Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
78.324 exploits
Exploit-DB
TP-Link TL-WA855RE V5_200415 - Device Reset Auth Bypass
CVE-2020-24363HIGHsob ataquewebappshardware23 nov 2020
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP
76RISCO
abrir
GitHub PoC
1stPeak/CVE-2018-15473
CVE-2018-15473MEDIUM23 nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC1
This container was made to explain and demonstrate how CVE-2019-15813 (Sentrifugo works)
CVE-2019-1581322 nov 2020
Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arb
35RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALsob ataqueransomware22 nov 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1394221 nov 2020
Remote Code Execution in Apache Unomi
50RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-11043HIGHsob ataqueransomware21 nov 2020
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
Metasploit600
qdPM 9.1 Authenticated Arbitrary PHP File Upload (RCE)
CVE-2020-724621 nov 2020
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir
GitHub PoC2
MasterSploit/LPE---CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware20 nov 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1394220 nov 2020
Remote Code Execution in Apache Unomi
50RISCO
abrir
VulnCheck XDB
local
CVE-2020-0796CRITICALsob ataqueransomware20 nov 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
Exploit-DB
PESCMS TEAM 2.3.2 - Multiple Reflected XSS
CVE-2020-28092webappsmultiple19 nov 2020
PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&s
23RISCO
abrir
VulnCheck XDB
infoleak
CVE-2018-13379CRITICALsob ataqueransomware19 nov 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
GitHub PoC6
FortiVuln
CVE-2018-13379CRITICALsob ataqueransomware19 nov 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
Exploit-DB
Fortinet FortiOS 6.0.4 - Unauthenticated SSL VPN User Password Modification
CVE-2018-13382CRITICALsob ataqueransomwarewebappshardware19 nov 2020
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISCO
abrir
Metasploit0
Google Chrome versions before 87.0.4280.88 integer overflow during SimplfiedLowering phase
CVE-2020-1604019 nov 2020
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RISCO
abrir
Exploit-DB
xuucms 3 - 'keywords' SQL Injection
CVE-2020-28091webappsmultiple19 nov 2020
cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parame
23RISCO
abrir
Exploit-DB
Gemtek WVRTM-127ACN 01.01.02.141 - Authenticated Arbitrary Command Injection
CVE-2020-24365webappscgi19 nov 2020
An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic n
28RISCO
abrir
GitHub PoC10
CVE-2017-3506
CVE-2017-3506HIGHsob ataque18 nov 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-3452HIGHsob ataque18 nov 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHsob ataqueransomware18 nov 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC4
CVE-2020-3452
CVE-2020-3452HIGHsob ataque18 nov 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC2
CVE-2017-10271
CVE-2017-10271HIGHsob ataqueransomware18 nov 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
Exploit-DB
BigBlueButton 2.2.25 - Arbitrary File Disclosure and Server-Side Request Forgery
CVE-2020-25820webappsmultiple18 nov 2020
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploade
28RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-11043HIGHsob ataqueransomware18 nov 2020
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC4
PHP-FPM Remote Command Execution Exploit
CVE-2019-11043HIGHsob ataqueransomware18 nov 2020
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
Metasploit0
Firefox MCallGetProperty Write Side Effects Use After Free Exploit
CVE-2020-2695018 nov 2020
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable
30RISCO
abrir
Exploit-DB
ZeroLogon - Netlogon Elevation of Privilege
CVE-2020-1472MEDIUMsob ataqueransomwareremotewindows18 nov 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
Metasploit600
OpenTSDB 2.4.0 unauthenticated command injection
CVE-2020-3547618 nov 2020
A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. Th
60RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-1721517 nov 2020
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could se
35RISCO
abrir
Exploit-DB
Aerospike Database 5.1.0.3 - OS Command Execution
CVE-2020-13151remotemultiple17 nov 2020
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
60RISCO
abrir
anteriorpágina 721 / 2.611próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.