Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
79.107 exploits
GitHub PoC
This Repository use to test Apache Killer (cve-2011-3192).
CVE-2011-319209 abr 2020
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISCO
abrir
Metasploit300
VMware vCenter Server vmdir Information Disclosure
CVE-2020-3952CRITICALsob ataque09 abr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISCO
abrir
Metasploit300
VMware vCenter Server vmdir Authentication Bypass
CVE-2020-3952CRITICALsob ataque09 abr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISCO
abrir
GitHub PoC25
CVE-2020-10199、CVE-2020-10204漏洞一键检测工具,图形化界面。CVE-2020-10199 and CVE-2020-10204 Vul Tool with GUI.
CVE-2020-10199HIGHsob ataque08 abr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISCO
abrir
GitHub PoC35
CVE-2020-10199、CVE-2020-10204、CVE-2020-11444
CVE-2020-10199HIGHsob ataque08 abr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-12149CRITICALsob ataqueransomware08 abr 2020
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir
Exploit-DB
Amcrest Dahua NVR Camera IP2M-841 - Denial of Service (PoC)
CVE-2020-5735HIGHsob ataquedoshardware08 abr 2020
Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacke
83RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-10199HIGHsob ataque08 abr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-20699CRITICALsob ataque08 abr 2020
Cisco Small Business RV Series Routers Vulnerabilities
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-10199HIGHsob ataque07 abr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALsob ataqueransomware07 abr 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC19
CVE-2020-10199 CVE-2020-10204 Python POC
CVE-2020-10199HIGHsob ataque07 abr 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALsob ataqueransomware07 abr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC8
CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本
CVE-2018-7600CRITICALsob ataqueransomware07 abr 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque07 abr 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
VulnCheck XDB
local
CVE-2020-0796CRITICALsob ataqueransomware07 abr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC7
CVE-2020-0796 (SMBGhost) LPE
CVE-2020-0796CRITICALsob ataqueransomware07 abr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
VulnCheck XDB
local
CVE-2019-1609807 abr 2020
The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user t
28RISCO
abrir
GitHub PoC
CVE-2017-10271
CVE-2017-10271HIGHsob ataqueransomware06 abr 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
Exploit-DB
WhatsApp Desktop 0.3.9308 - Persistent Cross-Site Scripting
CVE-2019-18426HIGHsob ataquewebappsmultiple06 abr 2020
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.
83RISCO
abrir
GitHub PoC75
Cobalt Strike AggressorScripts CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware06 abr 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
VulnCheck XDB
local
CVE-2019-1215HIGHsob ataqueransomware06 abr 2020
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Win
76RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHsob ataqueransomware06 abr 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-15133HIGHsob ataque05 abr 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISCO
abrir
GitHub PoC
Known security vulnerabilities detected. CVE-2022-21831 Critical severity CVE-2025-24293 Critical severity CVE-2020-8162 High severity CVE-2024-26144 Moderate severity
CVE-2025-24293CRITICAL05 abr 2020
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote
63RISCO
abrir
GitHub PoC4
XAMPP - CVE-2020-11107
CVE-2020-1110705 abr 2020
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged
28RISCO
abrir
GitHub PoC2
CVE-2020-0688 "Microsoft Exchange default MachineKeySection deserialize vulnerability"
CVE-2020-0688HIGHsob ataqueransomware05 abr 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC6
Laravel-PHP-Unit-RCE (CVE-2018-15133) Auto Exploiter and Shell Uploader
CVE-2018-15133HIGHsob ataque05 abr 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISCO
abrir
GitHub PoC27
PoCs for CVE-2020-11108; an RCE and priv esc in Pi-hole
CVE-2020-1110804 abr 2020
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RISCO
abrir
GitHub PoC1
rhbb/CVE-2019-7609
CVE-2019-7609CRITICALsob ataque03 abr 2020
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir
anteriorpágina 778 / 2.637próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.