Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8.846Nuclei 4.361Metasploit 3.490✓ só verificadosrecentespopularesrisco
79.107 exploits
GitHub PoC★ 20
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field.
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a
28RISCO
abrir ↗Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer
61RISCO
abrir ↗Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Arch
68RISCO
abrir ↗Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware
48RISCO
abrir ↗GitHub PoC★ 109
quarkslab/CVE-2020-0069_poc
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RISCO
abrir ↗Exploit-DB
UliCMS 2020.1 - Persistent Cross-Site Scripting
UliCMS before 2020.2 has PageController stored XSS.
23RISCO
abrir ↗VulnCheck XDB
local
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RISCO
abrir ↗Exploit-DB
UCM6202 1.0.18.13 - Remote Command Injection
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafte
100RISCO
abrir ↗GitHub PoC
A check for GHOST; cve-2015-0235
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RISCO
abrir ↗Exploit-DB
WordPress Plugin WPForms 1.5.8.2 - Persistent Cross-Site Scripting
A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.
23RISCO
abrir ↗Metasploit600
Grandstream UCM62xx IP PBX sendPasswordEmail RCE
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafte
100RISCO
abrir ↗GitHub PoC★ 6
CVE-2017-12636|exploit Couchdb
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISCO
abrir ↗GitHub PoC★ 1
DoS PoC for CVE-2020-0796 (SMBGhost)
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗VulnCheck XDB
client-side
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap
93RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VMware Fusion 11.5.2 - Privilege Escalation
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for
86RISCO
abrir ↗GitHub PoC★ 3
批量检测幽灵猫漏洞
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir ↗GitHub PoC★ 8
Vulnerability scanner for CVE-2020-0688
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir ↗Metasploit0
Safari in Operator Side Effect Exploit
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, wa
40RISCO
abrir ↗Metasploit0
Safari in Operator Side Effect Exploit
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. An application may be able
18RISCO
abrir ↗Metasploit600
macOS cfprefsd Arbitrary File Write Local Privilege Escalation
A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Cata
18RISCO
abrir ↗Metasploit0
Safari in Operator Side Effect Exploit
A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1.1. A malicious process may ca
18RISCO
abrir ↗GitHub PoC★ 66
An experimental script PoC for Kr00k vulnerability (CVE-2019-15126)
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal
23RISCO
abrir ↗Exploit-DB
Broadcom Wi-Fi Devices - 'KR00K Information Disclosure
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Rconfig 3.x - Chained Remote Code Execution (Metasploit)
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a
60RISCO
abrir ↗VulnCheck XDB
infoleak
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗VulnCheck XDB
infoleak
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir ↗Metasploit600
Vesta Control Panel Authenticated Remote Code Execution
Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint.
40RISCO
abrir ↗VulnCheck XDB
denial-of-service
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗GitHub PoC★ 1
Scanner CVE-2019-0708
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗VulnCheck XDB
initial-access
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.