Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
78.958 exploits
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware28 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
Metasploit600
OpenMediaVault rpc.php Authenticated PHP Code Injection
CVE-2020-2612428 set 2020
openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield PO
30RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALsob ataqueransomware28 set 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
Exploit-DB
Joplin 1.0.245 - Arbitrary Code Execution (PoC)
CVE-2020-15930webappsmultiple28 set 2020
An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
23RISCO
abrir
Exploit-DB
Mida eFramework 2.8.9 - Remote Code Execution
CVE-2020-15922webappshardware28 set 2020
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE)
35RISCO
abrir
Exploit-DB
MSI Ambient Link Driver 1.0.0.8 - Local Privilege Escalation
CVE-2020-17382localwindows28 set 2020
The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).
23RISCO
abrir
GitHub PoC3
To crash Windows-10 easily
CVE-2020-0796CRITICALsob ataqueransomware28 set 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC
CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware28 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
Fa1c0n35/CVE-2020-1472-02-
CVE-2020-1472MEDIUMsob ataqueransomware28 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC5
striveben/CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware26 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware26 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque25 set 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
VulnCheck XDB
local
CVE-2019-0808HIGHsob ataque25 set 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISCO
abrir
VulnCheck XDB
local
CVE-2020-3433HIGHsob ataqueransomware25 set 2020
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
91RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware25 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC42
PoCs and technical analysis of three vulnerabilities found on Cisco AnyConnect for Windows: CVE-2020-3433, CVE-2020-3434 and CVE-2020-3435
CVE-2020-3433HIGHsob ataqueransomware25 set 2020
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
91RISCO
abrir
GitHub PoC
CVE 2020-1472 Script de validación
CVE-2020-1472MEDIUMsob ataqueransomware24 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
This repository holds the advisory, exploits and vulnerable software of the CVE-2020-15492
CVE-2020-1549224 set 2020
An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe we
28RISCO
abrir
Metasploit600
HorizontCMS Arbitrary PHP File Upload
CVE-2020-2738724 set 2020
An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-12617HIGHsob ataque23 set 2020
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISCO
abrir
GitHub PoC1
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, City
CVE-2020-2527023 set 2020
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, o
23RISCO
abrir
Exploit-DB
Comodo Unified Threat Management Web Console 2.7.0 - Remote Code Execution
CVE-2018-17431webappsmultiple22 set 2020
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RISCO
abrir
Metasploit600
Micro Focus Operations Bridge Reporter shrboadmin default password
CVE-2020-1185721 set 2020
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The
23RISCO
abrir
Exploit-DB
BlackCat CMS 1.3.6 - Cross-Site Request Forgery
CVE-2020-25453webappsphp21 set 2020
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote
23RISCO
abrir
GitHub PoC
t31m0/CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware21 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
Exploit-DB
Mida eFramework 2.9.0 - Back Door Access
CVE-2020-15921webappshardware21 set 2020
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restric
28RISCO
abrir
VulnCheck XDB
local
CVE-2020-1048HIGH21 set 2020
Windows Print Spooler Elevation of Privilege Vulnerability
61RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware21 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
johnpathe/zerologon-cve-2020-1472-notes
CVE-2020-1472MEDIUMsob ataqueransomware20 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
hectorgie/CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware19 set 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
anteriorpágina 747 / 2.632próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.