Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
79.107 exploits
Exploit-DBVexDay Proof
D-Link Devices - Unauthenticated Remote Command Execution in ssdpcgi (Metasploit)
CVE-2019-20215remotelinux_mips10 fev 2020
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the
60RISCO
abrir
Exploit-DBVexDay Proof
iOS/macOS - Out-of-Bounds Timestamp Write in IOAccelCommandQueue2::processSegmentKernelCommand()
CVE-2020-3837HIGHsob ataquedosmultiple10 fev 2020
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3
76RISCO
abrir
Exploit-DB
Dota 2 7.23f - Denial of Service (PoC)
CVE-2020-7949doswindows10 fev 2020
schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by
23RISCO
abrir
Exploit-DB
Forcepoint WebSecurity 8.5 - Reflective Cross-Site Scripting
CVE-2019-6146webappsmultiple10 fev 2020
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host heade
23RISCO
abrir
GitHub PoC7
Containerized and deployable use of the CVE-2019-14287 vuln. View README.md for more.
CVE-2019-1428709 fev 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC1
Exhaust WordPress <V5.0.1 resources using long passwords (CVE-2014-9016)
CVE-2014-901608 fev 2020
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x
60RISCO
abrir
Exploit-DBVexDay Proof
Windscribe - WindscribeService Named Pipe Privilege Escalation (Metasploit)
CVE-2018-11479localwindows07 fev 2020
The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe s
38RISCO
abrir
Exploit-DB
EyesOfNetwork 5.3 - Remote Code Execution
CVE-2020-8656webappsphp07 fev 2020
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe
60RISCO
abrir
Metasploit600
Horde CSV import arbitrary PHP code execution
CVE-2020-851807 fev 2020
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execu
60RISCO
abrir
Exploit-DB
EyesOfNetwork 5.3 - Remote Code Execution
CVE-2020-8655HIGHsob ataquewebappsphp07 fev 2020
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability
98RISCO
abrir
Exploit-DB
EyesOfNetwork 5.3 - Remote Code Execution
CVE-2020-8654webappsphp07 fev 2020
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoD
60RISCO
abrir
GitHub PoC237
Proof of Concept for CVE-2019-18634
CVE-2019-1863407 fev 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2015-856207 fev 2020
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISCO
abrir
GitHub PoC59
A functional exploit for CVE-2019-18634, a BSS overflow in sudo's pwfeedback feature that allows for for privesc
CVE-2019-1863407 fev 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir
GitHub PoC
Adapted CVE-2015-8562 payload
CVE-2015-856207 fev 2020
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISCO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager 11.2.1 - 'LanFabricImpl' Command Injection
CVE-2019-15977CRITICALwebappsjava06 fev 2020
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
60RISCO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager 11.2.1 - 'LanFabricImpl' Command Injection
CVE-2019-15978HIGHwebappsjava06 fev 2020
Cisco Data Center Network Manager Command Injection Vulnerabilities
53RISCO
abrir
Exploit-DB
Sudo 1.8.25p - 'pwfeedback' Buffer Overflow
CVE-2019-18634locallinux06 fev 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-0601HIGHsob ataque06 fev 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager 11.2.1 - 'getVmHostData' SQL Injection
CVE-2019-15976CRITICALwebappsjava06 fev 2020
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
70RISCO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager 11.2 - Remote Code Execution
CVE-2019-15975CRITICALwebappsjava06 fev 2020
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
85RISCO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager 11.2.1 - 'getVmHostData' SQL Injection
CVE-2019-15984HIGHwebappsjava06 fev 2020
Cisco Data Center Network Manager SQL Injection Vulnerabilities
53RISCO
abrir
Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
CVE-2020-946506 fev 2020
An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL
40RISCO
abrir
GitHub PoC1
Final Project for Security and Privacy CS 600.443
CVE-2011-486206 fev 2020
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISCO
abrir
Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
CVE-2020-865606 fev 2020
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe
60RISCO
abrir
Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
CVE-2020-8657CRITICALsob ataque06 fev 2020
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include
100RISCO
abrir
Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
CVE-2020-8655HIGHsob ataque06 fev 2020
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability
98RISCO
abrir
Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
CVE-2020-865406 fev 2020
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoD
60RISCO
abrir
Metasploit600
CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow
CVE-2020-801205 fev 2020
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerabi
60RISCO
abrir
Metasploit600
CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow
CVE-2020-801005 fev 2020
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vu
30RISCO
abrir
anteriorpágina 790 / 2.637próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.