Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
79.230 exploits
GitHub PoC14
CVE-2019-11043 PHP7.x RCE
CVE-2019-11043HIGHsob ataqueransomware06 nov 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC
create12138/CVE-2018-15982
CVE-2018-15982HIGHsob ataqueransomware06 nov 2019
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
GitHub PoC3
CVE-2019-11043 && PHP7.x && RCE EXP
CVE-2019-11043HIGHsob ataqueransomware06 nov 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-11043HIGHsob ataqueransomware06 nov 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC13
vesche/CVE-2019-10475
CVE-2019-1047506 nov 2019
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML
50RISCO
abrir
GitHub PoC1
CVE-2017-0005 POC
CVE-2017-0005HIGHsob ataque05 nov 2019
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
76RISCO
abrir
GitHub PoC
Optional Mitigation Steps
CVE-2019-1231405 nov 2019
Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as
60RISCO
abrir
GitHub PoC4
PoC for Webmin Package Update Authenticated Remote Command Execution
CVE-2019-1284005 nov 2019
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISCO
abrir
GitHub PoC2
CVE-2018-3245
CVE-2018-324505 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
45RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-289305 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALsob ataqueransomware05 nov 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
CVE-2017-3248
CVE-2017-324805 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RISCO
abrir
GitHub PoC3
CVE-2017-3506
CVE-2017-3506HIGHsob ataque05 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
Metasploit600
Optergy Proton and Enterprise BMS Command Injection using a backdoor
CVE-2019-727605 nov 2019
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
60RISCO
abrir
GitHub PoC3
CVE-2019-2725
CVE-2019-2725HIGHsob ataqueransomware05 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
GitHub PoC2
(CVE-2017-10271)Java反序列化漏洞
CVE-2017-10271HIGHsob ataqueransomware05 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-2725HIGHsob ataqueransomware05 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-261805 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
35RISCO
abrir
VulnCheck XDB
local
CVE-2017-0005HIGHsob ataque05 nov 2019
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
76RISCO
abrir
Exploit-DBVexDay Proof
JavaScriptCore - Type Confusion During Bailout when Reconstructing Arguments Objects
CVE-2019-8820dosmultiple05 nov 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPad
23RISCO
abrir
Metasploit600
Microsoft Spooler Local Privilege Elevation Vulnerability
CVE-2020-1337HIGH04 nov 2019
Windows Print Spooler Elevation of Privilege Vulnerability
41RISCO
abrir
Metasploit600
Windows Update Orchestrator unchecked ScheduleWork call
CVE-2020-131304 nov 2019
An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file oper
30RISCO
abrir
Metasploit300
Microsoft Spooler Local Privilege Elevation Vulnerability
CVE-2020-1048HIGH04 nov 2019
Windows Print Spooler Elevation of Privilege Vulnerability
61RISCO
abrir
GitHub PoC3
POC for CVE-2019-13720
CVE-2019-13720HIGHsob ataque04 nov 2019
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap
93RISCO
abrir
Exploit-DBVexDay Proof
Micro Focus (HPE) Data Protector - SUID Privilege Escalation (Metasploit)
CVE-2019-11660locallinux04 nov 2019
Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30,
38RISCO
abrir
Metasploit600
FreeSWITCH Event Socket Command Execution
CVE-2019-1949203 nov 2019
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-1161002 nov 2019
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISCO
abrir
GitHub PoC
Standalone Python ≥3.6 RCE Unauthenticated exploit for Supervisor 3.0a1 to 3.3.2
CVE-2017-1161002 nov 2019
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISCO
abrir
Exploit-DBVexDay Proof
Nostromo - Directory Traversal Remote Command Execution (Metasploit)
CVE-2019-16278CRITICALsob ataqueremotemultiple01 nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-019201 nov 2019
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP
60RISCO
abrir
anteriorpágina 806 / 2.641próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.