Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8.846Nuclei 4.361Metasploit 3.490✓ só verificadosrecentespopularesrisco
79.107 exploits
VulnCheck XDB
initial-access
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗VulnCheck XDB
initial-access
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pi-hole 4.4.0 - Remote Code Execution (Authenticated)
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RISCO
abrir ↗GitHub PoC
yukar1z0e/CVE-2019-19781
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗GitHub PoC
gothburz/cve-2020-8617
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
78RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Plesk/myLittleAdmin - ViewState .NET Deserialization (Metasploit)
The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcod
60RISCO
abrir ↗GitHub PoC★ 12
TelerikUI Vulnerability Scanner (CVE-2019-18935)
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
35RISCO
abrir ↗VulnCheck XDB
initial-access
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir ↗VulnCheck XDB
initial-access
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Synology DiskStation Manager - smart.cgi Remote Command Execution (Metasploit)
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authe
60RISCO
abrir ↗GitHub PoC★ 22
CVE-2020-2551 POC to use in Internet
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISCO
abrir ↗GitHub PoC★ 87
QNAP pre-auth root RCE Exploit (CVE-2019-7192 ~ CVE-2019-7195)
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix the
100RISCO
abrir ↗VulnCheck XDB
infoleak
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix the
100RISCO
abrir ↗VulnCheck XDB
initial-access
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir ↗GitHub PoC★ 1
vulnerabilidad CVE-2019-0708 testing y explotacion
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗GitHub PoC★ 5
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS)
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebLogic Server - Deserialization RCE - BadAttributeValueExpException (Metasploit)
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISCO
abrir ↗Metasploit300
Documalis Free PDF Editor and Scanner JPEG Stack Buffer Overflow
Documalis Free PDF Editor / Free PDF Scanner Stack Based Buffer Overflow
28RISCO
abrir ↗GitHub PoC
saltstack CVE-2020-11652
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir ↗GitHub PoC
HKirito/phpmyadmin4.4_cve-2016-5734
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Druva inSync Windows Client 6.6.3 - Local Privilege Escalation
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RISCO
abrir ↗GitHub PoC★ 2
CVE-2017-17485:Jackson-databind RCE
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o
60RISCO
abrir ↗VulnCheck XDB
initial-access
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir ↗VulnCheck XDB
initial-access
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir ↗Exploit-DB
OpenEDX platform Ironwood 2.5 - Remote Code Execution
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>Ne
28RISCO
abrir ↗GitHub PoC★ 13
Checker for QNAP pre-auth root RCE (CVE-2019-7192 ~ CVE-2019-7195)
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix the
100RISCO
abrir ↗Exploit-DB
BIND - 'TSIG' Denial of Service
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
78RISCO
abrir ↗GitHub PoC★ 45
PoC for CVE-2020-8617 (BIND)
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
78RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.