Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DBVexDay Proof
Linux - BPF Sign Extension Local Privilege Escalation (Metasploit)
CVE-2017-16995locallinux19 jul 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
Exploit-DB
MyBB New Threads Plugin 1.1 - Cross-Site Scripting
CVE-2018-14392webappsphp19 jul 2018
The New Threads plugin before 1.2 for MyBB has XSS.
35RISCO
abrir
Exploit-DB
Open-AudIT Community 2.1.1 - Cross-Site Scripting
CVE-2018-11124webappsmultiple18 jul 2018
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows
23RISCO
abrir
Exploit-DBVexDay Proof
Nanopool Claymore Dual Miner - APIs Remote Code Execution (Metasploit)
CVE-2018-1000049remotemultiple17 jul 2018
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
60RISCO
abrir
Exploit-DBVexDay Proof
QNAP Q'Center - 'change_passwd' Command Execution (Metasploit)
CVE-2018-0706remotelinux17 jul 2018
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate
50RISCO
abrir
Exploit-DBVexDay Proof
QNAP Q'Center - 'change_passwd' Command Execution (Metasploit)
CVE-2018-0707remotelinux17 jul 2018
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
50RISCO
abrir
Exploit-DB
PrestaShop < 1.6.1.19 - 'AES CBC' Privilege Escalation
CVE-2018-13784webappsphp16 jul 2018
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RISCO
abrir
Exploit-DBVexDay Proof
Linux (Ubuntu) - Other Users coredumps Can Be Read via setgid Directory and killpriv Bypass
CVE-2018-13405doslinux16 jul 2018
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an
23RISCO
abrir
Exploit-DB
PrestaShop < 1.6.1.19 - 'BlowFish ECD' Privilege Escalation
CVE-2018-13784webappsphp16 jul 2018
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RISCO
abrir
Exploit-DBVexDay Proof
Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injection
CVE-2018-12463HIGHwebappsjava16 jul 2018
MFSBGN03811 rev.1 - Fortify Software Security Center (SSC), Multiple vulnerabilities
46RISCO
abrir
Exploit-DB
VelotiSmart WiFi B-380 Camera - Directory Traversal
CVE-2018-14064webappshardware16 jul 2018
The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../..
50RISCO
abrir
Exploit-DBVexDay Proof
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-12980webappsphp13 jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit
35RISCO
abrir
Exploit-DBVexDay Proof
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-12979webappsphp13 jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions
23RISCO
abrir
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0707webappshardware13 jul 2018
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
50RISCO
abrir
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0706webappshardware13 jul 2018
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - POP/MOV SS Local Privilege Elevation (Metasploit)
CVE-2018-8897localwindows13 jul 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RISCO
abrir
Exploit-DB
Grundig Smart Inter@ctive 3.0 - Cross-Site Request Forgery
CVE-2018-13989webappshardware13 jul 2018
Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable
23RISCO
abrir
Exploit-DB
G DATA Total Security 25.4.0.3 - Activex Buffer Overflow
CVE-2018-10018doswindows13 jul 2018
The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a lo
23RISCO
abrir
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0709webappshardware13 jul 2018
Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow auth
28RISCO
abrir
Exploit-DB
Cela Link CLR-M20 2.7.1.6 - Arbitrary File Upload
CVE-2018-15137webappshardware13 jul 2018
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml)
28RISCO
abrir
Exploit-DB
Zeta Producer Desktop CMS 14.2.0 - Remote Code Execution / Local File Disclosure
CVE-2018-13980webappsphp13 jul 2018
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclos
38RISCO
abrir
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0708webappshardware13 jul 2018
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo
28RISCO
abrir
Exploit-DB
Zeta Producer Desktop CMS 14.2.0 - Remote Code Execution / Local File Disclosure
CVE-2018-13981webappsphp13 jul 2018
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code
28RISCO
abrir
Exploit-DBVexDay Proof
phpMyAdmin - (Authenticated) Remote Code Execution (Metasploit)
CVE-2018-12613remotephp13 jul 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir
Exploit-DBVexDay Proof
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-12981webappsphp13 jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit
23RISCO
abrir
Exploit-DBVexDay Proof
Apache CouchDB - Arbitrary Command Execution (Metasploit)
CVE-2017-12636remotelinux13 jul 2018
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISCO
abrir
Exploit-DBVexDay Proof
Apache CouchDB - Arbitrary Command Execution (Metasploit)
CVE-2017-12635remotelinux13 jul 2018
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISCO
abrir
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0710webappshardware13 jul 2018
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - BoundFunction::NewInstance Out-of-Bounds Read
CVE-2018-8139doswindows12 jul 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Out-of-Bounds Reads/Writes
CVE-2018-8145doswindows12 jul 2018
An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could
35RISCO
abrir
anteriorpágina 92 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.