Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
Werewolf Online 0.8.8 - Information Disclosure
CVE-2018-1150527 mai 2018
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat outp
23RISCO
abrir
Exploit-DB
Bitmain Antminer D3/L3+/S9 - Remote Command Execution
CVE-2018-1122027 mai 2018
Bitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution via the system restore function.
28RISCO
abrir
Exploit-DB
ClipperCMS 1.3.3 - Cross-Site Scripting
CVE-2018-1133227 mai 2018
Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in
23RISCO
abrir
Exploit-DB
EasyService Billing 1.0 - 'q' SQL Injection
CVE-2018-1144426 mai 2018
A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0.
23RISCO
abrir
Exploit-DB
EasyService Billing 1.0 - Cross-Site Scripting
CVE-2018-1144326 mai 2018
The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.
23RISCO
abrir
Exploit-DB
EasyService Billing 1.0 - Cross-Site Request Forgery
CVE-2018-1144526 mai 2018
A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing
23RISCO
abrir
Exploit-DB
EasyService Billing 1.0 - Cross-Site Request Forgery
CVE-2018-1144226 mai 2018
A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= U
23RISCO
abrir
Exploit-DB
Oracle WebCenter FatWire Content Server < 7 - Improper Access Control
CVE-2017-1003325 mai 2018
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Support Tools). Support
23RISCO
abrir
Exploit-DB
Skia and Firefox - Integer Overflow in SkTDArray Leading to Out-of-Bounds Write
CVE-2018-515925 mai 2018
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks,
28RISCO
abrir
Exploit-DB
SAP Internet Transaction Server 6200.x - Session Fixation / Cross-Site Scripting
CVE-2018-1141525 mai 2018
SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: th
23RISCO
abrir
Exploit-DB
Oracle WebCenter Sites 11.1.1.8.0/12.2.1.x - Cross-Site Scripting
CVE-2018-279125 mai 2018
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported
50RISCO
abrir
Exploit-DB
Microsoft Edge Chakra - Cross Context Use-After-Free
CVE-2018-094625 mai 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RISCO
abrir
Exploit-DB
Honeywell XL Web Controller - Cross-Site Scripting
CVE-2014-311024 mai 2018
Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earli
23RISCO
abrir
Exploit-DB
Samsung Galaxy S7 Edge - Overflow in OMACP WbXml String Extension Processing
CVE-2018-1075123 mai 2018
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Ex
23RISCO
abrir
Exploit-DB
Siemens SCALANCE S613 - Remote Denial of Service
CVE-2016-396323 mai 2018
Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 4
23RISCO
abrir
Exploit-DB
Siemens SIMATIC S7-1500 CPU - Remote Denial of Service
CVE-2014-507422 mai 2018
Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device
23RISCO
abrir
Exploit-DB
Siemens SIMATIC S7-1200 CPU - Cross-Site Scripting
CVE-2014-290822 mai 2018
Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x
43RISCO
abrir
Exploit-DB
MakeMyTrip 7.2.4 - Information Disclosure
CVE-2018-1124222 mai 2018
An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypte
23RISCO
abrir
Exploit-DB
Microsoft Windows - 'POP/MOV SS' Privilege Escalation
CVE-2018-889722 mai 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RISCO
abrir
Exploit-DB
ERPnext 11 - Cross-Site Scripting
CVE-2018-1133922 mai 2018
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
23RISCO
abrir
Exploit-DB
AMD / ARM / Intel - Speculative Execution Variant 4 Speculative Store Bypass
CVE-2018-3639MEDIUM22 mai 2018
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RISCO
abrir
Exploit-DB
Linux 4.4.0 < 4.4.0-53 - 'AF_PACKET chocobo_root' Local Privilege Escalation (Metasploit)
CVE-2016-865522 mai 2018
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RISCO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - Magic Value Type Confusion
CVE-2018-095322 mai 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RISCO
abrir
Exploit-DB
Microsoft Internet Explorer 11 (Windows 7 x86/x64) - vbscript Code Execution
CVE-2018-8174HIGHsob ataqueransomware21 mai 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
Exploit-DB
Linux 2.6.30 < 2.6.36-rc8 - Reliable Datagram Sockets (RDS) Privilege Escalation (Metasploit)
CVE-2010-3904HIGHsob ataque21 mai 2018
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RISCO
abrir
Exploit-DB
Schneider Electric PLCs - Cross-Site Request Forgery
CVE-2013-066321 mai 2018
Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10
23RISCO
abrir
Exploit-DB
ManageEngine Recovery Manager Plus 5.3 - Cross-Site Scripting
CVE-2018-916321 mai 2018
A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) all
23RISCO
abrir
Exploit-DB
D-Link DSL-3782 - Authentication Bypass
CVE-2018-889820 mai 2018
A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B0
28RISCO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - Bound Check Elimination Bug
CVE-2018-098018 mai 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISCO
abrir
Exploit-DB
DynoRoot DHCP Client - Command Injection
CVE-2018-1111HIGH18 mai 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISCO
abrir
anteriorpágina 92 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.