Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.559exploits catalogados
34.978CVEs com exploração pública
24.695testados em laboratório
13.960 exploits
GitHub PoC4
Modified standalone exploit ported for Python 3
CVE-2018-1261316 set 2019
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir
GitHub PoC3
CVE-2019-0604: SharePoint RCE detection rules and sample PCAP
CVE-2019-0604CRITICALsob ataqueransomware15 set 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISCO
abrir
GitHub PoC
Tool to exploit CVE-2018-7284 and CVE-2018-19278
CVE-2018-728415 set 2019
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Ce
35RISCO
abrir
GitHub PoC1
CVE-2019-0708 C#验证漏洞
CVE-2019-0708CRITICALsob ataqueransomware11 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC1
distance-vector/CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware11 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
likekabin/CVE-2019-1253
CVE-2019-1253HIGHsob ataqueransomware11 set 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISCO
abrir
GitHub PoC19
AppXSvc Arbitrary File Security Descriptor Overwrite EoP
CVE-2019-1253HIGHsob ataqueransomware11 set 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISCO
abrir
GitHub PoC152
Poc for CVE-2019-1253
CVE-2019-1253HIGHsob ataqueransomware11 set 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISCO
abrir
GitHub PoC63
securifera/CVE-2019-1579
CVE-2019-1579HIGHsob ataqueransomware10 set 2019
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with Glob
83RISCO
abrir
GitHub PoC
0x6b7966/CVE-2018-1999002
CVE-2018-199900210 set 2019
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framewor
45RISCO
abrir
GitHub PoC133
Exploit for Pulse Connect Secure SSL VPN arbitrary file read vulnerability (CVE-2019-11510)
CVE-2019-11510CRITICALsob ataqueransomware09 set 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISCO
abrir
GitHub PoC4
CVE-2019-0708 With Metasploit-Framework Exploit
CVE-2019-0708CRITICALsob ataqueransomware07 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC1
CVE-2019-0708 RCE远程代码执行getshell教程
CVE-2019-0708CRITICALsob ataqueransomware07 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
CVE-2019-0708RDP MSF
CVE-2019-0708CRITICALsob ataqueransomware07 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC11
CVE-2019-0708-EXP(MSF) Vulnerability exploit program for cve-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware07 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC12
initial exploit for CVE-2019-0708, BlueKeep CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free The RDP termdd.sys driver improperly handles binds to internal-only channel MS_T120, allowing a malformed Disconnect Provider Indication message to cause use-after-free. With a controllable data/size remote nonpaged pool spray, an indirect call gadget of the freed channel is used to achieve arbitrary code execution.
CVE-2019-0708CRITICALsob ataqueransomware07 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC187
Root your MediaTek device with CVE-2020-0069
CVE-2020-0069HIGHsob ataque06 set 2019
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RISCO
abrir
GitHub PoC13
Metasploit module for CVE-2019-0708 (BlueKeep) - https://github.com/rapid7/metasploit-framework/tree/5a0119b04309c8e61b44763ac08811cd3ecbbf8d/modules/exploits/windows/rdp
CVE-2019-0708CRITICALsob ataqueransomware06 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
webcam bug (python)
CVE-2018-999505 set 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
GitHub PoC4
CVE-2019-10149
CVE-2019-10149CRITICALsob ataque05 set 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir
GitHub PoC132
Exploit for the Post-Auth RCE vulnerability in Pulse Secure Connect
CVE-2019-11539HIGHsob ataqueransomware04 set 2019
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISCO
abrir
GitHub PoC1
jaychouzzk/CVE-2019-0193-exp
CVE-2019-0193HIGHsob ataque03 set 2019
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISCO
abrir
GitHub PoC2
CVE-2019-0708 BlueKeep漏洞批量扫描工具和POC,暂时只有蓝屏。
CVE-2019-0708CRITICALsob ataqueransomware03 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
A script to Fuzz and and exploit Apache struts CVE-2017-9805
CVE-2017-9805HIGHsob ataque02 set 2019
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC
simplified version of https://github.com/shauntdergrigorian/cve-2006-6184
CVE-2006-618401 set 2019
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RISCO
abrir
GitHub PoC1
Simple python script to fuzz site for CVE-2017-9805
CVE-2017-9805HIGHsob ataque31 ago 2019
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC
jason3e7/CVE-2019-11510
CVE-2019-11510CRITICALsob ataqueransomware29 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISCO
abrir
GitHub PoC18
Nmap NSE script to detect Pulse Secure SSL VPN file disclosure CVE-2019-11510
CVE-2019-11510CRITICALsob ataqueransomware27 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISCO
abrir
GitHub PoC52
SSL VPN Rce
CVE-2019-11510CRITICALsob ataqueransomware27 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISCO
abrir
GitHub PoC5
PoC for CVE-2019-11510 | Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure vulnerability
CVE-2019-11510CRITICALsob ataqueransomware26 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISCO
abrir
anteriorpágina 416 / 466próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.