Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
78.958 exploits
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALsob ataqueransomware07 out 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-12615HIGHsob ataqueransomware07 out 2020
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2016-3088CRITICALsob ataque06 out 2020
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-999506 out 2020
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
Exploit-DB
SpamTitan 7.07 - Unauthenticated Remote Code Execution
CVE-2020-11698webappsphp05 out 2020
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHsob ataqueransomware05 out 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHsob ataqueransomware05 out 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALsob ataque05 out 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALsob ataque05 out 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALsob ataqueransomware04 out 2020
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALsob ataqueransomware04 out 2020
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALsob ataqueransomware04 out 2020
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir
Metasploit300
SAP Solution Manager remote unauthorized OS commands execution
CVE-2020-6207CRITICALsob ataque03 out 2020
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RISCO
abrir
Metasploit300
SAP Solution Manager remote unauthorized OS commands execution
CVE-2020-6207CRITICALsob ataque03 out 2020
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2018-239202 out 2020
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML Exter
50RISCO
abrir
GitHub PoC2
coldfusion exploit based on https://cvedetails.com/cve/CVE-2009-2265/
CVE-2009-226502 out 2020
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISCO
abrir
GitHub PoC2
Protect your domain controllers against Zerologon (CVE-2020-1472).
CVE-2020-1472MEDIUMsob ataqueransomware30 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC5
CVE-2019-18935
CVE-2019-18935CRITICALsob ataqueransomware30 set 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir
GitHub PoC
Ken-Abruzzi/CVE-2020-0674
CVE-2020-0674HIGHsob ataque30 set 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware30 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-0674HIGHsob ataque30 set 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISCO
abrir
GitHub PoC
Ken-Abruzzi/cve-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware30 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC11
POC for checking multiple hosts for Zerologon vulnerability
CVE-2020-1472MEDIUMsob ataqueransomware29 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware29 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware29 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC22
Zerologon AutoExploit Tool | CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware29 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
Exploit-DB
MSI Ambient Link Driver 1.0.0.8 - Local Privilege Escalation
CVE-2020-17382localwindows28 set 2020
The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).
23RISCO
abrir
GitHub PoC
Fa1c0n35/CVE-2020-1472-02-
CVE-2020-1472MEDIUMsob ataqueransomware28 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
Exploit-DB
Mida eFramework 2.8.9 - Remote Code Execution
CVE-2020-15922webappshardware28 set 2020
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE)
35RISCO
abrir
GitHub PoC3
To crash Windows-10 easily
CVE-2020-0796CRITICALsob ataqueransomware28 set 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
anteriorpágina 746 / 2.632próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.