Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.559exploits catalogados
34.978CVEs com exploração pública
24.695testados em laboratório
13.960 exploits
GitHub PoC1
CVE-2020-0601: Windows CryptoAPI Vulnerability. (CurveBall/ChainOfFools)
CVE-2020-0601HIGHsob ataque23 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC249
PoC (DoS + scanner) for CVE-2020-0609 & CVE-2020-0610 - RD Gateway RCE
CVE-2020-060923 jan 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISCO
abrir
GitHub PoC318
CVE-2019-0708-EXP-Windows版单文件exe版,运行后直接在当前控制台反弹System权限Shell
CVE-2019-0708CRITICALsob ataqueransomware21 jan 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC58
Indicator of Compromise Scanner for CVE-2019-19781
CVE-2019-19781CRITICALsob ataqueransomware21 jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC
Código desenvolvido para a verificação em massa da vulnerabilidade CVE-2019-19781 de hosts descobertos pelo Shodan. Pull requests são bem vindas.
CVE-2019-19781CRITICALsob ataqueransomware21 jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC40
Scanning for Remote Desktop Gateways (Potentially unpatched CVE-2020-0609 and CVE-2020-0610)
CVE-2020-060921 jan 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISCO
abrir
GitHub PoC94
Indicator of Compromise Scanner for CVE-2019-19781
CVE-2019-19781CRITICALsob ataqueransomware21 jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC
Ash112121/CVE-2020-0601
CVE-2020-0601HIGHsob ataque20 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC1
Remote Command Injection Vulnerability (CVE-2007-2447), allows remote attackers to execute arbitrary commands by specifying a Samba username containing shell meta characters.
CVE-2007-244720 jan 2020
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC5
tfp0 based on CVE-2019-8591/CVE-2019-8605
CVE-2019-859120 jan 2020
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.
23RISCO
abrir
GitHub PoC78
CVE-2020-0601 #curveball - Alternative Key Calculator
CVE-2020-0601HIGHsob ataque20 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC1
CVE-2017-12615 批量脚本
CVE-2017-12615HIGHsob ataqueransomware20 jan 2020
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
GitHub PoC3
CurveBall (CVE-2020-0601) - PoC CVE-2020-0601, or commonly referred to as CurveBall, is a vulnerability in which the signature of certificates using elliptic curve cryptography (ECC) is not correctly verified. Attackers can supply hand-rolled generators, bypassing validation, antivirus & all non-protections.
CVE-2020-0601HIGHsob ataque19 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC
Repo containing lua scripts and PCAP to find CVE-2020-0601 exploit attempts via network traffic
CVE-2020-0601HIGHsob ataque19 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC211
how detect CVE-2020-2551 poc exploit python Weblogic RCE with IIOP
CVE-2020-2551CRITICALsob ataque19 jan 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISCO
abrir
GitHub PoC80
Weblogic RCE with IIOP
CVE-2020-2551CRITICALsob ataque18 jan 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISCO
abrir
GitHub PoC4
CVE-2019-19844 Docker Edition
CVE-2019-1984418 jan 2020
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
35RISCO
abrir
GitHub PoC
Perl version of recently published scripts to build ECC certificates with specific parameters re CVE-2020-0601
CVE-2020-0601HIGHsob ataque18 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC1
CVE-2019-19781 Attack Triage Script
CVE-2019-19781CRITICALsob ataqueransomware17 jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC
MarkusZehnle/CVE-2020-0601
CVE-2020-0601HIGHsob ataque17 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC
批量概念驗證用
CVE-2019-19781CRITICALsob ataqueransomware17 jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC2
CurveBall CVE exploitation
CVE-2020-0601HIGHsob ataque17 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC
A fast multi threaded scanner for Citrix ADC (NetScaler) CVE-2019-19781 - Citrixmash
CVE-2019-19781CRITICALsob ataqueransomware17 jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC1
Powershell to patch CVE-2020-0601 . Complete security rollup for Windows 10 1507-1909
CVE-2020-0601HIGHsob ataque17 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC
C++ based utility to check if certificates are trying to exploit CVE-2020-0601
CVE-2020-0601HIGHsob ataque17 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC2
This script checks the Citrix Netscaler if it has been compromised by CVE-2019-19781 attacks and collects all file system information
CVE-2019-19781CRITICALsob ataqueransomware16 jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC66
Proof of Concept for CVE-2020-0601
CVE-2020-0601HIGHsob ataque16 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC
Castaldio86/Detect-CVE-2019-19781
CVE-2019-19781CRITICALsob ataqueransomware16 jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC5
😂An awesome curated list of repos for CVE-2020-0601.
CVE-2020-0601HIGHsob ataque16 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC1
Curated list of CVE-2020-0601 resources
CVE-2020-0601HIGHsob ataque16 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
anteriorpágina 408 / 466próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.