Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
FTPShell Client 6.7 - Buffer Overflow
CVE-2018-757308 mai 2018
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with t
50RISCO
abrir
Exploit-DB
PlaySMS - 'import.php' (Authenticated) CSV File Upload Code Execution (Metasploit)
CVE-2017-910108 mai 2018
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RISCO
abrir
Exploit-DB
2345 Security Guard 3.7 - '2345NetFirewall.sys' Denial of Service
CVE-2018-1080908 mai 2018
In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD)
23RISCO
abrir
Exploit-DB
Palo Alto Networks - 'readSessionVarsFromFile()' Session Corruption (Metasploit)
CVE-2017-15944CRITICALsob ataque08 mai 2018
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISCO
abrir
Exploit-DB
GNU wget - Cookie Injection
CVE-2018-049406 mai 2018
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequen
28RISCO
abrir
Exploit-DB
CSP MySQL User Manager 2.3.1 - Authentication Bypass
CVE-2018-1075706 mai 2018
CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a
23RISCO
abrir
Exploit-DB
DeviceLock Plug and Play Auditor 5.72 - Unicode Buffer Overflow (SEH)
CVE-2018-1065506 mai 2018
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
28RISCO
abrir
Exploit-DB
IceWarp Mail Server < 11.1.1 - Directory Traversal
CVE-2015-150304 mai 2018
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary
50RISCO
abrir
Exploit-DB
WordPress Plugin WF Cookie Consent 1.1.3 - Cross-Site Scripting
CVE-2018-1037104 mai 2018
An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scriptin
23RISCO
abrir
Exploit-DB
Google Chrome V8 - Object Allocation Size Integer Overflow
CVE-2018-6065HIGHsob ataque04 mai 2018
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RISCO
abrir
Exploit-DB
Microsoft Windows WMI - Recieve Notification Exploit (Metasploit)
CVE-2016-0040HIGHsob ataque04 mai 2018
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RISCO
abrir
Exploit-DB
GPON Routers - Authentication Bypass / Command Injection
CVE-2018-10562CRITICALsob ataqueransomware03 mai 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RISCO
abrir
Exploit-DB
GPON Routers - Authentication Bypass / Command Injection
CVE-2018-10561CRITICALsob ataque03 mai 2018
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images
100RISCO
abrir
Exploit-DB
JasperReports - (Authenticated) File Read
CVE-2018-5430HIGHsob ataque03 mai 2018
TIBCO JasperReports Server Information Disclosure Vulnerability
83RISCO
abrir
Exploit-DB
Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery
CVE-2018-930202 mai 2018
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to r
23RISCO
abrir
Exploit-DB
Exim < 4.90.1 - 'base64d' Remote Code Execution
CVE-2018-6789CRITICALsob ataqueransomware02 mai 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir
Exploit-DB
LibreOffice/Open Office - '.odt' Information Disclosure
CVE-2018-1058302 mai 2018
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
60RISCO
abrir
Exploit-DB
TBK DVR4104 / DVR4216 - Credentials Leak
CVE-2018-999502 mai 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
Exploit-DB
Norton Core Secure WiFi Router - 'BLE' Command Injection (PoC)
CVE-2018-523402 mai 2018
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic
28RISCO
abrir
Exploit-DB
WebKit - 'WebCore::jsElementScrollHeightGetter' Use-After-Free
CVE-2018-420002 mai 2018
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud
23RISCO
abrir
Exploit-DB
WordPress Plugin Responsive Cookie Consent 1.7 / 1.6 / 1.5 - (Authenticated) Persistent Cross-Site Scripting
CVE-2018-1030901 mai 2018
The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS.
23RISCO
abrir
Exploit-DB
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-873330 abr 2018
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an
43RISCO
abrir
Exploit-DB
Apple macOS/iOS - ReportCrash mach port Replacement due to Failure to Respect MIG Ownership Rules
CVE-2018-420630 abr 2018
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2
23RISCO
abrir
Exploit-DB
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-873530 abr 2018
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut
50RISCO
abrir
Exploit-DB
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-873630 abr 2018
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC
50RISCO
abrir
Exploit-DB
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit)
CVE-2018-7602CRITICALsob ataqueransomware30 abr 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISCO
abrir
Exploit-DB
WordPress Plugin Form Maker 1.12.20 - CSV Injection
CVE-2018-1050430 abr 2018
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
23RISCO
abrir
Exploit-DB
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-873430 abr 2018
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RISCO
abrir
Exploit-DB
Apple macOS 10.13.2 - Double mach_port_deallocate in kextd due to Failure to Comply with MIG Ownership Rules
CVE-2018-413930 abr 2018
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools"
23RISCO
abrir
Exploit-DB
SickRage < v2018.03.09 - Clear-Text Credentials HTTP Response
CVE-2018-916026 abr 2018
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RISCO
abrir
anteriorpágina 94 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.