Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
79.107 exploits
Exploit-DB
OpenSMTPD < 6.6.3p1 - Local Privilege Escalation + Remote Code Execution
CVE-2020-8794remoteopenbsd26 fev 2020
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for mult
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-0601HIGHsob ataque26 fev 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
Exploit-DB
OpenSMTPD 6.6.3 - Arbitrary File Read
CVE-2020-8793remotelinux26 fev 2020
OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combi
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-15133HIGHsob ataque25 fev 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISCO
abrir
GitHub PoC
cve-2015-3306 docker image
CVE-2015-330625 fev 2020
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir
GitHub PoC163
cve-2020-0688
CVE-2020-0688HIGHsob ataqueransomware25 fev 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
Metasploit600
Druva inSync inSyncCPHwnet64.exe RPC Type 5 Privilege Escalation
CVE-2019-399925 fev 2020
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, u
38RISCO
abrir
Metasploit600
Druva inSync inSyncCPHwnet64.exe RPC Type 5 Privilege Escalation
CVE-2020-575225 fev 2020
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RISCO
abrir
GitHub PoC
Cette exploit en python va vous permettre de créer des listes de sites et les exploiter rapidement.
CVE-2018-15133HIGHsob ataque25 fev 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISCO
abrir
Exploit-DB
ManageEngine EventLog Analyzer 10.0 - Information Disclosure
CVE-2019-19774webappsjava24 fev 2020
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetai
28RISCO
abrir
Exploit-DBVexDay Proof
Android Binder - Use-After-Free (Metasploit)
CVE-2019-2215HIGHsob ataquelocalandroid24 fev 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
Metasploit200
OpenSMTPD OOB Read Local Privilege Escalation
CVE-2020-879424 fev 2020
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for mult
60RISCO
abrir
Exploit-DB
Avaya IP Office Application Server 11.0.0.0 - Reflective Cross-Site Scripting
CVE-2019-7004MEDIUMwebappshardware24 fev 2020
Avaya IP Office XSS Vulnerability
33RISCO
abrir
Exploit-DBVexDay Proof
Apache James Server 2.3.2 - Insecure User Creation Arbitrary File Write (Metasploit)
CVE-2015-7611remotelinux24 fev 2020
Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary syst
50RISCO
abrir
Exploit-DB
Go SSH servers 0.0.2 - Denial of Service (PoC)
CVE-2020-9283doslinux24 fev 2020
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the
28RISCO
abrir
VulnCheck XDB
local
CVE-2014-0160HIGHsob ataque23 fev 2020
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1938CRITICALsob ataque22 fev 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC6
PoC exploit for CVE-2015-2291
CVE-2015-2291HIGHsob ataqueransomware22 fev 2020
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISCO
abrir
GitHub PoC3
CNVD-2020-10487 OR CVE-2020-1938 批量验证脚本,批量验证,并自动截图,方便提交及复核
CVE-2020-1938CRITICALsob ataque22 fev 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC67
The official exploit for Cacti v1.2.8 Remote Code Execution CVE-2020-8813
CVE-2020-881322 fev 2020
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISCO
abrir
GitHub PoC423
Ghostcat read file/code execute,CNVD-2020-10487(CVE-2020-1938)
CVE-2020-1938CRITICALsob ataque22 fev 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC14
批量扫描TomcatAJP漏洞
CVE-2020-1938CRITICALsob ataque21 fev 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC7
fatal0/tomcat-cve-2020-1938-check
CVE-2020-1938CRITICALsob ataque21 fev 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC56
Tomcat的文件包含及文件读取漏洞利用POC
CVE-2020-1938CRITICALsob ataque21 fev 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC2
h7hac9/CVE-2020-1938
CVE-2020-1938CRITICALsob ataque21 fev 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1938CRITICALsob ataque21 fev 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
Metasploit600
WordPress wpDiscuz Unauthenticated File Upload Vulnerability
CVE-2020-24186CRITICAL21 fev 2020
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISCO
abrir
GitHub PoC9
dacade/CVE-2020-1938
CVE-2020-1938CRITICALsob ataque21 fev 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC11
在一定条件下可执行命令
CVE-2020-1938CRITICALsob ataque21 fev 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC38
CVE-2020-1938漏洞复现
CVE-2020-1938CRITICALsob ataque21 fev 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
anteriorpágina 787 / 2.637próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.