Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
79.107 exploits
VulnCheck XDB
initial-access
CVE-2020-2551CRITICALsob ataque02 mar 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISCO
abrir
Exploit-DB
Joplin Desktop 1.0.184 - Cross-Site Scripting
CVE-2020-9038webappsmultiple02 mar 2020
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
23RISCO
abrir
Exploit-DB
CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow
CVE-2020-8012remotewindows02 mar 2020
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerabi
60RISCO
abrir
GitHub PoC1
CVE-2019-5096(UAF in upload handler) exploit cause Denial of Service
CVE-2019-5096CRITICAL02 mar 2020
An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base Go
60RISCO
abrir
Exploit-DB
Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution
CVE-2020-0688HIGHsob ataqueransomwareremotewindows02 mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
Metasploit600
SharePoint Workflows XOML Injection
CVE-2020-0646CRITICALsob ataque02 mar 2020
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.N
100RISCO
abrir
Exploit-DB
TP LINK TL-WR849N - Remote Code Execution
CVE-2020-9374webappshardware02 mar 2020
On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploit
35RISCO
abrir
GitHub PoC132
CVE-2020-2546,CVE-2020-2915 CVE-2020-2801 CVE-2020-2798 CVE-2020-2883 CVE-2020-2884 CVE-2020-2950 WebLogic T3 payload exploit poc python3,
CVE-2020-2546CRITICAL02 mar 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - Java
48RISCO
abrir
Exploit-DB
WordPress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
CVE-2020-8615webappsphp02 mar 2020
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves a
38RISCO
abrir
GitHub PoC6
CVE-2020-1938(GhostCat) clean and readable code version
CVE-2020-1938CRITICALsob ataque01 mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALsob ataque01 mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC354
Exploit and detect tools for CVE-2020-0688
CVE-2020-0688HIGHsob ataqueransomware01 mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC11
HumanSecurity/CVE-2019-18426
CVE-2019-18426HIGHsob ataque29 fev 2020
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.
83RISCO
abrir
VulnCheck XDB
client-side
CVE-2019-18426HIGHsob ataque29 fev 2020
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.
83RISCO
abrir
GitHub PoC1
I made this script for conducting CVE-2020-0688 more rapidly. It helps to improve checking the vuln, reducing hugely steps for that
CVE-2020-0688HIGHsob ataqueransomware28 fev 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC37
Quick tool for checking CVE-2020-0688 on multiple hosts with a non-intrusive method.
CVE-2020-0688HIGHsob ataqueransomware28 fev 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC10
CVE-2020-0688
CVE-2020-0688HIGHsob ataqueransomware28 fev 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-2551CRITICALsob ataque28 fev 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISCO
abrir
Exploit-DB
qdPM < 9.1 - Remote Code Execution
CVE-2020-7246webappsmultiple28 fev 2020
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir
GitHub PoC337
Weblogic IIOP CVE-2020-2551
CVE-2020-2551CRITICALsob ataque28 fev 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-6418HIGHsob ataque27 fev 2020
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHsob ataqueransomware27 fev 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHsob ataqueransomware27 fev 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC5
Disclosure report of CVE-2020-9038
CVE-2020-903827 fev 2020
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
23RISCO
abrir
GitHub PoC144
CVE-2020-0688_EXP Auto trigger payload & encrypt method
CVE-2020-0688HIGHsob ataqueransomware27 fev 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC328
cve-2020-0688
CVE-2020-0688HIGHsob ataqueransomware27 fev 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC2
Exchange Scanner CVE-2020-0688
CVE-2020-0688HIGHsob ataqueransomware27 fev 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC
Materials for the second Rijeka secuity meetup. We will be discussing Microsoft cryptoapi vulnerability dubbed CurveBall (CVE-2020-0601)
CVE-2020-0601HIGHsob ataque26 fev 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC66
CVE-2020-0688 - Exchange
CVE-2020-0688HIGHsob ataqueransomware26 fev 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC1
Learnings on how to verify if vulnerable to Ghostcat (aka CVE-2020-1938)
CVE-2020-1938CRITICALsob ataque26 fev 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
anteriorpágina 786 / 2.637próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.