Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8.843Nuclei 4.358Metasploit 3.489✓ só verificadosrecentespopularesrisco
78.958 exploits
Metasploit600
OpenMediaVault rpc.php Authenticated PHP Code Injection
openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield PO
30RISCO
abrir ↗VulnCheck XDB
denial-of-service
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗Exploit-DB
Joplin 1.0.245 - Arbitrary Code Execution (PoC)
An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
23RISCO
abrir ↗Exploit-DB
Mida eFramework 2.8.9 - Remote Code Execution
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE)
35RISCO
abrir ↗Exploit-DB
MSI Ambient Link Driver 1.0.0.8 - Local Privilege Escalation
The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).
23RISCO
abrir ↗GitHub PoC★ 3
To crash Windows-10 easily
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗VulnCheck XDB
local
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISCO
abrir ↗VulnCheck XDB
local
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
91RISCO
abrir ↗GitHub PoC★ 42
PoCs and technical analysis of three vulnerabilities found on Cisco AnyConnect for Windows: CVE-2020-3433, CVE-2020-3434 and CVE-2020-3435
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
91RISCO
abrir ↗GitHub PoC
CVE 2020-1472 Script de validación
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC
This repository holds the advisory, exploits and vulnerable software of the CVE-2020-15492
An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe we
28RISCO
abrir ↗Metasploit600
HorizontCMS Arbitrary PHP File Upload
An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access
23RISCO
abrir ↗VulnCheck XDB
initial-access
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISCO
abrir ↗GitHub PoC★ 1
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, City
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, o
23RISCO
abrir ↗Exploit-DB
Comodo Unified Threat Management Web Console 2.7.0 - Remote Code Execution
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RISCO
abrir ↗Metasploit600
Micro Focus Operations Bridge Reporter shrboadmin default password
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The
23RISCO
abrir ↗Exploit-DB
BlackCat CMS 1.3.6 - Cross-Site Request Forgery
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote
23RISCO
abrir ↗Exploit-DB
Mida eFramework 2.9.0 - Back Door Access
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restric
28RISCO
abrir ↗GitHub PoC
johnpathe/zerologon-cve-2020-1472-notes
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.