Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
79.057 exploits
VulnCheck XDB
initial-access
CVE-2018-289328 jul 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
60RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2020-061027 jul 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
35RISCO
abrir
VulnCheck XDB
local
CVE-2020-9934MEDIUMsob ataque27 jul 2020
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue
78RISCO
abrir
GitHub PoC3
Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API.
CVE-2019-11510CRITICALsob ataqueransomware27 jul 2020
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-19781CRITICALsob ataqueransomware27 jul 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC24
CVE-2020–9934 POC
CVE-2020-9934MEDIUMsob ataque27 jul 2020
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALsob ataqueransomware27 jul 2020
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-11510CRITICALsob ataqueransomware27 jul 2020
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISCO
abrir
GitHub PoC2
Citrix ADC scanner (CVE-2019-19781) using hosts retrieved from Shodan API.
CVE-2019-19781CRITICALsob ataqueransomware27 jul 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC2
This exploit is remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data
CVE-2016-209827 jul 2020
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISCO
abrir
Exploit-DB
Bio Star 2.8.2 - Local File Inclusion
CVE-2020-15050webappsmultiple26 jul 2020
An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary fi
50RISCO
abrir
Exploit-DB
WordPress Plugin Email Subscribers & Newsletters 4.2.2 - Unauthenticated File Download
CVE-2019-19985MEDIUMwebappsphp26 jul 2020
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file downloa
70RISCO
abrir
Exploit-DB
WordPress Plugin Email Subscribers & Newsletters 4.2.2 - 'hash' SQL Injection (Unauthenticated)
CVE-2019-20361HIGHwebappsphp26 jul 2020
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b
78RISCO
abrir
GitHub PoC2
A registry-based workaround can be used to help protect an affected Windows server, and it can be implemented without requiring an administrator to restart the server. Because of the volatility of this vulnerability, administrators may have to implement the workaround before they apply the security update in order to enable them to update their systems by using a standard deployment cadence.
CVE-2020-1350CRITICALsob ataque26 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir
Exploit-DB
Bludit 3.9.2 - Directory Traversal
CVE-2019-16113webappsmultiple26 jul 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISCO
abrir
Exploit-DB
pfSense 2.4.4-p3 - Cross-Site Request Forgery
CVE-2019-16667webappsphp26 jul 2020
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executi
35RISCO
abrir
Exploit-DB
ManageEngine Applications Manager 13 - 'MenuHandlerServlet' SQL Injection
CVE-2016-9488webappsjava26 jul 2020
ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities
23RISCO
abrir
Exploit-DB
F5 Big-IP 13.1.3 Build 0.0.6 - Local File Inclusion
CVE-2020-5902CRITICALsob ataqueransomwarewebappshardware26 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
Exploit-DB
INNEO Startup TOOLS 2018 M040 13.0.70.3804 - Remote Code Execution
CVE-2020-15492webappsmultiple26 jul 2020
An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe we
28RISCO
abrir
Exploit-DB
Rails 5.0.1 - Remote Code Execution
CVE-2020-8163webappsruby26 jul 2020
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
60RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2015-856225 jul 2020
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISCO
abrir
VulnCheck XDB
local
CVE-2020-1054HIGHsob ataque25 jul 2020
Win32k Elevation of Privilege Vulnerability
98RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-3452HIGHsob ataque25 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC20
KaLendsi/CVE-2020-1054
CVE-2020-1054HIGHsob ataque25 jul 2020
Win32k Elevation of Privilege Vulnerability
98RISCO
abrir
GitHub PoC3
Little, stupid python validator(?) for CVE-2020-3452 on CISCO devices.
CVE-2020-3452HIGHsob ataque25 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC
没有编写完成,以后学习更多知识在回来完善
CVE-2015-856225 jul 2020
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISCO
abrir
GitHub PoC2
XDev05/CVE-2020-3452-PoC
CVE-2020-3452HIGHsob ataque24 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC2
unauth file read in cisco asa & firepower.
CVE-2020-3452HIGHsob ataque24 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
Metasploit600
Mida Solutions eFramework ajaxreq.php Command Injection
CVE-2020-1592024 jul 2020
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Executi
60RISCO
abrir
GitHub PoC25
CVE-2020-3452 Cisco ASA Scanner -unauth Path Traversal Check
CVE-2020-3452HIGHsob ataque24 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
anteriorpágina 758 / 2.636próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.