Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.039exploits catalogados
36.284CVEs com exploração pública
24.695testados em laboratório
78.343 exploits
GitHub PoC
primebeast/CVE-2019-11932
CVE-2019-1193212 set 2020
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque11 set 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
local
CVE-2015-754711 set 2020
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISCO
abrir
VulnCheck XDB
local
CVE-2015-363611 set 2020
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RISCO
abrir
VulnCheck XDB
local
CVE-2014-6271CRITICALsob ataque11 set 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque11 set 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
1337in/CVE-2020-3187
CVE-2020-3187CRITICAL11 set 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISCO
abrir
Exploit-DBVexDay Proof
CuteNews 2.1.2 - Remote Code Execution
CVE-2019-11447webappsphp10 set 2020
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISCO
abrir
Exploit-DB
ZTE Router F602W - Captcha Bypass
CVE-2020-6862webappshardware10 set 2020
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could lo
23RISCO
abrir
GitHub PoC2
Automatically exploit systems with vulnerable davfs2 (CVE-2013-4362)
CVE-2013-436210 set 2020
WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1
23RISCO
abrir
Metasploit300
WordPress File Manager Unauthenticated Remote Code Execution
CVE-2020-25213CRITICALsob ataque09 set 2020
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir
GitHub PoC
(CVE-2020-5902) BIG IP F5 TMUI RCE Vulnerability RCE PoC/ Test Script
CVE-2020-5902CRITICALsob ataqueransomware09 set 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
Metasploit600
Palo Alto Networks Authenticated Remote Code Execution
CVE-2020-2038HIGH09 set 2020
PAN-OS: OS command injection vulnerability in the management web interface
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-5902CRITICALsob ataqueransomware09 set 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC1.827
Test tool for CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware08 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware08 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
Exploit-DB
ManageEngine Applications Manager 14700 - Remote Code Execution (Authenticated)
CVE-2020-14008webappsjava07 set 2020
Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in
35RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALsob ataque04 set 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALsob ataqueransomware04 set 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-1676303 set 2020
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-1315603 set 2020
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-17496CRITICALsob ataque03 set 2020
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-11043HIGHsob ataqueransomware03 set 2020
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC3
(CVE-2020-17496) vBulletin 5.x Widget_tabbedcontainer_tab_panel RCE Vuln Test script
CVE-2020-17496CRITICALsob ataque03 set 2020
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbe
100RISCO
abrir
GitHub PoC2
This is an updated version of the CVE-2018-16763 for fuelCMS 1.4.1
CVE-2018-1676303 set 2020
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC12
CVE-2017-13156-Janus复现
CVE-2017-1315603 set 2020
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RISCO
abrir
GitHub PoC
Wh1t3Fox/cve-2018-15473
CVE-2018-15473MEDIUM02 set 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
Exploit-DB
Rukovoditel 2.7.1 - Remote Code Execution (2) (Authenticated)
CVE-2020-11819webappsphp02 set 2020
In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve
28RISCO
abrir
GitHub PoC
Use shell to build weblogic debug environment for CVE-2020-2551
CVE-2020-2551CRITICALsob ataque02 set 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISCO
abrir
VulnCheck XDB
local
CVE-2020-1350CRITICALsob ataque02 set 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir
anteriorpágina 734 / 2.612próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.