Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.559exploits catalogados
34.978CVEs com exploração pública
24.695testados em laboratório
13.947 exploits
GitHub PoC
Description and public exploit for CVE-2020-12712
CVE-2020-1271215 jun 2020
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 an
23RISCO
abrir
GitHub PoC1
A PoC for CVE-2020-8816 that does not use $PATH but $PWD and globbing
CVE-2020-8816CRITICALsob ataque15 jun 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RISCO
abrir
GitHub PoC
sionnx/cve-2003-0282
CVE-2003-028214 jun 2020
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters bet
28RISCO
abrir
GitHub PoC3
for 供養
CVE-2020-6418HIGHsob ataque13 jun 2020
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISCO
abrir
GitHub PoC23
cve-2020-0688 UNIVERSAL Python implementation utilizing ASPX webshell for command output
CVE-2020-0688HIGHsob ataqueransomware12 jun 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC
freshdemo/ApacheStruts-CVE-2018-11776
CVE-2018-11776HIGHsob ataque12 jun 2020
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC
Struts 2.5 - 2.5.12 REST Plugin XStream RCE
CVE-2017-9805HIGHsob ataque11 jun 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC
批量测试CVE-2020-0796 - SMBv3 RCE
CVE-2020-0796CRITICALsob ataqueransomware11 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC
Norton Core Secure WiFi PoC (CVE-2018-5234) on Rust.
CVE-2018-523410 jun 2020
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic
28RISCO
abrir
GitHub PoC354
SMBGhost (CVE-2020-0796) Automate Exploitation and Detection
CVE-2020-0796CRITICALsob ataqueransomware10 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC3
SMBv3 Ghost (CVE-2020-0796) Vulnerability
CVE-2020-0796CRITICALsob ataqueransomware09 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC
ratiros01/CVE-2004-1561
CVE-2004-156109 jun 2020
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISCO
abrir
GitHub PoC5
Bludit >= 3.9.2 - Authenticated RCE (CVE-2019-16113)
CVE-2019-1611309 jun 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISCO
abrir
GitHub PoC
适配12.2.1.3和12.2.1.4版本
CVE-2020-2883CRITICALsob ataque09 jun 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISCO
abrir
GitHub PoC3
This is the exploit of CVE-2019-17240.
CVE-2019-17240LOW08 jun 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISCO
abrir
GitHub PoC72
Triggering and Analyzing Android Kernel Vulnerability CVE-2019-2215
CVE-2019-2215HIGHsob ataque07 jun 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC13
CVE-2019-16113 - bludit >= 3.9.2 RCE authenticate
CVE-2019-1611304 jun 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISCO
abrir
GitHub PoC5
ynots0ups/CVE-2019-16113
CVE-2019-1611303 jun 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISCO
abrir
GitHub PoC3
Data Collection Related to Exim CVE-2019-10149
CVE-2019-10149CRITICALsob ataque03 jun 2020
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir
GitHub PoC
CVE-2020-5410
CVE-2020-5410HIGHsob ataque03 jun 2020
Directory Traversal with spring-cloud-config-server
100RISCO
abrir
GitHub PoC5
Exploit for CVE-2020-9283 based on Go
CVE-2020-928302 jun 2020
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the
28RISCO
abrir
GitHub PoC
CVE-2020-0796-exp
CVE-2020-0796CRITICALsob ataqueransomware02 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC
CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware02 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC89
PoC exploit for VMware Cloud Director RCE (CVE-2020-3956)
CVE-2020-395601 jun 2020
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4
28RISCO
abrir
GitHub PoC3
nmurilo/CVE-2008-4687-exploit
CVE-2008-468730 mai 2020
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISCO
abrir
GitHub PoC5
The reproduction code for CVE-2019-8641.
CVE-2019-864129 mai 2020
An out-of-bounds read was addressed with improved input validation.
28RISCO
abrir
GitHub PoC2
This project for CVE-2019-18935
CVE-2019-18935CRITICALsob ataqueransomware29 mai 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir
GitHub PoC
yukar1z0e/CVE-2017-15944
CVE-2017-15944CRITICALsob ataque29 mai 2020
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISCO
abrir
GitHub PoC
halsten/CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware28 mai 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC55
CVE-2016-4437-Shiro反序列化爆破模块和key,命令执行,反弹shell的脚本
CVE-2016-4437CRITICALsob ataque27 mai 2020
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISCO
abrir
anteriorpágina 396 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.