Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.558exploits catalogados
34.977CVEs com exploração pública
24.695testados em laboratório
13.947 exploits
GitHub PoC
Bludit Exploitation Via upload Image.php
CVE-2019-1611317 jul 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISCO
abrir
GitHub PoC
Disables AJP connectors to remediate CVE-2020-1938!
CVE-2020-1938CRITICALsob ataque17 jul 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC10
Citrix Unauthorized Remote Code Execution Attacker - CVE-2019-19781
CVE-2019-19781CRITICALsob ataqueransomware17 jul 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC11
CVE-2020-1350 Proof-of-Concept
CVE-2020-1350CRITICALsob ataque17 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir
GitHub PoC8
GUI
CVE-2020-5902CRITICALsob ataqueransomware17 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC18
Denial of Service PoC for CVE-2020-1350 (SIGRed)
CVE-2020-1350CRITICALsob ataque16 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir
GitHub PoC1
Environment for CVE_2019_17571
CVE-2019-17571CRITICAL16 jul 2020
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be explo
60RISCO
abrir
GitHub PoC225
PoC for CVE-2020-6287, CVE-2020-6286 (SAP RECON vulnerability)
CVE-2020-6287CRITICALsob ataque15 jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISCO
abrir
GitHub PoC2
ctlyz123/CVE-2020-8193
CVE-2020-8193MEDIUMsob ataque15 jul 2020
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RISCO
abrir
GitHub PoC
Windows registry mitigation response to CVE-2020-1350
CVE-2020-1350CRITICALsob ataque15 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir
GitHub PoC237
A denial-of-service proof-of-concept for CVE-2020-1350
CVE-2020-1350CRITICALsob ataque15 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir
GitHub PoC15
This Powershell Script is checking if your server is vulnerable for the CVE-2020-1350 Remote Code Execution flaw in the Windows DNS Service
CVE-2020-1350CRITICALsob ataque15 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir
GitHub PoC9
Detection of attempts to exploit Microsoft Windows DNS server via CVE-2020-1350 (AKA SIGRed)
CVE-2020-1350CRITICALsob ataque15 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir
GitHub PoC7
Fake exploit tool, designed to rickroll users attempting to actually exploit.
CVE-2020-1350CRITICALsob ataque14 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir
GitHub PoC279
HoneyPoC: Proof-of-Concept (PoC) script to exploit SIGRed (CVE-2020-1350). Achieves Domain Admin on Domain Controllers running Windows Server 2000 up to Windows Server 2019.
CVE-2020-1350CRITICALsob ataque14 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir
GitHub PoC4
mr-r3b00t/CVE-2020-1350
CVE-2020-1350CRITICALsob ataque14 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir
GitHub PoC8
Scanning for CVE-2020-8193 - Auth Bypass check
CVE-2020-8193MEDIUMsob ataque13 jul 2020
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RISCO
abrir
GitHub PoC
quick and dirty PHP RCE proof of concept
CVE-2019-11043HIGHsob ataqueransomware13 jul 2020
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC3
TeamViewer Store Credentials Decryption
CVE-2019-18988HIGHsob ataque13 jul 2020
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for dif
86RISCO
abrir
GitHub PoC45
Citrix ADC从权限绕过到RCE
CVE-2020-8193MEDIUMsob ataque12 jul 2020
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RISCO
abrir
GitHub PoC
momika233/cve-2020-5902
CVE-2020-5902CRITICALsob ataqueransomware12 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC
freeFV/CVE-2020-5902-fofa-scan
CVE-2020-5902CRITICALsob ataqueransomware12 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC6
This Metasploit-Framework module can be use to help companies to check the last Citrix vulnerability CVE-2020-8193, CVE-2020-8195 and CVE-2020-8196 (disclosed July 08, 2020).
CVE-2020-8193MEDIUMsob ataque12 jul 2020
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RISCO
abrir
GitHub PoC
Exploits for CVE-2020-5902 POC
CVE-2020-5902CRITICALsob ataqueransomware11 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC10
CVE-2020-5902
CVE-2020-5902CRITICALsob ataqueransomware11 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC2
批量检测CVE-2020-5902
CVE-2020-5902CRITICALsob ataqueransomware10 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC5
Checker CVE-2020-5902: BIG-IP versions 15.0.0 through 15.1.0.3, 14.1.0 through 14.1.2.5, 13.1.0 through 13.1.3.3, 12.1.0 through 12.1.5.1, and 11.6.1 through 11.6.5.1 suffer from Traffic Management User Interface (TMUI) arbitrary file read and command execution vulnerabilities.
CVE-2020-5902CRITICALsob ataqueransomware10 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC62
F5 BIG-IP RCE CVE-2020-5902 automatic check tool
CVE-2020-5902CRITICALsob ataqueransomware10 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC88
Citrix ADC Vulns
CVE-2020-8193MEDIUMsob ataque10 jul 2020
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RISCO
abrir
GitHub PoC
SharpHack/CVE-2019-19781
CVE-2019-19781CRITICALsob ataqueransomware09 jul 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
anteriorpágina 393 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.