Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.607exploits catalogados
34.986CVEs com exploração pública
24.695testados em laboratório
13.974 exploits
GitHub PoC26
CVE-2019-1064 Local Privilege Escalation Vulnerability
CVE-2019-1064HIGHsob ataqueransomware12 jun 2019
Windows Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC11
CVE-2019-1064 Local Privilege Escalation Vulnerability
CVE-2019-1064HIGHsob ataqueransomware12 jun 2019
Windows Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC58
A fully automatic CVE-2019-0841 bypass targeting all versions of Edge in Windows 10.
CVE-2019-0841HIGHsob ataqueransomware11 jun 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RISCO
abrir
GitHub PoC13
CVE-2019-0708批量检测
CVE-2019-0708CRITICALsob ataqueransomware11 jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC2
welove88888/CVE-2019-2725
CVE-2019-2725HIGHsob ataqueransomware11 jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
GitHub PoC22
quick fix for CVE-2019-10149, works on Debian\Ubuntu\Centos
CVE-2019-10149CRITICALsob ataque10 jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir
GitHub PoC2
POC of CVE-2017-5487 + tool
CVE-2017-548710 jun 2019
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISCO
abrir
GitHub PoC1
exploit tool of CVE-2018-10118
CVE-2018-1011810 jun 2019
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI
23RISCO
abrir
GitHub PoC1
exploit tool of CVE-2018-11564
CVE-2018-1156410 jun 2019
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.
23RISCO
abrir
GitHub PoC1
POC of CVE-2018-8718 + tool
CVE-2018-871810 jun 2019
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated
23RISCO
abrir
GitHub PoC118
CVE-2019-0859 1day Exploit
CVE-2019-0859HIGHsob ataque07 jun 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISCO
abrir
GitHub PoC9
Vim/Neovim Arbitrary Code Execution via Modelines (CVE-2019-12735)
CVE-2019-1273506 jun 2019
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RISCO
abrir
GitHub PoC
799600966/CVE-2018-17456
CVE-2018-1745605 jun 2019
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISCO
abrir
GitHub PoC
tarantula-team/CVE-2019-12542
CVE-2019-1254204 jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID paramete
23RISCO
abrir
GitHub PoC
loudong
CVE-2015-754704 jun 2019
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISCO
abrir
GitHub PoC
tarantula-team/CVE-2019-12538
CVE-2019-1253804 jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.
23RISCO
abrir
GitHub PoC
tarantula-team/CVE-2019-12541
CVE-2019-1254104 jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText par
23RISCO
abrir
GitHub PoC
tarantula-team/CVE-2019-12543
CVE-2019-1254304 jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceReques
23RISCO
abrir
GitHub PoC27
Python script to detect bluekeep vulnerability (CVE-2019-0708) with TLS/SSL and x509 support
CVE-2019-0708CRITICALsob ataqueransomware03 jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC37
Privesc through import of Sheduled tasks + Hardlinks - CVE-2019-1069
CVE-2019-1069HIGHsob ataqueransomware03 jun 2019
Task Scheduler Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC1
CVE-2017-0144
CVE-2017-0144HIGHsob ataqueransomware02 jun 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC342
An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits
CVE-2019-0708CRITICALsob ataqueransomware31 mai 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC1
JasonLOU/CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware31 mai 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC1
CVE-2019-0708批量蓝屏恶搞
CVE-2019-0708CRITICALsob ataqueransomware31 mai 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC40
CVE-2019-0708 - BlueKeep (RDP)
CVE-2019-0708CRITICALsob ataqueransomware31 mai 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC1
A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability.
CVE-2019-0708CRITICALsob ataqueransomware30 mai 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC1
CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware30 mai 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC1.181
Proof of concept for CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware29 mai 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC6
infiniti-team/CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware29 mai 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
CVE-2019-0708 bluekeep 漏洞检测
CVE-2019-0708CRITICALsob ataqueransomware29 mai 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
anteriorpágina 421 / 466próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.