Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
79.107 exploits
GitHub PoC1
这资源是作者复现微软签字证书漏洞CVE-2020-0601,结合相关资源及文章实现。推荐大家结合作者博客,复现了该漏洞和理解恶意软件自启动劫持原理。作为网络安全初学者,自己确实很菜,但希望坚持下去,一起加油!
CVE-2018-20250HIGHsob ataqueransomware17 fev 2020
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
GitHub PoC3
Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995
CVE-2018-999515 fev 2020
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-999515 fev 2020
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
GitHub PoC196
SQL Server Reporting Services(CVE-2020-0618)中的RCE
CVE-2020-0618CRITICALsob ataqueransomware15 fev 2020
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISCO
abrir
GitHub PoC2
User Enumeration Proof Of Concept Exploit for CVE-2019-8449
CVE-2019-844914 fev 2020
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate username
60RISCO
abrir
GitHub PoC1
POE code for CVE-2017-1000112 adapted to both funtion on a specific VM and Escape a Docker
CVE-2017-100011214 fev 2020
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISCO
abrir
GitHub PoC
exploit for DNS 4.3
CVE-2013-698713 fev 2020
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before
28RISCO
abrir
Exploit-DB
PANDORAFMS 7.0 - Authenticated Remote Code Execution
CVE-2020-8947webappsphp13 fev 2020
functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metac
28RISCO
abrir
GitHub PoC2
An Python Exploit for Sudo vulnerability CVE-2019-18634
CVE-2019-1863413 fev 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir
GitHub PoC
PoC for CVE-2020-0601 vulnerability (Code Signing)
CVE-2020-0601HIGHsob ataque12 fev 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC3
PostgreSQL Remote Code Executuon
CVE-2019-919312 fev 2020
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
Exploit-DBVexDay Proof
HP System Event Utility - Local Privilege Escalation
CVE-2019-18915localwindows12 fev 2020
A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version
23RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-919312 fev 2020
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
Metasploit600
Service Tracing Privilege Elevation Vulnerability
CVE-2020-066811 fev 2020
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Window
23RISCO
abrir
VulnCheck XDB
local
CVE-2020-0683HIGHsob ataque11 fev 2020
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-133511 fev 2020
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISCO
abrir
GitHub PoC
N0b1e6/CVE-2018-1335-Python3
CVE-2018-133511 fev 2020
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISCO
abrir
Exploit-DBVexDay Proof
OpenSMTPD 6.4.0 < 6.6.1 - Local Privilege Escalation + Remote Code Execution
CVE-2020-7247CRITICALsob ataqueremoteopenbsd11 fev 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISCO
abrir
GitHub PoC336
CVE-2020-0683 - Windows MSI “Installer service” Elevation of Privilege
CVE-2020-0683HIGHsob ataque11 fev 2020
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
71RISCO
abrir
Metasploit600
Exchange Control Panel ViewState Deserialization
CVE-2020-0688HIGHsob ataqueransomware11 fev 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
Exploit-DB
CHIYU BF430 TCP IP Converter - Stored Cross-Site Scripting
CVE-2020-8839webappscgi11 fev 2020
Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cg
23RISCO
abrir
Metasploit600
SQL Server Reporting Services (SSRS) ViewState Deserialization
CVE-2020-0618CRITICALsob ataqueransomware11 fev 2020
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISCO
abrir
Exploit-DB
Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting
CVE-2020-8825webappsphp11 fev 2020
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
23RISCO
abrir
GitHub PoC
https://github.com/awakened1712/CVE-2019-11932
CVE-2019-1193211 fev 2020
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
Exploit-DBVexDay Proof
iOS/macOS - Out-of-Bounds Timestamp Write in IOAccelCommandQueue2::processSegmentKernelCommand()
CVE-2020-3837HIGHsob ataquedosmultiple10 fev 2020
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3
76RISCO
abrir
Exploit-DBVexDay Proof
OpenSMTPD - MAIL FROM Remote Code Execution (Metasploit)
CVE-2020-7247CRITICALsob ataqueremotelinux10 fev 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISCO
abrir
Exploit-DB
Forcepoint WebSecurity 8.5 - Reflective Cross-Site Scripting
CVE-2019-6146webappsmultiple10 fev 2020
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host heade
23RISCO
abrir
Exploit-DB
Dota 2 7.23f - Denial of Service (PoC)
CVE-2020-7949doswindows10 fev 2020
schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by
23RISCO
abrir
Exploit-DBVexDay Proof
Ricoh Driver - Privilege Escalation (Metasploit)
CVE-2019-19363localwindows10 fev 2020
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attacker
38RISCO
abrir
Exploit-DBVexDay Proof
D-Link Devices - Unauthenticated Remote Command Execution in ssdpcgi (Metasploit)
CVE-2019-20215remotelinux_mips10 fev 2020
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the
60RISCO
abrir
anteriorpágina 789 / 2.637próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.