Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
79.107 exploits
Exploit-DB
BIND - 'TSIG' Denial of Service
CVE-2020-8617HIGHdosmultiple20 mai 2020
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
78RISCO
abrir
GitHub PoC105
Cisco AnyConnect < 4.8.02042 privilege escalation through path traversal
CVE-2020-3153MEDIUMsob ataqueransomware19 mai 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RISCO
abrir
Exploit-DBVexDay Proof
Pi-Hole - heisenbergCompensator Blocklist OS Command Execution (Metasploit)
CVE-2020-11108remotephp19 mai 2020
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHsob ataqueransomware19 mai 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
Exploit-DB
Submitty 20.04.01 - Persistent Cross-Site Scripting
CVE-2020-12882webappsphp19 mai 2020
Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a
23RISCO
abrir
Metasploit300
BIND TSIG Badtime Query Denial of Service
CVE-2020-8617HIGH19 mai 2020
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
78RISCO
abrir
Exploit-DB
Mikrotik Router Monitoring System 1.2.3 - 'community' SQL Injection
CVE-2020-13118webappshardware18 mai 2020
An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community
23RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHsob ataqueransomware18 mai 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
Exploit-DB
HP LinuxKI 6.01 - Remote Command Injection
CVE-2020-7209remotemultiple18 mai 2020
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RISCO
abrir
GitHub PoC
yukar1z0e/CVE-2018-13379
CVE-2018-13379CRITICALsob ataqueransomware18 mai 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-13379CRITICALsob ataqueransomware18 mai 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
GitHub PoC30
Tool to try multiple paths for PHPunit RCE CVE-2017-9841
CVE-2017-9841CRITICALsob ataque18 mai 2020
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALsob ataque18 mai 2020
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir
Exploit-DB
Oracle Hospitality RES 3700 5.7 - Remote Code Execution
CVE-2019-3025webappsjava18 mai 2020
Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Food and Beverage Applications. The supported versi
28RISCO
abrir
GitHub PoC
TelerikUI Vulnerability Scanner (CVE-2019-18935)
CVE-2019-18935CRITICALsob ataqueransomware17 mai 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-18935CRITICALsob ataqueransomware17 mai 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir
Metasploit600
LinuxKI Toolset 6.01 Remote Command Execution
CVE-2020-720917 mai 2020
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RISCO
abrir
VulnCheck XDB
local
CVE-2018-0802HIGHsob ataqueransomware17 mai 2020
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-2883CRITICALsob ataque16 mai 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISCO
abrir
GitHub PoC89
Weblogic Vuln POC EXP cve-2020-2551 cve-2020-2555 cve-2020-2883 ,。。。
CVE-2020-2551CRITICALsob ataque16 mai 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISCO
abrir
GitHub PoC
CVE-2018-10933_Scanner
CVE-2018-10933CRITICAL15 mai 2020
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC
cdedmondson/Modified-CVE-2015-3306-Exploit
CVE-2015-330615 mai 2020
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1280015 mai 2020
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Uploa
60RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-10199HIGHsob ataque15 mai 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISCO
abrir
Metasploit600
Plesk/myLittleAdmin ViewState .NET Deserialization
CVE-2020-1316615 mai 2020
The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcod
60RISCO
abrir
VulnCheck XDB
local
CVE-2020-3153MEDIUMsob ataqueransomware15 mai 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RISCO
abrir
GitHub PoC
PoC for CVE-2020-3153 Cisco AnyConnect Secure Mobility Client EoP
CVE-2020-3153MEDIUMsob ataqueransomware15 mai 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RISCO
abrir
GitHub PoC31
CVE-2020-10199 回显版本
CVE-2020-10199HIGHsob ataque15 mai 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-0193HIGHsob ataque14 mai 2020
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISCO
abrir
GitHub PoC
ES File Explorer Open Port Vulnerability - CVE-2019-6447
CVE-2019-644714 mai 2020
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISCO
abrir
anteriorpágina 770 / 2.637próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.