Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
phpMyAdmin 4.8.0 < 4.8.0-1 - Cross-Site Request Forgery
CVE-2018-1018823 abr 2018
phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_ope
23RISCO
abrir
Exploit-DB
Monstra cms 3.0.4 - Persitent Cross-Site Scripting
CVE-2018-1010923 abr 2018
Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload
23RISCO
abrir
Exploit-DB
Drupal avatar_uploader v7.x-1.0-beta8 - Arbitrary File Disclosure
CVE-2018-920523 abr 2018
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
50RISCO
abrir
Exploit-DB
Ncomputing vSpace Pro 10/11 - Directory Traversal
CVE-2018-1020123 abr 2018
An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible t
50RISCO
abrir
Exploit-DB
Oracle Weblogic Server 10.3.6.0 / 12.1.3.0 / 12.2.1.2 / 12.2.1.3 - Deserialization Remote Command Execution
CVE-2018-2628CRITICALsob ataque22 abr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
Exploit-DB
Cobub Razor 0.8.0 - Physical Path Leakage
CVE-2018-805620 abr 2018
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/ma
28RISCO
abrir
Exploit-DB
Cobub Razor 0.8.0 - Physical Path Leakage
CVE-2018-877020 abr 2018
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, contro
50RISCO
abrir
Exploit-DB
Easy File Sharing Web Server 7.2 - Stack Buffer Overflow
CVE-2018-905918 abr 2018
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RISCO
abrir
Exploit-DB
Kodi 17.6 - Persistent Cross-Site Scripting
CVE-2018-883118 abr 2018
A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/s
35RISCO
abrir
Exploit-DB
Match Clone Script 1.0.4 - Cross-Site Scripting
CVE-2018-985718 abr 2018
PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" sc
23RISCO
abrir
Exploit-DB
WordPress Plugin Caldera Forms 1.5.9.1 - Cross-Site Scripting
CVE-2018-774718 abr 2018
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow re
23RISCO
abrir
Exploit-DB
Geist WatchDog Console 3.2.2 - Multiple Vulnerabilities
CVE-2018-1007818 abr 2018
Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to i
23RISCO
abrir
Exploit-DB
Lutron Quantum 2.0 - 3.2.243 - Information Disclosure
CVE-2018-888018 abr 2018
Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing th
28RISCO
abrir
Exploit-DB
Geist WatchDog Console 3.2.2 - Multiple Vulnerabilities
CVE-2018-1007718 abr 2018
XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to re
23RISCO
abrir
Exploit-DB
Brave Browser < 0.13.0 - 'long alert() argument' Denial of Service
CVE-2017-1825617 abr 2018
Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert
23RISCO
abrir
Exploit-DB
Joomla! Component jDownloads 3.2.58 - Cross Site Scripting
CVE-2018-1006817 abr 2018
The jDownloads extension before 3.2.59 for Joomla! has XSS.
23RISCO
abrir
Exploit-DB
D-Link DIR-615 Wireless Router - Persistent Cross Site Scripting
CVE-2018-1011017 abr 2018
D-Link DIR-615 T1 devices allow XSS via the Add User feature.
23RISCO
abrir
Exploit-DB
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit)
CVE-2018-7600CRITICALsob ataqueransomware17 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
Exploit-DB
Ultra MiniHTTPd 1.2 - 'GET' Remote Stack Buffer Overflow (PoC)
CVE-2013-501917 abr 2018
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RISCO
abrir
Exploit-DB
Brave Browser < 0.13.0 - 'window.close(self)' Denial of Service
CVE-2016-1071817 abr 2018
Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial
28RISCO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQueryVirtualMemory (MemoryImageInformation)' Kernel 64-bit Stack Memory Disclosure
CVE-2018-096816 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir
Exploit-DB
Microsoft Windows - 'CiSetFileCache' TOCTOU Incomplete Fix
CVE-2018-096616 abr 2018
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
23RISCO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQuerySystemInformation (SystemPageFileInformation(Ex))' Kernel 64-bit Stack Memory Disclosure
CVE-2018-097116 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQueryInformationTransactionManager (TransactionManagerRecoveryInformation)' Kernel Pool Memory Disclosure
CVE-2018-097216 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir
Exploit-DB
CloudMe Sync 1.11.0 - Local Buffer Overflow
CVE-2018-788616 abr 2018
An issue was discovered in CloudMe 1.11.0. An unauthenticated local attacker that can connect to the "CloudMe Sync" clie
23RISCO
abrir
Exploit-DB
Cobub Razor 0.8.0 - SQL injection
CVE-2018-805716 abr 2018
A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a
28RISCO
abrir
Exploit-DB
Sophos Cyberoam UTM CR25iNG - 10.6.3 MR-5 - Direct Object Reference
CVE-2016-778616 abr 2018
Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via dir
23RISCO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQueryFullAttributesFile' Kernel Stack Memory Disclosure
CVE-2018-097516 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQueryInformationProcess (ProcessImageFileName)' Kernel 64-bit Pool/Stack Memory Disclosure
CVE-2018-097316 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQueryAttributesFile' Kernel Stack Memory Disclosure
CVE-2018-096916 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir
anteriorpágina 96 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.