Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.542exploits catalogados
34.971CVEs com exploração pública
24.695testados em laboratório
13.947 exploits
GitHub PoC157
Exchange2010 authorized RCE
CVE-2020-17144HIGHsob ataque09 dez 2020
Microsoft Exchange Remote Code Execution Vulnerability
83RISCO
abrir
GitHub PoC
WildfootW/CVE-2007-2447_Samba_3.0.25rc3
CVE-2007-244709 dez 2020
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC
WildfootW/CVE-2014-0160_OpenSSL_1.0.1f_Heartbleed
CVE-2014-0160HIGHsob ataque09 dez 2020
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
WildfootW/CVE-2018-15473_OpenSSH_7.7
CVE-2018-15473MEDIUM09 dez 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC
Remote code execution in Mediawiki Score
CVE-2020-29007CRITICAL08 dez 2020
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of
48RISCO
abrir
GitHub PoC1
PoC for CVE: 2017-5638 - Apache Struts2 S2-045
CVE-2017-5638CRITICALsob ataqueransomware06 dez 2020
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
Exploit for the vulnerability CVE-2007-2447
CVE-2007-244706 dez 2020
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC
[qdPM < 9.1 - Remote Code Execution](https://www.exploit-db.com/exploits/48146)
CVE-2020-724605 dez 2020
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir
GitHub PoC14
This small script helps to avoid using MetaSploit (msfconsole) during the Enterprise pentests and OSCP-like exams. Grep included function will help you to get only the important information.
CVE-2006-339204 dez 2020
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISCO
abrir
GitHub PoC1
Scan through given ip list
CVE-2019-0708CRITICALsob ataqueransomware03 dez 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
ActorExpose/CVE-2017-11882
CVE-2017-11882HIGHsob ataqueransomware03 dez 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC
diegojuan/CVE-2019-15107
CVE-2019-15107CRITICALsob ataqueransomware03 dez 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC49
Python / scapy module implementing SRVLOC/SLP protocol and scans for enabled OpenSLP services.
CVE-2020-3992CRITICALsob ataqueransomware01 dez 2020
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-
100RISCO
abrir
GitHub PoC49
Python / scapy module implementing SRVLOC/SLP protocol and scans for enabled OpenSLP services.
CVE-2019-5544CRITICALsob ataqueransomware01 dez 2020
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of
100RISCO
abrir
GitHub PoC34
CVE-2020-27950 exploit
CVE-2020-27950MEDIUMsob ataque01 dez 2020
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RISCO
abrir
GitHub PoC
wikiZ/cve-2018-8120
CVE-2018-8120HIGHsob ataqueransomware30 nov 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC9
This module massively scan and exploit a path traversal vulnerability in the FortiOS SSL VPN web portal may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests (CVE-2018-13379).
CVE-2018-13379CRITICALsob ataqueransomware30 nov 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
GitHub PoC1
wikiZ/cve-2014-4113
CVE-2014-4113HIGHsob ataque30 nov 2020
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RISCO
abrir
GitHub PoC1
Scanning tool to test for SaltStack vulnerabilities CVE-2020-11651 & CVE-2020-11652.
CVE-2020-11651CRITICALsob ataque30 nov 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
GitHub PoC
Vbulletin RCE Exploits
CVE-2019-16759CRITICALsob ataque29 nov 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC42
OpenSSH 2.3 < 7.7 - Username Enumeration
CVE-2018-15473MEDIUM29 nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC1
Exploit script for Apache Struts2 REST Plugin XStream RCE (‎CVE-2017-9805)
CVE-2017-9805HIGHsob ataque28 nov 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC
Dirty-Racoon/CVE-2018-15473-py3
CVE-2018-15473MEDIUM27 nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC5
CVE-2020-2883
CVE-2020-2883CRITICALsob ataque26 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISCO
abrir
GitHub PoC
openssh<7.7 用户名枚举
CVE-2018-15473MEDIUM26 nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC4
A CVE-2020-17087 PoC.
CVE-2020-17087HIGHsob ataque26 nov 2020
Windows Kernel Local Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC1
www201001/https-github.com-iBearcat-CVE-2018-8174_EXP
CVE-2018-8174HIGHsob ataqueransomware24 nov 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
GitHub PoC1
www201001/https-github.com-iBearcat-CVE-2018-8174_EXP.git-
CVE-2018-8174HIGHsob ataqueransomware24 nov 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
GitHub PoC
1stPeak/CVE-2018-15473
CVE-2018-15473MEDIUM23 nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC1
This container was made to explain and demonstrate how CVE-2019-15813 (Sentrifugo works)
CVE-2019-1581322 nov 2020
Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arb
35RISCO
abrir
anteriorpágina 384 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.