Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
79.057 exploits
GitHub PoC5
ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and application termination via a malformed payload.
CVE-2020-1595604 ago 2020
ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer
28RISCO
abrir
GitHub PoC11
Pi-hole Remote Code Execution authenticated Version >= 4.3.2
CVE-2020-8816CRITICALsob ataque04 ago 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RISCO
abrir
GitHub PoC1
CVE-2020-3452 - directory traversal in Cisco ASA and Cisco Firepower Threat Defense
CVE-2020-3452HIGHsob ataque03 ago 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-3452HIGHsob ataque03 ago 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-398003 ago 2020
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to
23RISCO
abrir
GitHub PoC
Checks a list of SSH servers for password-based auth availability and for the existence of SSH user enumeration vulnerability (CVE-2018-15473) in those identified.
CVE-2018-15473MEDIUM03 ago 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC
修改IP地址即可实现命令执行
CVE-2017-804601 ago 2020
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-804601 ago 2020
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2020-1350CRITICALsob ataque01 ago 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-3452HIGHsob ataque01 ago 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC42
POC for CVE-2020-13151
CVE-2020-1315101 ago 2020
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
60RISCO
abrir
GitHub PoC24
CVE-2020-3452 exploit
CVE-2020-3452HIGHsob ataque01 ago 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-8174HIGHsob ataqueransomware31 jul 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
GitHub PoC
ericisnotrealname/CVE-2018-8174_EXP
CVE-2018-8174HIGHsob ataqueransomware31 jul 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
GitHub PoC15
ActiveMQ_putshell直接获取webshell
CVE-2016-3088CRITICALsob ataque31 jul 2020
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2016-3088CRITICALsob ataque31 jul 2020
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISCO
abrir
Metasploit500
Aerospike Database UDF Lua Code Execution
CVE-2020-1315131 jul 2020
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-19781CRITICALsob ataqueransomware30 jul 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC7
Shitrix : CVE-2019-19781 - Remote Code Execution on Citrix ADC Netscaler exploit
CVE-2019-19781CRITICALsob ataqueransomware30 jul 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC1
Simple detection tool for Blueborne vulnerability found on Android devices --- CVE-2017-0781.
CVE-2017-078130 jul 2020
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RISCO
abrir
Exploit-DB
Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
CVE-2020-3187CRITICALwebappshardware29 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISCO
abrir
GitHub PoC
CVE-2020-3452 : Cisco ASA and FTD Unauthorized Remote File Reading Nmap NSE Script
CVE-2020-3452HIGHsob ataque29 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
Exploit-DB
Wordpress Plugin Maintenance Mode by SeedProd 5.1.1 - Persistent Cross-Site Scripting
CVE-2020-15038webappsphp29 jul 2020
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
23RISCO
abrir
VulnCheck XDB
local
CVE-2020-1071329 jul 2020
A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB veri
23RISCO
abrir
Exploit-DB
Cisco Adaptive Security Appliance Software 9.11 - Local File Inclusion
CVE-2020-3452HIGHsob ataquewebappshardware28 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-3452HIGHsob ataque28 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC
Better version of rastating.github.io/bludit-brute-force-mitigation-bypass/
CVE-2019-17240LOW28 jul 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISCO
abrir
GitHub PoC1
环境下载
CVE-2020-14645CRITICAL28 jul 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RISCO
abrir
GitHub PoC1
CrackerCat/CVE-2020-3187
CVE-2020-3187CRITICAL28 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISCO
abrir
GitHub PoC4
A network detection package for CVE-2020-5902, a CVE10.0 vulnerability affecting F5 Networks, Inc BIG-IP devices.
CVE-2020-5902CRITICALsob ataqueransomware28 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
anteriorpágina 757 / 2.636próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.