Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
78.331 exploits
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALsob ataque14 set 2020
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware14 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC179
Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.
CVE-2020-1472MEDIUMsob ataqueransomware14 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC38
cube0x0/CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware14 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware14 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-1472MEDIUMsob ataqueransomware14 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware14 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC397
Exploit Code for CVE-2020-1472 aka Zerologon
CVE-2020-1472MEDIUMsob ataqueransomware14 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC1.316
PoC for Zerologon - all research credits go to Tom Tervoort of Secura
CVE-2020-1472MEDIUMsob ataqueransomware14 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC705
Exploit for zerologon cve-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware14 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-21307HIGH13 set 2020
Remote Code Exploit in Lucee Admin
78RISCO
abrir
GitHub PoC7
CVE-2019-15107 exploit
CVE-2019-15107CRITICALsob ataqueransomware13 set 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-5902CRITICALsob ataqueransomware13 set 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-15505CRITICALsob ataque13 set 2020
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1,
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALsob ataqueransomware13 set 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALsob ataqueransomware13 set 2020
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALsob ataqueransomware13 set 2020
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
GitHub PoC
primebeast/CVE-2019-11932
CVE-2019-1193212 set 2020
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
Metasploit600
MobileIron MDM Hessian-Based Java Deserialization RCE
CVE-2020-15505CRITICALsob ataque12 set 2020
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1,
100RISCO
abrir
VulnCheck XDB
local
CVE-2015-363611 set 2020
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque11 set 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque11 set 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
local
CVE-2014-6271CRITICALsob ataque11 set 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
local
CVE-2015-754711 set 2020
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISCO
abrir
GitHub PoC
1337in/CVE-2020-3187
CVE-2020-3187CRITICAL11 set 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISCO
abrir
Exploit-DBVexDay Proof
CuteNews 2.1.2 - Remote Code Execution
CVE-2019-11447webappsphp10 set 2020
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISCO
abrir
Exploit-DB
ZTE Router F602W - Captcha Bypass
CVE-2020-6862webappshardware10 set 2020
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could lo
23RISCO
abrir
GitHub PoC2
Automatically exploit systems with vulnerable davfs2 (CVE-2013-4362)
CVE-2013-436210 set 2020
WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1
23RISCO
abrir
Metasploit600
Palo Alto Networks Authenticated Remote Code Execution
CVE-2020-2038HIGH09 set 2020
PAN-OS: OS command injection vulnerability in the management web interface
78RISCO
abrir
Metasploit300
WordPress File Manager Unauthenticated Remote Code Execution
CVE-2020-25213CRITICALsob ataque09 set 2020
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir
anteriorpágina 733 / 2.612próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.