Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DB
Nikto 2.1.6 - CSV Injection
CVE-2018-11652locallinux18 jun 2018
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the S
28RISCO
abrir
Exploit-DB
Redis-cli < 5.0 - Buffer Overflow (PoC)
CVE-2018-12326locallinux18 jun 2018
Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution
23RISCO
abrir
Exploit-DB
Pale Moon Browser < 27.9.3 - Use After Free (PoC)
CVE-2018-12292localwindows18 jun 2018
A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.
23RISCO
abrir
Exploit-DB
Dimofinf CMS 3.0.0 - Cross-Site Scripting
CVE-2018-12094webappsphp15 jun 2018
Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arb
23RISCO
abrir
Exploit-DB
OEcms 3.1 - Cross-Site Scripting
CVE-2018-12095webappsphp15 jun 2018
A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerabil
38RISCO
abrir
Exploit-DB
Joomla! Component Ek Rishta 2.10 - SQL Injection
CVE-2018-12254webappsphp14 jun 2018
router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to
23RISCO
abrir
Exploit-DB
MACCMS 10 - Cross-Site Request Forgery (Add User)
CVE-2018-12114webappsphp13 jun 2018
Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.
23RISCO
abrir
Exploit-DBVexDay Proof
DHCP Client - Command Injection 'DynoRoot' (Metasploit)
CVE-2018-1111HIGHremotelinux13 jun 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - Child Process Restriction Mitigation Bypass
CVE-2018-0982localwindows13 jun 2018
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows
23RISCO
abrir
Exploit-DB
RSLinx Classic and FactoryTalk Linx Gateway - Privilege Escalation
CVE-2018-10619localwindows13 jun 2018
An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.
23RISCO
abrir
Exploit-DBVexDay Proof
glibc - 'realpath()' Privilege Escalation (Metasploit)
CVE-2018-1000001locallinux13 jun 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5751webappsxml12 jun 2018
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RISCO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5754webappsxml12 jun 2018
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and
23RISCO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5753webappsxml12 jun 2018
The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev
23RISCO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5755webappsxml12 jun 2018
Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.
23RISCO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5756webappsxml12 jun 2018
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RISCO
abrir
Exploit-DB
Canon PrintMe EFI - Cross-Site Scripting
CVE-2018-12111webappsphp12 jun 2018
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitra
23RISCO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5752webappsxml12 jun 2018
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RISCO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2017-17062webappsxml12 jun 2018
The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev4
23RISCO
abrir
Exploit-DB
Schools Alert Management Script - SQL Injection
CVE-2018-12055webappsphp11 jun 2018
Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.ph
23RISCO
abrir
Exploit-DB
WordPress Plugin Pie Register < 3.0.9 - Blind SQL Injection
CVE-2018-10969webappsphp11 jun 2018
SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute ar
23RISCO
abrir
Exploit-DB
Schools Alert Management Script - Arbitrary File Read
CVE-2018-12054webappsphp11 jun 2018
Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absol
50RISCO
abrir
Exploit-DB
WebKitGTK+ < 2.21.3 - 'WebKitFaviconDatabase' Denial of Service (Metasploit)
CVE-2018-11646doslinux11 jun 2018
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon
50RISCO
abrir
Exploit-DB
Schools Alert Management Script - Arbitrary File Deletion
CVE-2018-12053webappsphp11 jun 2018
Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.p
28RISCO
abrir
Exploit-DB
Schools Alert Management Script - 'get_sec.php' SQL Injection
CVE-2018-12052webappsphp11 jun 2018
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
23RISCO
abrir
Exploit-DBVexDay Proof
WebKit - Use-After-Free when Resuming Generator
CVE-2018-4218dosmultiple08 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
23RISCO
abrir
Exploit-DB
XiongMai uc-httpd 1.0.0 - Buffer Overflow
CVE-2018-10088webappshardware08 jun 2018
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE
50RISCO
abrir
Exploit-DBVexDay Proof
WebRTC - VP9 Frame Processing Out-of-Bounds Memory Access
CVE-2018-6130dosmultiple08 jun 2018
Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to pot
23RISCO
abrir
Exploit-DBVexDay Proof
WebKit - WebAssembly Compilation Info Leak
CVE-2018-4222dosmultiple08 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
28RISCO
abrir
Exploit-DBVexDay Proof
TrendMicro OfficeScan XG 11.0 - Change Prevention Bypass
CVE-2018-10507localwindows08 jun 2018
A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or
23RISCO
abrir
anteriorpágina 95 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.