Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8.860Nuclei 4.361Metasploit 3.491✓ só verificadosrecentespopularesrisco
79.230 exploits
GitHub PoC
create12138/CVE-2018-15982
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir ↗GitHub PoC★ 13
vesche/CVE-2019-10475
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML
50RISCO
abrir ↗GitHub PoC★ 1
CVE-2017-0005 POC
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
76RISCO
abrir ↗GitHub PoC
Optional Mitigation Steps
Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as
60RISCO
abrir ↗GitHub PoC★ 4
PoC for Webmin Package Update Authenticated Remote Command Execution
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISCO
abrir ↗GitHub PoC★ 2
CVE-2018-3245
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
45RISCO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
60RISCO
abrir ↗VulnCheck XDB
initial-access
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗GitHub PoC
CVE-2017-3248
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RISCO
abrir ↗GitHub PoC★ 3
CVE-2017-3506
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir ↗Metasploit600
Optergy Proton and Enterprise BMS Command Injection using a backdoor
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
60RISCO
abrir ↗GitHub PoC★ 3
CVE-2019-2725
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir ↗GitHub PoC★ 2
(CVE-2017-10271)Java反序列化漏洞
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
35RISCO
abrir ↗VulnCheck XDB
local
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
76RISCO
abrir ↗Exploit-DB✓ VexDay Proof
JavaScriptCore - Type Confusion During Bailout when Reconstructing Arguments Objects
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPad
23RISCO
abrir ↗Metasploit600
Microsoft Spooler Local Privilege Elevation Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
41RISCO
abrir ↗Metasploit600
Windows Update Orchestrator unchecked ScheduleWork call
An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file oper
30RISCO
abrir ↗Metasploit300
Microsoft Spooler Local Privilege Elevation Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
61RISCO
abrir ↗GitHub PoC★ 3
POC for CVE-2019-13720
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap
93RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Micro Focus (HPE) Data Protector - SUID Privilege Escalation (Metasploit)
Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30,
38RISCO
abrir ↗Metasploit600
FreeSWITCH Event Socket Command Execution
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISCO
abrir ↗VulnCheck XDB
client-side
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISCO
abrir ↗GitHub PoC
Standalone Python ≥3.6 RCE Unauthenticated exploit for Supervisor 3.0a1 to 3.3.2
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Nostromo - Directory Traversal Remote Command Execution (Metasploit)
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir ↗VulnCheck XDB
initial-access
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.