Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.559exploits catalogados
34.978CVEs com exploração pública
24.695testados em laboratório
13.960 exploits
GitHub PoC
cve-2014-6271
CVE-2014-6271CRITICALsob ataque13 nov 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
Sindayifu/CVE-2019-14287-CVE-2014-6271
CVE-2014-6271CRITICALsob ataque13 nov 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC348
Privilege Escalation: Weaponizing CVE-2019-1405 and CVE-2019-1322
CVE-2019-1405HIGHsob ataqueransomware13 nov 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RISCO
abrir
GitHub PoC
Sindayifu/CVE-2019-14287-CVE-2014-6271
CVE-2019-1428713 nov 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC19
Suricata LUA scripts to detect CVE-2019-12255, CVE-2019-12256, CVE-2019-12258, and CVE-2019-12260
CVE-2019-1225512 nov 2019
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TC
45RISCO
abrir
GitHub PoC
Sindadziy/cve-2014-6271
CVE-2014-6271CRITICALsob ataque12 nov 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
Sindadziy/cve-2019-14287
CVE-2019-1428712 nov 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC1
load-scripts.php file, which purpose is to retrieve several JavaScript packages through one single request.
CVE-2018-638911 nov 2019
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
GitHub PoC
cve-2019-14287
CVE-2019-1428711 nov 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC16
Ladon POC Moudle CVE-2019-11043 (PHP-FPM + Ngnix)
CVE-2019-11043HIGHsob ataqueransomware11 nov 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC13
The official exploit for rConfig 3.9.2 Pre-auth Remote Code Execution CVE-2019-16662
CVE-2019-1666210 nov 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISCO
abrir
GitHub PoC8
A standalone POC for CVE-2019-12840
CVE-2019-1284009 nov 2019
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISCO
abrir
GitHub PoC1
Centreon v.19.04 Remote Code Execution exploit (CVE-2019-13024)
CVE-2019-1302408 nov 2019
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitra
35RISCO
abrir
GitHub PoC1
phongld97/detect-cve-2018-16858
CVE-2018-16858HIGH07 nov 2019
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RISCO
abrir
GitHub PoC10
Case study and POC of CVE-2017-12635: Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation
CVE-2017-1263507 nov 2019
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISCO
abrir
GitHub PoC
create12138/CVE-2018-15982
CVE-2018-15982HIGHsob ataqueransomware06 nov 2019
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
GitHub PoC3
CVE-2019-11043 && PHP7.x && RCE EXP
CVE-2019-11043HIGHsob ataqueransomware06 nov 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC14
CVE-2019-11043 PHP7.x RCE
CVE-2019-11043HIGHsob ataqueransomware06 nov 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC13
vesche/CVE-2019-10475
CVE-2019-1047506 nov 2019
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML
50RISCO
abrir
GitHub PoC
Optional Mitigation Steps
CVE-2019-1231405 nov 2019
Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as
60RISCO
abrir
GitHub PoC
CVE-2017-3248
CVE-2017-324805 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RISCO
abrir
GitHub PoC3
CVE-2017-3506
CVE-2017-3506HIGHsob ataque05 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
GitHub PoC1
CVE-2017-0005 POC
CVE-2017-0005HIGHsob ataque05 nov 2019
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
76RISCO
abrir
GitHub PoC2
CVE-2018-3245
CVE-2018-324505 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
45RISCO
abrir
GitHub PoC3
CVE-2019-2725
CVE-2019-2725HIGHsob ataqueransomware05 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
GitHub PoC4
PoC for Webmin Package Update Authenticated Remote Command Execution
CVE-2019-1284005 nov 2019
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISCO
abrir
GitHub PoC2
(CVE-2017-10271)Java反序列化漏洞
CVE-2017-10271HIGHsob ataqueransomware05 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC3
POC for CVE-2019-13720
CVE-2019-13720HIGHsob ataque04 nov 2019
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap
83RISCO
abrir
GitHub PoC
Standalone Python ≥3.6 RCE Unauthenticated exploit for Supervisor 3.0a1 to 3.3.2
CVE-2017-1161002 nov 2019
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISCO
abrir
GitHub PoC
CVE-2018-15473-Exploit
CVE-2018-15473MEDIUM01 nov 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
anteriorpágina 412 / 466próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.