Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8.846Nuclei 4.361Metasploit 3.490✓ só verificadosrecentespopularesrisco
79.107 exploits
Exploit-DB✓ VexDay Proof
DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expect
50RISCO
abrir ↗VulnCheck XDB
initial-access
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISCO
abrir ↗GitHub PoC★ 11
CVE-2020-5260演示记录
malicious URLs may cause Git to present stored credentials to the wrong server
53RISCO
abrir ↗GitHub PoC
https://bugs.chromium.org/p/project-zero/issues/detail?id=2021
malicious URLs may cause Git to present stored credentials to the wrong server
53RISCO
abrir ↗GitHub PoC★ 37
A HTTP PoC Endpoint for cve-2020-5260 which can be deployed to Heroku
malicious URLs may cause Git to present stored credentials to the wrong server
53RISCO
abrir ↗Metasploit600
Cisco UCS Director Cloupia Script RCE
Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
75RISCO
abrir ↗Metasploit600
Cisco UCS Director Cloupia Script RCE
Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
85RISCO
abrir ↗GitHub PoC★ 4
Vuln Check
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISCO
abrir ↗GitHub PoC★ 6
NVMS 1000 - Directory Traversal Attack Exploit for CVE-2019-20085
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISCO
abrir ↗VulnCheck XDB
infoleak
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x
100RISCO
abrir ↗Metasploit300
Veeam ONE Agent .NET Deserialization
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.
85RISCO
abrir ↗Metasploit300
Veeam ONE Agent .NET Deserialization
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.
75RISCO
abrir ↗Exploit-DB
Oracle WebLogic Server 12.2.1.4.0 - Remote Code Execution
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISCO
abrir ↗GitHub PoC
This tool helps scan large subnets for cve-2020-0796 vulnerable systems
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗GitHub PoC★ 27
patches for SNYK-JS-JQUERY-565129, SNYK-JS-JQUERY-567880, CVE-2020-1102, CVE-2020-11023, includes the patches for SNYK-JS-JQUERY-174006, CVE-2019-11358, CVE-2019-5428
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISCO
abrir ↗VulnCheck XDB
infoleak
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir ↗GitHub PoC
Reproduction of privilege escalation breach CVE-2019-3010
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RISCO
abrir ↗VulnCheck XDB
local
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RISCO
abrir ↗Exploit-DB
MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 a
23RISCO
abrir ↗Exploit-DB
TVT NVMS 1000 - Directory Traversal
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISCO
abrir ↗GitHub PoC★ 19
Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RISCO
abrir ↗VulnCheck XDB
initial-access
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir ↗VulnCheck XDB
local
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RISCO
abrir ↗VulnCheck XDB
client-side
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RISCO
abrir ↗GitHub PoC★ 2
https://bugs.chromium.org/p/project-zero/issues/detail?id=1820
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RISCO
abrir ↗GitHub PoC★ 8
CVE-2018-7600【Drupal7】批量扫描工具。
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗VulnCheck XDB
initial-access
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗GitHub PoC★ 1
Code execution for CVE-2017-11176
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISCO
abrir ↗Metasploit300
Zen Load Balancer Directory Traversal
Monitoring::Logs in Zen Load Balancer 3.10.1 allows remote authenticated admins to conduct absolute path traversal attac
18RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.