Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
78.295 exploits
GitHub PoC7
quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual exploitation of CVE-2020-1472. requires admin access to the DCs
CVE-2020-1472MEDIUMsob ataqueransomware07 jan 2021
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC5
uzzzval/CVE-2020-17530
CVE-2020-17530CRITICALsob ataque07 jan 2021
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir
GitHub PoC3
Python implementation of Roundcube LFI (CVE-2017-16651)
CVE-2017-16651HIGHsob ataque06 jan 2021
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
98RISCO
abrir
Exploit-DBVexDay Proof
Gitea 1.7.5 - Remote Code Execution
CVE-2019-11229webappsmultiple06 jan 2021
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to rem
35RISCO
abrir
Exploit-DBVexDay Proof
PaperStream IP (TWAIN) 1.42.0.5685 - Local Privilege Escalation
CVE-2018-16156localwindows06 jan 2021
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes u
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-798006 jan 2021
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RISCO
abrir
VulnCheck XDB
local
CVE-2017-16651HIGHsob ataque06 jan 2021
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
98RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1751806 jan 2021
Apache Flink directory traversal attack: remote file writing through the REST API
50RISCO
abrir
Exploit-DB
IPeakCMS 3.5 - Boolean-based blind SQLi
CVE-2021-3018webappsmultiple06 jan 2021
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the
43RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALsob ataque06 jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALsob ataque06 jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALsob ataque06 jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir
GitHub PoC48
Apache Flink 目录遍历漏洞批量检测 (CVE-2020-17519)
CVE-2020-17519CRITICALsob ataque06 jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir
GitHub PoC1
QmF0c3UK/CVE-2020-17519
CVE-2020-17519CRITICALsob ataque06 jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir
GitHub PoC3
Apache Flink Directory Traversal (CVE-2020-17519) Nmap NSE Script
CVE-2020-17519CRITICALsob ataque06 jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir
Exploit-DBVexDay Proof
Sonatype Nexus 3.21.1 - Remote Code Execution (Authenticated)
CVE-2020-10199HIGHsob ataquewebappsjava06 jan 2021
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISCO
abrir
Exploit-DB
Fluentd TD-agent plugin 4.0.1 - Insecure Folder Permission
CVE-2020-28169localwindows05 jan 2021
The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-10148CRITICALsob ataque05 jan 2021
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RISCO
abrir
Exploit-DBVexDay Proof
Klog Server 2.4.1 - Command Injection (Unauthenticated)
CVE-2020-35729webappsphp05 jan 2021
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RISCO
abrir
GitHub PoC10
SolarWinds Orion API 远程代码执行漏洞批量检测脚本
CVE-2020-10148CRITICALsob ataque05 jan 2021
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RISCO
abrir
Exploit-DB
IncomCMS 2.0 - Insecure File Upload
CVE-2020-29597webappsmultiple05 jan 2021
IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows un
60RISCO
abrir
GitHub PoC99
CISCO CVE-2020-3452 Scanner & Exploiter
CVE-2020-3452HIGHsob ataque05 jan 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
Metasploit300
Apache Flink JobManager Traversal
CVE-2020-17519CRITICALsob ataque05 jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir
GitHub PoC1
andyfeili/CVE-2014-4688
CVE-2014-468805 jan 2021
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-3452HIGHsob ataque05 jan 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
Exploit-DB
Mantis Bug Tracker 2.24.3 - 'access' SQL Injection
CVE-2020-28413MEDIUMwebappsphp04 jan 2021
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the A
33RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHsob ataqueransomware04 jan 2021
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
Exploit-DB
Advanced Comment System 1.0 - 'ACS_path' Path Traversal
CVE-2020-35598webappsphp04 jan 2021
ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=.
43RISCO
abrir
GitHub PoC21
Remote Code Execution on Microsoft Exchange Server through fixed cryptographic keys
CVE-2020-0688HIGHsob ataqueransomware04 jan 2021
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC16
Scanner for Zyxel products which are potentially vulnerable due to an undocumented user account (CVE-2020-29583)
CVE-2020-29583CRITICALsob ataque04 jan 2021
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The p
100RISCO
abrir
anteriorpágina 713 / 2.610próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.