFO' Privilege Escalation (Metasploit)
CVE-2017-100011203 ago 2018
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISCO
abrir
Exploit-DB
Vuze Bittorrent Client 5.7.6.0 - SSDP Processing XML External Entity Injection
CVE-2018-1341703 ago 2018
In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External E
28RISCO
abrir
Exploit-DB
Plex Media Server 1.13.2.5154 - SSDP Processing XML External Entity Injection
CVE-2018-1341503 ago 2018
In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External En
35RISCO
abrir
Exploit-DB
WityCMS 0.6.2 - Cross-Site Request Forgery (Password Change)
CVE-2018-1402902 ago 2018
CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as dem
23RISCO
abrir
Exploit-DB
Sun Solaris 11.3 AVS Kernel - Local Privilege Escalation
CVE-2018-289202 ago 2018
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Availability Suite Service).
23RISCO
abrir
Exploit-DB
Universal Media Server 7.1.0 - SSDP Processing XML External Entity Injection
CVE-2018-1341602 ago 2018
In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML Extern
28RISCO
abrir
Exploit-DB
Seq 4.2.476 - Authentication Bypass
CVE-2018-809602 ago 2018
Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name
35RISCO
abrir
Exploit-DB
Craft CMS SEOmatic plugin 3.1.4 - Server-Side Template Injection
CVE-2018-1471631 jul 2018
A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because reques
35RISCO
abrir
Exploit-DB
Responsive Filemanager 9.13.1 - Server-Side Request Forgery
CVE-2018-1472830 jul 2018
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
60RISCO
abrir
Exploit-DB
fusermount - user_allow_other Restriction Bypass and SELinux Label Control
CVE-2018-10906MEDIUM30 jul 2018
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is act
33RISCO
abrir
Exploit-DB
H2 Database 1.4.197 - Information Disclosure
CVE-2018-14335MEDIUM30 jul 2018
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read
38RISCO
abrir
Exploit-DB
SoftNAS Cloud < 4.0.3 - OS Command Injection
CVE-2018-1441727 jul 2018
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particul
45RISCO
abrir
anteriorpágina 85 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.