Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
78.324 exploits
VulnCheck XDB
initial-access
CVE-2020-14883HIGHsob ataque09 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALsob ataque06 nov 2020
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
GitHub PoC48
PoC para las vulnerabilidades CVE-2020-14750 y cve-2020-14882
CVE-2020-14750CRITICALsob ataque06 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC
CVE-2020-0796-POC
CVE-2020-0796CRITICALsob ataqueransomware06 nov 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC
AaronCaiii/CVE-2019-0708-POC
CVE-2019-0708CRITICALsob ataqueransomware06 nov 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-14750CRITICALsob ataque06 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC2
Writeup on CVE-2020-28328: SuiteCRM Log File Remote Code Execution plus some bonus Cross-Site Scripting
CVE-2020-2832806 nov 2020
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain
50RISCO
abrir
GitHub PoC3
CVE-2020-28351 - Reflected Cross-Site Scripting attack in ShoreTel version 19.46.1802.0.
CVE-2020-2835106 nov 2020
The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a r
43RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-0796CRITICALsob ataqueransomware06 nov 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-0708CRITICALsob ataqueransomware06 nov 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
Metasploit300
Abandoned Cart for WooCommerce SQLi Scanner
CVE-2025-47608CRITICAL05 nov 2020
WordPress Recover abandoned cart for WooCommerce plugin <= 2.5 - SQL Injection Vulnerability
43RISCO
abrir
Exploit-DB
TP-Link WDR4300 - Remote Code Execution (Authenticated)
CVE-2017-13772remotehardware05 nov 2020
Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated
35RISCO
abrir
GitHub PoC1
mingchen-script/CVE-2020-1472-visualizer
CVE-2020-1472MEDIUMsob ataqueransomware05 nov 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC3
mmioimm/cve-2020-14882
CVE-2020-14882CRITICALsob ataque05 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
Exploit-DB
Amarok 2.8.0 - Denial-of-Service
CVE-2020-13152localwindows05 nov 2020
A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will tri
23RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-14882CRITICALsob ataque05 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALsob ataque04 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC3
CVE-2020-15999
CVE-2020-15999CRITICALsob ataque04 nov 2020
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploi
90RISCO
abrir
GitHub PoC11
Re-implementation of VirtueSecurity's benigncertain-monitor
CVE-2016-6415HIGHsob ataque04 nov 2020
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x
100RISCO
abrir
Metasploit600
Git Remote Code Execution via git-lfs (CVE-2020-27955)
CVE-2020-2795504 nov 2020
Git LFS 2.12.0 allows Remote Code Execution.
40RISCO
abrir
GitHub PoC19
CVE-2020-14882/14883/14750
CVE-2020-14882CRITICALsob ataque04 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2016-6415HIGHsob ataque04 nov 2020
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x
100RISCO
abrir
GitHub PoC1
CVE-2020-14882 detection script
CVE-2020-14882CRITICALsob ataque03 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
Metasploit600
SaltStack Salt REST API Arbitrary Command Execution
CVE-2020-2559203 nov 2020
In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authent
30RISCO
abrir
Metasploit600
SaltStack Salt REST API Arbitrary Command Execution
CVE-2020-16846CRITICALsob ataque03 nov 2020
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH clien
100RISCO
abrir
GitHub PoC144
CVE-2020-14882_ALL综合利用工具,支持命令回显检测、批量命令回显、外置xml无回显命令执行等功能。
CVE-2020-14882CRITICALsob ataque03 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC13
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a handle to be opened to an arbitrary process.
CVE-2017-976903 nov 2020
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpe
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALsob ataque03 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-14882CRITICALsob ataque03 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-11022MEDIUM02 nov 2020
jQuery has a potential XSS vulnerability
55RISCO
abrir
anteriorpágina 724 / 2.611próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.