Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
13.937 exploits
GitHub PoC11
CVE-2020-25223
CVE-2020-25223CRITICALsob ataque29 ago 2021
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RISCO
abrir
GitHub PoC1
Citrix ADC RCE cve-2019-19781
CVE-2019-19781CRITICALsob ataqueransomware29 ago 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC9
Exploit for CVE-2019-19609 in Strapi (Remote Code Execution)
CVE-2019-1960929 ago 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISCO
abrir
GitHub PoC
BabyTeam1024/CVE-2017-3248
CVE-2017-324829 ago 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RISCO
abrir
GitHub PoC1
CVE-2004-2687 DistCC Daemon Command Execution
CVE-2004-268728 ago 2021
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISCO
abrir
GitHub PoC
AssassinUKG/CVE-2021-29447
CVE-2021-29447HIGH27 ago 2021
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC1
A proof of concept for CVE-2016-6515
CVE-2016-651526 ago 2021
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a
35RISCO
abrir
GitHub PoC1
Kibana Prototype Pollution
CVE-2019-7609CRITICALsob ataque24 ago 2021
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir
GitHub PoC24
my exp for chrome V8 CVE-2021-30551
CVE-2021-30551HIGHsob ataque22 ago 2021
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corru
83RISCO
abrir
GitHub PoC1
An implementation of CVE-2015-3306
CVE-2015-330621 ago 2021
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir
GitHub PoC
rood8008/CVE-2021-35464
CVE-2021-35464CRITICALsob ataqueransomware21 ago 2021
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RISCO
abrir
GitHub PoC11
CVE-2018-19320 LPE Exploit
CVE-2018-19320HIGHsob ataqueransomware19 ago 2021
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RISCO
abrir
GitHub PoC1
CVE-2019-11932
CVE-2019-1193217 ago 2021
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC1
Multiple Stored XSS Online Doctor Appointment System
CVE-2021-2579116 ago 2021
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment S
23RISCO
abrir
GitHub PoC1
A tool to crash MySQL servers with CVE-2017-3599
CVE-2017-359916 ago 2021
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions t
45RISCO
abrir
GitHub PoC30
CVE-2021-34473 Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-34473CRITICALsob ataqueransomware16 ago 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
tools for automate configure Ubuntu 20.04 enviroment for testing CVE-2021-28476.
CVE-2021-28476CRITICAL15 ago 2021
Windows Hyper-V Remote Code Execution Vulnerability
60RISCO
abrir
GitHub PoC
The Heartbleed bug `CVE-2014-0160` is a severe implementation flaw in the OpenSSL library, which enables attackers to steal data from the memory of the victim server. The contents of the stolen data depend on what is there in the memory of the server. It could potentially contain private keys, TLS session keys, usernames, passwords, credit cards, etc. The vulnerability is in the implementation of the Heartbeat protocol, which is used by SSL/TLS to keep the connection alive.
CVE-2014-0160HIGHsob ataque15 ago 2021
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC3
WordPress File Upload Vulnerability, Modern Events Calendar Lite WordPress plugin before 5.16.5
CVE-2021-2414514 ago 2021
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RISCO
abrir
GitHub PoC1
An implementation of CVE-2020-1938
CVE-2020-1938CRITICALsob ataque14 ago 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC
WpDiscuz 7.0.4 Arbitrary File Upload Exploit
CVE-2020-24186CRITICAL13 ago 2021
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISCO
abrir
GitHub PoC1
Sudo Heap Overflow Baron Samedit
CVE-2021-3156HIGHsob ataque13 ago 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC3
Exploit for CVE-2021-36934
CVE-2021-36934HIGHsob ataque12 ago 2021
Windows Elevation of Privilege Vulnerability
98RISCO
abrir
GitHub PoC5
Scanner for CVE-2021-34473, ProxyShell, A Microsoft Exchange On-premise Vulnerability
CVE-2021-34473CRITICALsob ataqueransomware11 ago 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Zeek Package to detect cve-2017-2741
CVE-2017-274111 ago 2021
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RISCO
abrir
GitHub PoC
Jerry-zhuang/CVE-2017-1000117
CVE-2017-100011711 ago 2021
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RISCO
abrir
GitHub PoC2
CVE-2019-11043
CVE-2019-11043HIGHsob ataqueransomware10 ago 2021
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC
ZeroShell命令执行漏洞批量扫描poc+exp
CVE-2019-1272510 ago 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir
GitHub PoC46
nuclei scanner for proxyshell ( CVE-2021-34473 )
CVE-2021-34473CRITICALsob ataqueransomware10 ago 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
OlivierLaflamme/CVE-2021-36934-export-shadow-volume-POC
CVE-2021-36934HIGHsob ataque10 ago 2021
Windows Elevation of Privilege Vulnerability
98RISCO
abrir
anteriorpágina 362 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.