Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DB
WUZHI CMS 4.1.0 - 'form[qq_10]' Cross-Site Scripting
CVE-2018-10313webappsphp13 mai 2018
WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 2003 SP2 - 'RRAS' SMB Remote Code Execution
CVE-2017-11885remotewindows13 mai 2018
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold,
35RISCO
abrir
Exploit-DB
Open-AudIT Community 2.2.0 - Cross-Site Scripting
CVE-2018-10314webappswindows11 mai 2018
Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web s
23RISCO
abrir
Exploit-DB
2345 Security Guard 3.7 - '2345BdPcSafe.sys' Denial of Service
CVE-2018-10830doswindows11 mai 2018
In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv
23RISCO
abrir
Exploit-DB
Open-AudIT Professional - 2.1.1 - Cross-Site Scripting
CVE-2018-9155webappswindows11 mai 2018
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary we
23RISCO
abrir
Exploit-DB
EMC RecoverPoint 4.3 - 'Admin CLI' Command Injection
CVE-2018-1185localwindows11 mai 2018
An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0
23RISCO
abrir
Exploit-DB
MyBB Latest Posts on Profile Plugin 1.1 - Cross-Site Scripting
CVE-2018-10580webappsphp10 mai 2018
The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displ
23RISCO
abrir
Exploit-DB
Dell Touchpad - 'ApMsgFwd.exe' Denial of Service
CVE-2018-10828doswindows10 mai 2018
An issue was discovered in Alps Pointing-device Driver 10.1.101.207. ApMsgFwd.exe allows the current user to map and wri
23RISCO
abrir
Exploit-DB
ModbusPal 1.6b - XML External Entity Injection
CVE-2018-10832webappsjava10 mai 2018
ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations c
23RISCO
abrir
Exploit-DBVexDay Proof
Mantis Bug Tracker 1.1.3 - 'manage_proj_page' PHP Code Execution (Metasploit)
CVE-2008-4687remotephp10 mai 2018
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISCO
abrir
Exploit-DB
Fastweb FASTGate 0.00.47 - Cross-Site Request Forgery
CVE-2018-6023webappshardware10 mai 2018
Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi act
23RISCO
abrir
Exploit-DBVexDay Proof
PlaySMS 1.4 - 'sendfromfile.php?Filename' (Authenticated) 'Code Execution (Metasploit)
CVE-2017-9080remotephp08 mai 2018
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile
50RISCO
abrir
Exploit-DBVexDay Proof
FTPShell Client 6.7 - Buffer Overflow
CVE-2018-7573remotewindows08 mai 2018
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with t
50RISCO
abrir
Exploit-DB
2345 Security Guard 3.7 - '2345NetFirewall.sys' Denial of Service
CVE-2018-10809doswindows_x8608 mai 2018
In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD)
23RISCO
abrir
Exploit-DBVexDay Proof
PlaySMS - 'import.php' (Authenticated) CSV File Upload Code Execution (Metasploit)
CVE-2017-9101remotephp08 mai 2018
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RISCO
abrir
Exploit-DBVexDay Proof
Palo Alto Networks - 'readSessionVarsFromFile()' Session Corruption (Metasploit)
CVE-2017-15944CRITICALsob ataqueremoteunix08 mai 2018
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISCO
abrir
Exploit-DB
CSP MySQL User Manager 2.3.1 - Authentication Bypass
CVE-2018-10757webappslinux06 mai 2018
CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a
23RISCO
abrir
Exploit-DB
DeviceLock Plug and Play Auditor 5.72 - Unicode Buffer Overflow (SEH)
CVE-2018-10655localwindows06 mai 2018
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
28RISCO
abrir
Exploit-DB
GNU wget - Cookie Injection
CVE-2018-0494locallinux06 mai 2018
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequen
28RISCO
abrir
Exploit-DB
IceWarp Mail Server < 11.1.1 - Directory Traversal
CVE-2015-1503webappsphp04 mai 2018
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary
50RISCO
abrir
Exploit-DB
WordPress Plugin WF Cookie Consent 1.1.3 - Cross-Site Scripting
CVE-2018-10371webappsphp04 mai 2018
An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scriptin
23RISCO
abrir
Exploit-DBVexDay Proof
Google Chrome V8 - Object Allocation Size Integer Overflow
CVE-2018-6065HIGHsob ataqueremotemultiple04 mai 2018
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows WMI - Recieve Notification Exploit (Metasploit)
CVE-2016-0040HIGHsob ataquelocalwindows_x86-6404 mai 2018
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RISCO
abrir
Exploit-DB
GPON Routers - Authentication Bypass / Command Injection
CVE-2018-10562CRITICALsob ataqueransomwareremotehardware03 mai 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RISCO
abrir
Exploit-DB
JasperReports - (Authenticated) File Read
CVE-2018-5430HIGHsob ataquewebappsmultiple03 mai 2018
TIBCO JasperReports Server Information Disclosure Vulnerability
83RISCO
abrir
Exploit-DB
GPON Routers - Authentication Bypass / Command Injection
CVE-2018-10561CRITICALsob ataqueremotehardware03 mai 2018
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images
100RISCO
abrir
Exploit-DB
TBK DVR4104 / DVR4216 - Credentials Leak
CVE-2018-9995remotehardware02 mai 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
Exploit-DB
LibreOffice/Open Office - '.odt' Information Disclosure
CVE-2018-10583localwindows02 mai 2018
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
60RISCO
abrir
Exploit-DB
Norton Core Secure WiFi Router - 'BLE' Command Injection (PoC)
CVE-2018-5234remotehardware02 mai 2018
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic
28RISCO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::jsElementScrollHeightGetter' Use-After-Free
CVE-2018-4200dosmultiple02 mai 2018
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud
23RISCO
abrir
anteriorpágina 99 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.