Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
79.107 exploits
Exploit-DB
Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)
CVE-2020-8425webappsphp29 jan 2020
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
23RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-0601HIGHsob ataque29 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
Exploit-DB
Satellian 1.12 - Remote Code Execution
CVE-2020-7980webappshardware29 jan 2020
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RISCO
abrir
Exploit-DB
Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)
CVE-2020-8424webappsphp29 jan 2020
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php
23RISCO
abrir
Exploit-DB
XMLBlueprint 16.191112 - XML External Entity Injection
CVE-2019-19032localwindows29 jan 2020
XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an
23RISCO
abrir
GitHub PoC1
proof of concept for CVE-2020-0601
CVE-2020-0601HIGHsob ataque29 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC
ianxtianxt/CVE-2016-8735
CVE-2016-8735CRITICALsob ataque29 jan 2020
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8
100RISCO
abrir
Exploit-DB
Microsoft Windows 10 - Theme API 'ThemePack' File Parsing
CVE-2018-8413localwindows29 jan 2020
A remote code execution vulnerability exists when "Windows Theme API" does not properly decompress files, aka "Windows T
35RISCO
abrir
GitHub PoC4
TheCyberGeek/CVE-2020-5844
CVE-2020-584429 jan 2020
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators t
35RISCO
abrir
Metasploit600
OpenSMTPD MAIL FROM Remote Code Execution
CVE-2020-7247CRITICALsob ataque28 jan 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISCO
abrir
GitHub PoC1
*CVE-2014-6271* Unix Arbitrary Code Execution Exploit commonly know as Shell Shock. Examples, Docs, Incident Response and Vulnerability/Risk Assessment, and Additional Resources may be dumped here. Enjoy :) --- somhmxxghoul ---
CVE-2014-6271CRITICALsob ataque28 jan 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-0601HIGHsob ataque28 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
Exploit-DBVexDay Proof
Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password)
CVE-2020-7991webappsphp28 jan 2020
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
23RISCO
abrir
GitHub PoC1
Python CVE-2019-19781 exploit
CVE-2019-19781CRITICALsob ataqueransomware28 jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC73
PoC script that shows RCE vulnerability over Intellian Satellite controller
CVE-2020-798028 jan 2020
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-798028 jan 2020
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RISCO
abrir
Exploit-DB
Octeth Oempro 4.8 - 'CampaignID' SQL Injection
CVE-2019-19740webappsphp28 jan 2020
Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
23RISCO
abrir
GitHub PoC20
PoC for CVE-2020-0601 - CryptoAPI exploit
CVE-2020-0601HIGHsob ataque28 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - Information Disclosure
CVE-2019-1125MEDIUMlocalwindows27 jan 2020
Windows Kernel Information Disclosure Vulnerability
33RISCO
abrir
GitHub PoC41
This repository contains the sources and documentation for the SWAPGS attack PoC (CVE-2019-1125)
CVE-2019-1125MEDIUM27 jan 2020
Windows Kernel Information Disclosure Vulnerability
33RISCO
abrir
Metasploit600
Centreon Poller Authenticated Remote Command Execution
CVE-2019-1969927 jan 2020
There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers mi
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALsob ataque25 jan 2020
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC
PoC for "CurveBall" CVE-2020-0601
CVE-2020-0601HIGHsob ataque25 jan 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC
Citrix ADC (NetScaler) Honeypot. Supports detection for CVE-2019-19781 and login attempts
CVE-2019-19781CRITICALsob ataqueransomware24 jan 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
Exploit-DB
Genexis Platinum-4410 2.1 - Authentication Bypass
CVE-2020-6170webappshardware24 jan 2020
An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cl
23RISCO
abrir
GitHub PoC2
Archi73ct/CVE-2020-0609
CVE-2020-060924 jan 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISCO
abrir
Exploit-DB
TP-Link TP-SG105E 1.0.0 - Unauthenticated Remote Reboot
CVE-2019-16893webappshardware24 jan 2020
The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the
35RISCO
abrir
GitHub PoC68
A proof-of-concept scanner to check an RDG Gateway Server for vulnerabilities CVE-2020-0609 & CVE-2020-0610.
CVE-2020-060924 jan 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISCO
abrir
GitHub PoC78
PoC for the Remote Desktop Gateway vulnerability - CVE-2020-0609 & CVE-2020-0610
CVE-2020-060924 jan 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISCO
abrir
Exploit-DB
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
CVE-2020-0610doswindows23 jan 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
35RISCO
abrir
anteriorpágina 792 / 2.637próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.