Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.542exploits catalogados
34.971CVEs com exploração pública
24.695testados em laboratório
13.947 exploits
GitHub PoC29
CVE-2020–14882 by Jang
CVE-2020-14882CRITICALsob ataque28 out 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC14
PoC for old Binder vulnerability (based on P0 exploit)
CVE-2019-2215HIGHsob ataque27 out 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC8
POC For CVE-2020-1481 - Jira Username Enumerator/Validator
CVE-2020-1418126 out 2020
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
60RISCO
abrir
GitHub PoC
datntsec/CVE-2019-12735
CVE-2019-1273526 out 2020
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RISCO
abrir
GitHub PoC2
Python exploit for CVE-2012-2982
CVE-2012-298225 out 2020
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir
GitHub PoC11
CVE-2020-0688 PoC
CVE-2020-0688HIGHsob ataqueransomware23 out 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC1
PoC for apache struts 2 vuln cve-2019-0230
CVE-2019-023022 out 2020
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISCO
abrir
GitHub PoC
puckiestyle/CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware21 out 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC2
Bludit <= 3.9.2 - Authentication Bruteforce Mitigation Bypass Exploit/PoC
CVE-2019-17240LOW21 out 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISCO
abrir
GitHub PoC
Elsfa7-110/CVE-2019-1579
CVE-2019-1579HIGHsob ataqueransomware21 out 2020
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with Glob
83RISCO
abrir
GitHub PoC
HYWZ36/CVE-2020-14645-code
CVE-2020-14645CRITICAL21 out 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RISCO
abrir
GitHub PoC2
cve-2020-14644 漏洞环境
CVE-2020-14644CRITICALsob ataque20 out 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISCO
abrir
GitHub PoC7
ThinkAdmin CVE-2020-25540 poc
CVE-2020-2554019 out 2020
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RISCO
abrir
GitHub PoC
datntsec/CVE-2019-13272
CVE-2019-13272HIGHsob ataque19 out 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
GitHub PoC
Exploitable target to CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware19 out 2020
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
stealth-ronin/CVE-2017-0199-PY-KIT
CVE-2017-0199HIGHsob ataqueransomware18 out 2020
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC
Exploits CuteNews 2.1.2 via poor file upload checks used when uploading an avatar image leading to RCE.
CVE-2019-1144718 out 2020
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISCO
abrir
GitHub PoC5
C# Vulnerability Checker for CVE-2020-1472 Aka Zerologon
CVE-2020-1472MEDIUMsob ataqueransomware17 out 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC1
Converted with tweaks from a metasploit module as an exercise for OSCP studying and exploit development
CVE-2015-330616 out 2020
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir
GitHub PoC
Check for events that indicate non compatible devices -> CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware15 out 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC3
CVE-2019–15107 - Unauthenticated RCE Webmin <=1.920
CVE-2019-15107CRITICALsob ataqueransomware15 out 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC2
FancyDoesSecurity/CVE-2020-2883
CVE-2020-2883CRITICALsob ataque14 out 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISCO
abrir
GitHub PoC10
BlueBorne Exploits & Framework This repository contains a PoC code of various exploits for the BlueBorne vulnerabilities. Under 'android' exploits for the Android RCE vulnerability (CVE-2017-0781), and the SDP Information leak vulnerability (CVE-2017-0785) can be found. Under 'linux-bluez' exploits for the Linux-RCE vulnerability (CVE-2017-1000251) can be found (for Amazon Echo, and Samsung Gear S3). Under 'l2cap_infra' a general testing framework to send and receive raw l2cap messages (using scapy) can be found. Under 'nRF24_BDADDR_Sniffer' a tool to capture bluetooth mac addresses (BDADDR) over the air, using a nRF24L01 chip For more details on BlueBorne, you may read the full technical white paper available here: https://www.armis.com/blueborne/ In addition a several detailed blog posts on the exploitation of these vulnerability can be found here: https://www.armis.com/blog/ =============== Dependencies:
CVE-2017-078112 out 2020
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RISCO
abrir
GitHub PoC58
https://medium.com/@mansoorr/exploiting-cve-2020-25213-wp-file-manager-wordpress-plugin-6-9-3f79241f0cd8
CVE-2020-25213CRITICALsob ataque10 out 2020
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir
GitHub PoC4
n3m1sys/CVE-2018-16763-Exploit-Python3
CVE-2018-1676310 out 2020
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC2
shanfenglan/cve-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware10 out 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC2
提供单个或批量URL扫描是否存在CVE-2022-22954功能
CVE-2022-22954CRITICALsob ataqueransomware09 out 2020
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
GitHub PoC5
Typesetter CMS文件上传漏洞环境
CVE-2020-2579009 out 2020
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archi
28RISCO
abrir
GitHub PoC
Bludit 3.9.2 - Remote command execution - CVE-2019-16113
CVE-2019-1611307 out 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISCO
abrir
GitHub PoC7
EternalBlue is a well-known SMB exploit created by the NSA to attack various versions of Windows, including Windows 7. Etern-Blue-Windows-7-Checker will basically send SMB packets to a host to see if that Windows host machine is vulnerable to the EternalBlue exploit (CVE-2017-0143).
CVE-2017-0143HIGHsob ataqueransomware07 out 2020
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
anteriorpágina 387 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.