Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.542exploits catalogados
34.971CVEs com exploração pública
24.695testados em laboratório
13.947 exploits
GitHub PoC
Wh1t3Fox/cve-2018-15473
CVE-2018-15473MEDIUM02 set 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC2
(CVE-2019-2725) Oracle WLS(Weblogic) RCE test sciript
CVE-2019-2725HIGHsob ataqueransomware31 ago 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
GitHub PoC1
(CVE-2020-3452) Cisco Adaptive Security Appliance Software - Local File Inclusion Vuln Test sciript
CVE-2020-3452HIGHsob ataque31 ago 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC4
(CVE-2019-6340, CVE-2018-7600) drupal8-REST-RCE
CVE-2018-7600CRITICALsob ataqueransomware31 ago 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC3
PoC of Full Account Takeover on RAD SecFlow-1v
CVE-2020-1325931 ago 2020
A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauth
23RISCO
abrir
GitHub PoC1
(CVE-2017-5638) XworkStruts RCE Vuln test script
CVE-2017-5638CRITICALsob ataqueransomware31 ago 2020
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC4
(CVE-2019-6340, CVE-2018-7600) drupal8-REST-RCE
CVE-2019-6340HIGHsob ataque31 ago 2020
Drupal core - Highly critical - Remote Code Execution
100RISCO
abrir
GitHub PoC1
(CVE-2019-16759) vBulletin_Routestring-RCE
CVE-2019-16759CRITICALsob ataque31 ago 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC22
Tool to test for existence of CVE-2020-8218
CVE-2020-8218HIGHsob ataque29 ago 2020
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform
83RISCO
abrir
GitHub PoC22
[CVE-2017-9822] DotNetNuke Cookie Deserialization Remote Code Execution (RCE)
CVE-2017-9822HIGHsob ataqueransomware28 ago 2020
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RISCO
abrir
GitHub PoC47
An exploit for CVE-2019-17026. It pops xcalc and was tested on Ubuntu (x64).
CVE-2019-17026HIGHsob ataque27 ago 2020
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are
83RISCO
abrir
GitHub PoC
This CVE-2018-8120 File
CVE-2018-8120HIGHsob ataqueransomware27 ago 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC
TelerikUI Vulnerability Scanner (CVE-2019-18935)
CVE-2019-18935CRITICALsob ataqueransomware26 ago 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir
GitHub PoC2
Exploit for CVE-2019-16724
CVE-2019-1672425 ago 2020
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Excepti
60RISCO
abrir
GitHub PoC1
sunian19/CVE-2019-16759
CVE-2019-16759CRITICALsob ataque24 ago 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC
CVE-2017-8570 Exp及利用样本分析
CVE-2017-0261HIGHsob ataque22 ago 2020
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the softwar
93RISCO
abrir
GitHub PoC
starling021/CVE-2019-11932-SupportApp
CVE-2019-1193220 ago 2020
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC1
ctlyz123/CVE-2020-17496
CVE-2020-17496CRITICALsob ataque20 ago 2020
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbe
100RISCO
abrir
GitHub PoC35
CVE-2019-0230 & s2-059 poc.
CVE-2019-023020 ago 2020
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISCO
abrir
GitHub PoC16
[CVE-2019-18935] Telerik UI for ASP.NET AJAX (RadAsyncUpload Handler) .NET JSON Deserialization
CVE-2019-18935CRITICALsob ataqueransomware19 ago 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir
GitHub PoC532
WebLogic利用CVE-2020-2883打Shiro rememberMe反序列化漏洞,一键注册蚁剑filter内存shell
CVE-2020-2883CRITICALsob ataque19 ago 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISCO
abrir
GitHub PoC
Logeirs/CVE-2018-0114
CVE-2018-011418 ago 2020
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir
GitHub PoC
superzerosec/cve-2020-5902
CVE-2020-5902CRITICALsob ataqueransomware18 ago 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC4
[CVE-2020-0688] Microsoft Exchange Server Fixed Cryptographic Key Remote Code Execution (RCE)
CVE-2020-0688HIGHsob ataqueransomware17 ago 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC1
cyberharsh/PHP_CVE-2012-1823
CVE-2012-1823CRITICALsob ataque17 ago 2020
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISCO
abrir
GitHub PoC6
This tools will extracts and dumps Email + SMTP from vBulletin database server
CVE-2019-16759CRITICALsob ataque16 ago 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC3
dwisiswant0/CVE-2020-9496
CVE-2020-949615 ago 2020
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISCO
abrir
GitHub PoC2
[CVE-2020-5902] F5 BIG-IP Remote Code Execution (RCE)
CVE-2020-5902CRITICALsob ataqueransomware13 ago 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC2
[CVE-2016-2386] SAP NetWeaver AS JAVA UDDI Component SQL Injection
CVE-2016-2386CRITICALsob ataque13 ago 2020
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC7
[CVE-2020-3452] Cisco Adaptive Security Appliance (ASA) & Cisco Firepower Threat Defense (FTD) Web Service Read-Only Directory Traversal
CVE-2020-3452HIGHsob ataque13 ago 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
anteriorpágina 390 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.