Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8.846Nuclei 4.361Metasploit 3.490✓ só verificadosrecentespopularesrisco
79.107 exploits
GitHub PoC★ 9
CVE-2020-0796 Flaw Mitigation - Active Directory Administrative Templates
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗GitHub PoC★ 162
NSE scripts to detect CVE-2020-1350 SIGRED and CVE-2020-0796 SMBGHOST, CVE-2021-21972, proxyshell, CVE-2021-34473
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir ↗GitHub PoC★ 14
Script that checks if the system is vulnerable to CVE-2020-0796 (SMB v3.1.1)
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗GitHub PoC★ 18
Weaponized PoC for SMBv3 TCP codec/compression vulnerability
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗Exploit-DB
Horde Groupware Webmail Edition 5.2.22 - Remote Code Execution
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execu
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Nagios XI - Authenticated Remote Command Execution (Metasploit)
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RISCO
abrir ↗GitHub PoC★ 14
CVE-2020-2555
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISCO
abrir ↗Metasploit600
Background Intelligent Transfer Service Arbitrary File Move Privilege Elevation Vulnerability
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISCO
abrir ↗Metasploit300
CVE-2020-1170 Cloud Filter Arbitrary File Creation EOP
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
41RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome 80 - JSCreate Side-effect Type Confusion (Metasploit)
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome 67_ 68 and 69 - Object.create Type Confusion (Metasploit)
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome 72 and 73 - Array.map Out-of-Bounds Write (Metasploit)
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploi
90RISCO
abrir ↗GitHub PoC★ 1
exploit for sudo CVE-2019-18634
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir ↗Metasploit600
Pandora FMS Ping Authenticated Remote Code Execution
Pandora FMS Authenticated Remote Code Execution via Ping Module
36RISCO
abrir ↗GitHub PoC★ 13
PoC of CVE-2019-15126 kr00k vulnerability
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSMTPD - OOB Read Local Privilege Escalation (Metasploit)
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for mult
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-FPM - Underflow Remote Code Execution (Metasploit)
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache ActiveMQ 5.x-5.11.1 - Directory Traversal Shell Upload (Metasploit)
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5
60RISCO
abrir ↗VulnCheck XDB
infoleak
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗GitHub PoC★ 1
Gather a list of Citrix appliances in a country / state pair, and check if they're vulnerable to CVE-2019-19781
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗GitHub PoC★ 177
Weblogic com.tangosol.util.extractor.ReflectionExtractor RCE
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISCO
abrir ↗GitHub PoC
simple poc for CVE-2020-0069
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RISCO
abrir ↗GitHub PoC★ 47
CVE-2020-8597 pppd buffer overflow poc
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RISCO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir ↗VulnCheck XDB
client-side
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir ↗VulnCheck XDB
initial-access
Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.
28RISCO
abrir ↗GitHub PoC★ 6
A CVE-2019-11580 shell
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RISCO
abrir ↗GitHub PoC
CVE-2020-8597
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RISCO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.