Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8.843Nuclei 4.358Metasploit 3.489✓ só verificadosrecentespopularesrisco
79.057 exploits
GitHub PoC
Disables AJP connectors to remediate CVE-2020-1938!
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir ↗Exploit-DB
CMSUno 1.6 - Cross-Site Request Forgery (Change Admin Password)
An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
23RISCO
abrir ↗VulnCheck XDB
denial-of-service
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir ↗GitHub PoC★ 18
Denial of Service PoC for CVE-2020-1350 (SIGRed)
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir ↗GitHub PoC★ 1
Environment for CVE_2019_17571
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be explo
60RISCO
abrir ↗Exploit-DB
Zyxel Armor X1 WAP6806 - Directory Traversal
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
23RISCO
abrir ↗GitHub PoC★ 225
PoC for CVE-2020-6287, CVE-2020-6286 (SAP RECON vulnerability)
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISCO
abrir ↗GitHub PoC★ 237
A denial-of-service proof-of-concept for CVE-2020-1350
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir ↗GitHub PoC
Windows registry mitigation response to CVE-2020-1350
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir ↗GitHub PoC★ 9
Detection of attempts to exploit Microsoft Windows DNS server via CVE-2020-1350 (AKA SIGRed)
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir ↗GitHub PoC★ 15
This Powershell Script is checking if your server is vulnerable for the CVE-2020-1350 Remote Code Execution flaw in the Windows DNS Service
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir ↗GitHub PoC★ 2
ctlyz123/CVE-2020-8193
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RISCO
abrir ↗VulnCheck XDB
denial-of-service
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow
35RISCO
abrir ↗VulnCheck XDB
initial-access
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuratio
38RISCO
abrir ↗VulnCheck XDB
initial-access
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISCO
abrir ↗Exploit-DB
SuperMicro IPMI WebInterface 03.40 - Cross-Site Request Forgery (Add Admin)
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to
23RISCO
abrir ↗GitHub PoC★ 7
Fake exploit tool, designed to rickroll users attempting to actually exploit.
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir ↗Exploit-DB
Trend Micro Web Security Virtual Appliance 6.5 SP2 Patch 4 Build 1901 - Remote Code Execution (Metasploit)
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitr
60RISCO
abrir ↗GitHub PoC★ 4
mr-r3b00t/CVE-2020-1350
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir ↗Exploit-DB
BSA Radar 1.6.7234.24750 - Local File Inclusion
downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and e
23RISCO
abrir ↗GitHub PoC★ 279
HoneyPoC: Proof-of-Concept (PoC) script to exploit SIGRed (CVE-2020-1350). Achieves Domain Admin on Domain Controllers running Windows Server 2000 up to Windows Server 2019.
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir ↗Metasploit600
Apache Airflow 1.10.10 - Example DAG Remote Code Execution
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was disco
100RISCO
abrir ↗Metasploit300
SAP Unauthenticated WebService User Creation
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISCO
abrir ↗Metasploit600
SharePoint DataSet / DataTable Deserialization
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the softwar
100RISCO
abrir ↗Metasploit600
Apache Airflow 1.10.10 - Example DAG Remote Code Execution
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th
100RISCO
abrir ↗VulnCheck XDB
local
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for dif
86RISCO
abrir ↗Metasploit600
Apache OFBiz XML-RPC Java Deserialization
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RISCO
abrir ↗Metasploit600
Apache OFBiz XML-RPC Java Deserialization
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.