Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
October CMS User Plugin 1.4.5 - Persistent Cross-Site Scripting
CVE-2018-1036626 abr 2018
An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the nam
23RISCO
abrir
Exploit-DB
Jfrog Artifactory < 4.16 - Arbitrary File Upload / Remote Command Execution
CVE-2016-1003626 abr 2018
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to
28RISCO
abrir
Exploit-DB
Frog CMS 0.9.5 - Persistent Cross-Site Scripting
CVE-2018-1032126 abr 2018
Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.
23RISCO
abrir
Exploit-DB
SickRage < v2018.03.09 - Clear-Text Credentials HTTP Response
CVE-2018-916026 abr 2018
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RISCO
abrir
Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - CSV Injection
CVE-2018-1025725 abr 2018
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RISCO
abrir
Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - Local File Inclusion
CVE-2018-1026025 abr 2018
A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.
23RISCO
abrir
Exploit-DB
Blog Master Pro 1.0 - CSV Injection
CVE-2018-1025525 abr 2018
A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level pri
23RISCO
abrir
Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - 'award_id' SQL Injection
CVE-2018-1025625 abr 2018
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RISCO
abrir
Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - (Authenticated) Cross-Site Scripting
CVE-2018-1025925 abr 2018
An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged u
23RISCO
abrir
Exploit-DB
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code Execution (PoC)
CVE-2018-7602CRITICALsob ataqueransomware25 abr 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISCO
abrir
Exploit-DB
Shopy Point of Sale 1.0 - CSV Injection
CVE-2018-1025825 abr 2018
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to
23RISCO
abrir
Exploit-DB
Open-AudIT 2.1 - CSV Macro Injection
CVE-2018-913724 abr 2018
Open-AudIT before 2.2 has CSV Injection.
23RISCO
abrir
Exploit-DB
VLC Media Player/Kodi/PopcornTime 'Red Chimera' < 2.2.5 - Memory Corruption (PoC)
CVE-2017-831124 abr 2018
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an inpu
23RISCO
abrir
Exploit-DB
Ericsson-LG iPECS NMS A.1Ac - Cleartext Credential Disclosure
CVE-2018-924524 abr 2018
The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that a
23RISCO
abrir
Exploit-DB
Adobe Flash - Overflow when Playing Sound
CVE-2018-493624 abr 2018
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Successful exploitat
28RISCO
abrir
Exploit-DB
Microsoft Windows - Local Privilege Escalation
CVE-2018-103824 abr 2018
The Windows kernel in Windows 7 SP1 and Windows Server 2008 R2 SP1 allows an elevation of privilege vulnerability due to
23RISCO
abrir
Exploit-DB
Adobe Flash - Info Leak in Image Inflation
CVE-2018-493424 abr 2018
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful expl
28RISCO
abrir
Exploit-DB
Monstra CMS 3.0.4 - Arbitrary Folder Deletion
CVE-2018-903824 abr 2018
Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uplo
23RISCO
abrir
Exploit-DB
WSO2 Carbon / WSO2 Dashboard Server 5.3.0 - Persistent Cross-Site Scripting
CVE-2018-871624 abr 2018
WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
35RISCO
abrir
Exploit-DB
Adobe Flash - Out-of-Bounds Write in blur Filtering
CVE-2018-493724 abr 2018
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exp
28RISCO
abrir
Exploit-DB
UK Cookie Consent - Persistent Cross-Site Scripting
CVE-2018-1031024 abr 2018
A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Conse
23RISCO
abrir
Exploit-DB
Adobe Flash - Overflow in Slab Rendering
CVE-2018-493524 abr 2018
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exp
28RISCO
abrir
Exploit-DB
Interspire Email Marketer < 6.1.6 - Remote Admin Authentication Bypass
CVE-2017-1432224 abr 2018
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior
35RISCO
abrir
Exploit-DB
WUZHI CMS 4.1.0 - Cross-Site Request Forgery
CVE-2018-1031224 abr 2018
index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.
23RISCO
abrir
Exploit-DB
Easy File Sharing Web Server 7.2 - 'UserID' Remote Buffer Overflow (DEP Bypass)
CVE-2018-905924 abr 2018
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RISCO
abrir
Exploit-DB
ASUS infosvr - Authentication Bypass Command Execution (Metasploit)
CVE-2014-958324 abr 2018
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC
60RISCO
abrir
Exploit-DB
Ericsson-LG iPECS NMS A.1Ac - Cleartext Credential Disclosure
CVE-2018-1028524 abr 2018
The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any
28RISCO
abrir
Exploit-DB
Ericsson-LG iPECS NMS A.1Ac - Cleartext Credential Disclosure
CVE-2018-1028624 abr 2018
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and th
23RISCO
abrir
Exploit-DB
phpMyAdmin 4.8.0 < 4.8.0-1 - Cross-Site Request Forgery
CVE-2018-1018823 abr 2018
phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_ope
23RISCO
abrir
Exploit-DB
Monstra cms 3.0.4 - Persitent Cross-Site Scripting
CVE-2018-1010923 abr 2018
Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload
23RISCO
abrir
anteriorpágina 95 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.