Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
78.958 exploits
Exploit-DB
Apache OpenMeetings 5.0.0 - 'hostname' Denial of Service
CVE-2020-13951webappsmultiple24 nov 2020
Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.
45RISCO
abrir
Exploit-DBVexDay Proof
ZeroShell 3.9.0 - 'cgi-bin/kerbynet' Remote Root Command Injection (Metasploit)
CVE-2019-12725webappslinux24 nov 2020
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir
GitHub PoC1
www201001/https-github.com-iBearcat-CVE-2018-8174_EXP
CVE-2018-8174HIGHsob ataqueransomware24 nov 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
GitHub PoC1
www201001/https-github.com-iBearcat-CVE-2018-8174_EXP.git-
CVE-2018-8174HIGHsob ataqueransomware24 nov 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
Exploit-DB
LifeRay 7.2.1 GA2 - Stored XSS
CVE-2020-7934webappsmultiple23 nov 2020
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyA
23RISCO
abrir
Exploit-DB
TP-Link TL-WA855RE V5_200415 - Device Reset Auth Bypass
CVE-2020-24363HIGHsob ataquewebappshardware23 nov 2020
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP
76RISCO
abrir
GitHub PoC
1stPeak/CVE-2018-15473
CVE-2018-15473MEDIUM23 nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC1
This container was made to explain and demonstrate how CVE-2019-15813 (Sentrifugo works)
CVE-2019-1581322 nov 2020
Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arb
35RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALsob ataqueransomware22 nov 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
Metasploit600
qdPM 9.1 Authenticated Arbitrary PHP File Upload (RCE)
CVE-2020-724621 nov 2020
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-11043HIGHsob ataqueransomware21 nov 2020
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1394221 nov 2020
Remote Code Execution in Apache Unomi
50RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1394220 nov 2020
Remote Code Execution in Apache Unomi
50RISCO
abrir
GitHub PoC2
MasterSploit/LPE---CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware20 nov 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
VulnCheck XDB
local
CVE-2020-0796CRITICALsob ataqueransomware20 nov 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC6
FortiVuln
CVE-2018-13379CRITICALsob ataqueransomware19 nov 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
Exploit-DB
Gemtek WVRTM-127ACN 01.01.02.141 - Authenticated Arbitrary Command Injection
CVE-2020-24365webappscgi19 nov 2020
An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic n
28RISCO
abrir
Metasploit0
Google Chrome versions before 87.0.4280.88 integer overflow during SimplfiedLowering phase
CVE-2020-1604019 nov 2020
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RISCO
abrir
Exploit-DB
xuucms 3 - 'keywords' SQL Injection
CVE-2020-28091webappsmultiple19 nov 2020
cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parame
23RISCO
abrir
Exploit-DB
PESCMS TEAM 2.3.2 - Multiple Reflected XSS
CVE-2020-28092webappsmultiple19 nov 2020
PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&s
23RISCO
abrir
Exploit-DB
Fortinet FortiOS 6.0.4 - Unauthenticated SSL VPN User Password Modification
CVE-2018-13382CRITICALsob ataqueransomwarewebappshardware19 nov 2020
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2018-13379CRITICALsob ataqueransomware19 nov 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHsob ataqueransomware18 nov 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC4
CVE-2020-3452
CVE-2020-3452HIGHsob ataque18 nov 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC2
CVE-2017-10271
CVE-2017-10271HIGHsob ataqueransomware18 nov 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-3452HIGHsob ataque18 nov 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
Exploit-DB
BigBlueButton 2.2.25 - Arbitrary File Disclosure and Server-Side Request Forgery
CVE-2020-25820webappsmultiple18 nov 2020
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploade
28RISCO
abrir
Exploit-DB
ZeroLogon - Netlogon Elevation of Privilege
CVE-2020-1472MEDIUMsob ataqueransomwareremotewindows18 nov 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC10
CVE-2017-3506
CVE-2017-3506HIGHsob ataque18 nov 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
GitHub PoC4
PHP-FPM Remote Command Execution Exploit
CVE-2019-11043HIGHsob ataqueransomware18 nov 2020
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
anteriorpágina 738 / 2.632próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.