Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.542exploits catalogados
34.971CVEs com exploração pública
24.695testados em laboratório
13.947 exploits
GitHub PoC1
Simple detection tool for Blueborne vulnerability found on Android devices --- CVE-2017-0781.
CVE-2017-078130 jul 2020
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RISCO
abrir
GitHub PoC
CVE-2020-3452 : Cisco ASA and FTD Unauthorized Remote File Reading Nmap NSE Script
CVE-2020-3452HIGHsob ataque29 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC1
CrackerCat/CVE-2020-3187
CVE-2020-3187CRITICAL28 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISCO
abrir
GitHub PoC4
A network detection package for CVE-2020-5902, a CVE10.0 vulnerability affecting F5 Networks, Inc BIG-IP devices.
CVE-2020-5902CRITICALsob ataqueransomware28 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC
Better version of rastating.github.io/bludit-brute-force-mitigation-bypass/
CVE-2019-17240LOW28 jul 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISCO
abrir
GitHub PoC1
环境下载
CVE-2020-14645CRITICAL28 jul 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RISCO
abrir
GitHub PoC2
Citrix ADC scanner (CVE-2019-19781) using hosts retrieved from Shodan API.
CVE-2019-19781CRITICALsob ataqueransomware27 jul 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC2
This exploit is remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data
CVE-2016-209827 jul 2020
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISCO
abrir
GitHub PoC24
CVE-2020–9934 POC
CVE-2020-9934MEDIUMsob ataque27 jul 2020
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue
78RISCO
abrir
GitHub PoC1
Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API.
CVE-2019-11510CRITICALsob ataqueransomware27 jul 2020
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISCO
abrir
GitHub PoC2
A registry-based workaround can be used to help protect an affected Windows server, and it can be implemented without requiring an administrator to restart the server. Because of the volatility of this vulnerability, administrators may have to implement the workaround before they apply the security update in order to enable them to update their systems by using a standard deployment cadence.
CVE-2020-1350CRITICALsob ataque26 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir
GitHub PoC
没有编写完成,以后学习更多知识在回来完善
CVE-2015-856225 jul 2020
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISCO
abrir
GitHub PoC20
KaLendsi/CVE-2020-1054
CVE-2020-1054HIGHsob ataque25 jul 2020
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
98RISCO
abrir
GitHub PoC3
Little, stupid python validator(?) for CVE-2020-3452 on CISCO devices.
CVE-2020-3452HIGHsob ataque25 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC
mr-r3b00t/CVE-2020-3452
CVE-2020-3452HIGHsob ataque24 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC25
CVE-2020-3452 Cisco ASA Scanner -unauth Path Traversal Check
CVE-2020-3452HIGHsob ataque24 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC2
unauth file read in cisco asa & firepower.
CVE-2020-3452HIGHsob ataque24 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC2
XDev05/CVE-2020-3452-PoC
CVE-2020-3452HIGHsob ataque24 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC
A powershell script to deploy the registry mitigation key for CVE-2020-1350
CVE-2020-1350CRITICALsob ataque22 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir
GitHub PoC2
sap netweaver portal add user administrator
CVE-2020-6287CRITICALsob ataque22 jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISCO
abrir
GitHub PoC28
Onapsis/CVE-2020-6287_RECON-scanner
CVE-2020-6287CRITICALsob ataque21 jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISCO
abrir
GitHub PoC17
f5devcentral/cve-2020-5902-ioc-bigip-checker
CVE-2020-5902CRITICALsob ataqueransomware20 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC96
PoC for CVE-2020-6287 The PoC in python for add user only, no administrator permission set. Inspired by @zeroSteiner from metasploit. Original Metasploit PR module: https://github.com/rapid7/metasploit-framework/pull/13852/commits/d1e2c75b3eafa7f62a6aba9fbe6220c8da97baa8 This PoC only create user with unauthentication permission and no more administrator permission set. This project is created only for educational purposes and cannot be used for law violation or personal gain. The author of this project is not responsible for any possible harm caused by the materials of this project. Original finding: CVE-2020-6287: Pablo Artuso CVE-2020-6286: Yvan 'iggy' G. Usage: python sap-CVE-2020-6287-add-user.py <HTTP(s)://IP:Port
CVE-2020-6287CRITICALsob ataque20 jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISCO
abrir
GitHub PoC1
Ported Exploit From Python To Golang
CVE-2018-689220 jul 2020
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RISCO
abrir
GitHub PoC80
Weblogic CVE-2020-14645 UniversalExtractor JNDI injection getDatabaseMetaData()
CVE-2020-14645CRITICAL20 jul 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RISCO
abrir
GitHub PoC3
DaBoQuan/CVE-2020-14645
CVE-2020-14645CRITICAL20 jul 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RISCO
abrir
GitHub PoC
DNS Vulnerability - CVE-2020-1350
CVE-2020-1350CRITICALsob ataque19 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir
GitHub PoC4
Iamgublin/CVE-2020-1054
CVE-2020-1054HIGHsob ataque19 jul 2020
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
98RISCO
abrir
GitHub PoC2
Scanner and Mitigator for CVE 2020-1350
CVE-2020-1350CRITICALsob ataque18 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir
GitHub PoC4
Enviroment and exploit to rce test
CVE-2020-816318 jul 2020
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
60RISCO
abrir
anteriorpágina 392 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.