Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DBVexDay Proof
HongCMS 3.0.0 - (Authenticated) SQL Injection
CVE-2018-12912webappsphp28 jun 2018
An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via a
23RISCO
abrir
Exploit-DBVexDay Proof
Quest KACE Systems Management - Command Injection (Metasploit)
CVE-2018-11138CRITICALsob ataqueransomwareremoteunix27 jun 2018
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by
100RISCO
abrir
Exploit-DB
PoDoFo 0.9.5 - Buffer Overflow (PoC)
CVE-2018-8002doslinux26 jun 2018
In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.
23RISCO
abrir
Exploit-DB
WordPress Plugin iThemes Security < 7.0.3 - SQL Injection
CVE-2018-12636webappsphp25 jun 2018
The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admi
28RISCO
abrir
Exploit-DB
WordPress Plugin Advanced Order Export For WooCommerce < 1.5.4 - CSV Injection
CVE-2018-11525webappsphp25 jun 2018
The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.
23RISCO
abrir
Exploit-DB
DIGISOL DG-BR4000NG - Cross-Site Scripting
CVE-2018-12705webappshardware25 jun 2018
DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).
23RISCO
abrir
Exploit-DBVexDay Proof
KVM (Nested Virtualization) - L1 Guest Privilege Escalation
CVE-2018-12904doslinux25 jun 2018
In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause
23RISCO
abrir
Exploit-DBVexDay Proof
Foxit Reader 9.0.1.1049 - Remote Code Execution
CVE-2018-9948remotewindows25 jun 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RISCO
abrir
Exploit-DB
Ecessa ShieldLink SL175EHQ < 10.7.4 - Cross-Site Request Forgery (Add Superuser)
CVE-2018-13032webappshardware25 jun 2018
ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogi
23RISCO
abrir
Exploit-DB
DIGISOL DG-BR4000NG - Buffer Overflow (PoC)
CVE-2018-12706doshardware25 jun 2018
DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.
23RISCO
abrir
Exploit-DBVexDay Proof
Foxit Reader 9.0.1.1049 - Remote Code Execution
CVE-2018-9958remotewindows25 jun 2018
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RISCO
abrir
Exploit-DB
WordPress Plugin Comments Import & Export < 2.0.4 - CSV Injection
CVE-2018-11526webappsphp25 jun 2018
The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
23RISCO
abrir
Exploit-DB
GreenCMS 2.3.0603 - Information Disclosure
CVE-2018-12604webappsphp22 jun 2018
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_d
28RISCO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (2)
CVE-2018-12613webappsphp22 jun 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir
Exploit-DB
QEMU Guest Agent 2.12.50 - Denial of Service
CVE-2018-12617doslinux22 jun 2018
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 h
28RISCO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (1)
CVE-2018-12613webappsphp21 jun 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir
Exploit-DB
LFCMS 3.7.0 - Cross-Site Request Forgery (Add User)
CVE-2018-12602webappsphp21 jun 2018
A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.
23RISCO
abrir
Exploit-DB
LFCMS 3.7.0 - Cross-Site Request Forgery (Add Admin)
CVE-2018-12603webappsphp21 jun 2018
Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authen
23RISCO
abrir
Exploit-DB
Dell EMC RecoverPoint < 5.1.2 - Local Root Command Execution
CVE-2018-1235locallinux21 jun 2018
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command inje
35RISCO
abrir
Exploit-DBVexDay Proof
Apache CouchDB < 2.1.0 - Remote Code Execution
CVE-2017-12636webappslinux20 jun 2018
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISCO
abrir
Exploit-DB
MaDDash 2.0.2 - Directory Listing
CVE-2018-12524webappsjava20 jun 2018
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provi
23RISCO
abrir
Exploit-DB
MaDDash 2.0.2 - Directory Listing
CVE-2018-12523webappsjava20 jun 2018
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provi
23RISCO
abrir
Exploit-DB
MaDDash 2.0.2 - Directory Listing
CVE-2018-12525webappsjava20 jun 2018
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ pr
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - Desktop Bridge Virtual Registry CVE-2018-0880 Incomplete Fix Privilege Escalation
CVE-2018-8214doswindows20 jun 2018
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - Desktop Bridge Activation Arbitrary Directory Creation Privilege Escalation
CVE-2018-8208doswindows20 jun 2018
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RISCO
abrir
Exploit-DB
IPConfigure Orchid VMS 2.0.5 - Directory Traversal / Information Disclosure (Metasploit)
CVE-2018-10956webappsmultiple20 jun 2018
IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.
50RISCO
abrir
Exploit-DB
MaDDash 2.0.2 - Directory Listing
CVE-2018-12522webappsjava20 jun 2018
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ pro
23RISCO
abrir
Exploit-DB
ntp 4.2.8p11 - Local Buffer Overflow (PoC)
CVE-2018-12327doslinux20 jun 2018
Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or es
28RISCO
abrir
Exploit-DB
Redis 5.0 - Denial of Service
CVE-2018-12453doslinux20 jun 2018
Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers t
28RISCO
abrir
Exploit-DB
Pale Moon Browser < 27.9.3 - Use After Free (PoC)
CVE-2018-12292localwindows18 jun 2018
A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.
23RISCO
abrir
anteriorpágina 94 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.