Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
79.107 exploits
GitHub PoC20
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field.
CVE-2020-937525 mar 2020
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a
28RISCO
abrir
Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
CVE-2020-10884HIGH25 mar 2020
This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer
61RISCO
abrir
Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
CVE-2020-10882HIGH25 mar 2020
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Arch
68RISCO
abrir
Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
CVE-2020-10883MEDIUM25 mar 2020
This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware
48RISCO
abrir
GitHub PoC109
quarkslab/CVE-2020-0069_poc
CVE-2020-0069HIGHsob ataque24 mar 2020
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RISCO
abrir
Exploit-DB
UliCMS 2020.1 - Persistent Cross-Site Scripting
CVE-2020-12704webappsphp24 mar 2020
UliCMS before 2020.2 has PageController stored XSS.
23RISCO
abrir
VulnCheck XDB
local
CVE-2020-0069HIGHsob ataque24 mar 2020
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RISCO
abrir
Exploit-DB
UCM6202 1.0.18.13 - Remote Command Injection
CVE-2020-5722CRITICALsob ataquewebappshardware24 mar 2020
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafte
100RISCO
abrir
GitHub PoC
A check for GHOST; cve-2015-0235
CVE-2015-023524 mar 2020
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RISCO
abrir
Exploit-DB
WordPress Plugin WPForms 1.5.8.2 - Persistent Cross-Site Scripting
CVE-2020-10385webappsphp24 mar 2020
A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.
23RISCO
abrir
Metasploit600
Grandstream UCM62xx IP PBX sendPasswordEmail RCE
CVE-2020-5722CRITICALsob ataque23 mar 2020
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafte
100RISCO
abrir
GitHub PoC6
CVE-2017-12636|exploit Couchdb
CVE-2017-1263623 mar 2020
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISCO
abrir
GitHub PoC1
DoS PoC for CVE-2020-0796 (SMBGhost)
CVE-2020-0796CRITICALsob ataqueransomware21 mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2019-13720HIGHsob ataque21 mar 2020
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap
93RISCO
abrir
Exploit-DBVexDay Proof
VMware Fusion 11.5.2 - Privilege Escalation
CVE-2020-3950HIGHsob ataquelocalmacos20 mar 2020
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for
86RISCO
abrir
GitHub PoC3
批量检测幽灵猫漏洞
CVE-2020-1938CRITICALsob ataque20 mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC8
Vulnerability scanner for CVE-2020-0688
CVE-2020-0688HIGHsob ataqueransomware19 mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
Metasploit0
Safari in Operator Side Effect Exploit
CVE-2020-985018 mar 2020
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, wa
40RISCO
abrir
Metasploit0
Safari in Operator Side Effect Exploit
CVE-2020-985618 mar 2020
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. An application may be able
18RISCO
abrir
Metasploit600
macOS cfprefsd Arbitrary File Write Local Privilege Escalation
CVE-2020-983918 mar 2020
A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Cata
18RISCO
abrir
Metasploit0
Safari in Operator Side Effect Exploit
CVE-2020-980118 mar 2020
A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1.1. A malicious process may ca
18RISCO
abrir
GitHub PoC66
An experimental script PoC for Kr00k vulnerability (CVE-2019-15126)
CVE-2019-1512618 mar 2020
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal
23RISCO
abrir
Exploit-DB
Broadcom Wi-Fi Devices - 'KR00K Information Disclosure
CVE-2019-15126remotemultiple18 mar 2020
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal
23RISCO
abrir
Exploit-DBVexDay Proof
Rconfig 3.x - Chained Remote Code Execution (Metasploit)
CVE-2019-19509remotelinux17 mar 2020
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-0708CRITICALsob ataqueransomware17 mar 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALsob ataque17 mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
Metasploit600
Vesta Control Panel Authenticated Remote Code Execution
CVE-2020-1080817 mar 2020
Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint.
40RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALsob ataqueransomware17 mar 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC1
Scanner CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware17 mar 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALsob ataqueransomware17 mar 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
anteriorpágina 781 / 2.637próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.