Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
79.107 exploits
GitHub PoC106
dozernz/cve-2020-11651
CVE-2020-11651CRITICALsob ataque04 mai 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
GitHub PoC40
CVE-2020-11651: Proof of Concept
CVE-2020-11651CRITICALsob ataque04 mai 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
GitHub PoC5
POC code for CVE-2020-3153 - Cisco anyconnect path traversal vulnerability
CVE-2020-3153MEDIUMsob ataqueransomware04 mai 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RISCO
abrir
GitHub PoC5
CVE-2020-11651&&CVE-2020-11652 EXP
CVE-2020-11651CRITICALsob ataque04 mai 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
GitHub PoC6
PoC for CVE-2020-11651
CVE-2020-11651CRITICALsob ataque04 mai 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
VulnCheck XDB
local
CVE-2018-8639HIGHsob ataqueransomware02 mai 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RISCO
abrir
GitHub PoC
sumedhaDharmasena/-Kernel-ptrace-c-mishandles-vulnerability-CVE-2019-13272
CVE-2019-13272HIGHsob ataque02 mai 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
GitHub PoC
Billith/CVE-2019-5736-PoC
CVE-2019-573601 mai 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
VulnCheck XDB
local
CVE-2019-573601 mai 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC108
Salt security backports for CVE-2020-11651 & CVE-2020-11652
CVE-2020-11651CRITICALsob ataque01 mai 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
GitHub PoC6
Checks for CVE-2020-11651 and CVE-2020-11652
CVE-2020-11651CRITICALsob ataque01 mai 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALsob ataque01 mai 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
Exploit-DBVexDay Proof
Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
CVE-2016-4437CRITICALsob ataqueremotemultiple01 mai 2020
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISCO
abrir
Exploit-DB
Apache OFBiz 17.12.03 - Cross-Site Request Forgery (Account Takeover)
CVE-2019-0235webappsjava01 mai 2020
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
35RISCO
abrir
Metasploit300
SaltStack Salt Master Server Root Key Disclosure
CVE-2020-11652MEDIUMsob ataque30 abr 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-11882HIGHsob ataqueransomware30 abr 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
Metasploit300
WebLogic Server Deserialization RCE BadAttributeValueExpException ExtComp
CVE-2020-2883CRITICALsob ataque30 abr 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHsob ataqueransomware30 abr 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
Metasploit500
SaltStack Salt Master/Minion Unauthenticated RCE
CVE-2020-11651CRITICALsob ataque30 abr 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
Metasploit500
SaltStack Salt Master/Minion Unauthenticated RCE
CVE-2020-11652MEDIUMsob ataque30 abr 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
Metasploit300
SaltStack Salt Master Server Root Key Disclosure
CVE-2020-11651CRITICALsob ataque30 abr 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
Metasploit300
Wordpress LearnPress current_items Authenticated SQLi
CVE-2020-601029 abr 2020
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
50RISCO
abrir
Metasploit600
TP-Link Cloud Cameras NCXXX Bonjour Command Injection
CVE-2020-1210929 abr 2020
Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220
40RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALsob ataque29 abr 2020
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
GitHub PoC1
yukar1z0e/CVE-2018-14847
CVE-2018-14847CRITICALsob ataque29 abr 2020
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
Exploit-DBVexDay Proof
Druva inSync Windows Client 6.5.2 - Local Privilege Escalation
CVE-2019-3999localwindows29 abr 2020
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, u
38RISCO
abrir
Exploit-DBVexDay Proof
Docker-Credential-Wincred.exe - Privilege Escalation (Metasploit)
CVE-2019-15752HIGHsob ataquelocalwindows28 abr 2020
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-c
98RISCO
abrir
Metasploit600
Netsweeper WebAdmin unixlogin.php Python Code Injection
CVE-2020-1316728 abr 2020
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain
40RISCO
abrir
Metasploit600
GOG GalaxyClientService Privilege Escalation
CVE-2020-7352HIGH28 abr 2020
GOG Galaxy GalaxyClientService Privilege Escalation
36RISCO
abrir
Metasploit600
TrixBox CE endpoint_devicemap.php Authenticated Command Execution
CVE-2020-7351HIGH28 abr 2020
Fonality Trixbox CE Post-Authentication Command Injection
48RISCO
abrir
anteriorpágina 774 / 2.637próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.