Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
GitHub PoC20
CVE-2019-16759 vbulletin 5.0.0 till 5.5.4 pre-auth rce
CVE-2019-16759CRITICALsob ataque02 out 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
Exploit-DBVexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
CVE-2017-0145HIGHsob ataqueransomwareremotewindows02 out 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DBVexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
CVE-2017-0144HIGHsob ataqueransomwareremotewindows02 out 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DB
DotNetNuke < 9.4.0 - Cross-Site Scripting
CVE-2019-12562webappsmultiple01 out 2019
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the mali
23RISCO
abrir
GitHub PoC245
ispy V1.0 - Eternalblue(ms17-010)/Bluekeep(CVE-2019-0708) Scanner and exploit ( Metasploit automation )
CVE-2019-0708CRITICALsob ataqueransomware30 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
Exploit-DB
Cisco Small Business 220 Series - Multiple Vulnerabilities
CVE-2019-1913CRITICALremotehardware30 set 2019
Cisco Small Business 220 Series Smart Switches Remote Code Execution Vulnerabilities
53RISCO
abrir
Exploit-DB
Cisco Small Business 220 Series - Multiple Vulnerabilities
CVE-2019-1912CRITICALremotehardware30 set 2019
Cisco Small Business 220 Series Smart Switches Authentication Bypass Vulnerability
53RISCO
abrir
Exploit-DB
vBulletin 5.x - Remote Command Execution (Metasploit)
CVE-2019-16759CRITICALsob ataquewebappsphp30 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
Exploit-DB
Cisco Small Business 220 Series - Multiple Vulnerabilities
CVE-2019-1914HIGHremotehardware30 set 2019
Cisco Small Business 220 Series Smart Switches Command Injection Vulnerability
46RISCO
abrir
Exploit-DB
WordPress Plugin ARforms 3.7.1 - Arbitrary File Deletion
CVE-2019-16902webappsphp30 set 2019
In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an
23RISCO
abrir
Exploit-DB
GoAhead 2.5.0 - Host Header Injection
CVE-2019-16645remotemultiple30 set 2019
An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) cre
23RISCO
abrir
Exploit-DB
phpIPAM 1.4 - SQL Injection
CVE-2019-16692webappsphp30 set 2019
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is us
28RISCO
abrir
GitHub PoC
A simple exploit for CVE-2007-2447
CVE-2007-244730 set 2019
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
VulnCheck XDB
client-side
CVE-2019-11708CRITICALsob ataque29 set 2019
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
90RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALsob ataque29 set 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2019-981029 set 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISCO
abrir
GitHub PoC624
Full exploit chain (CVE-2019-11708 & CVE-2019-9810) against Firefox on Windows 64-bit.
CVE-2019-11708CRITICALsob ataque29 set 2019
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
90RISCO
abrir
GitHub PoC21
PoC of CVE-2018-14847 Mikrotik Vulnerability using simple script
CVE-2018-14847CRITICALsob ataque29 set 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
GitHub PoC75
it works on xp (all version sp2 sp3)
CVE-2019-0708CRITICALsob ataqueransomware29 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-845128 set 2019
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con
60RISCO
abrir
GitHub PoC5
Exploit code for CVE-2019-16692
CVE-2019-1669227 set 2019
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is us
28RISCO
abrir
GitHub PoC21
vBulletin 5.x 未授权远程代码执行漏洞
CVE-2019-16759CRITICALsob ataque26 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC3
Nmap NSE Script to Detect vBulletin pre-auth 5.x RCE CVE-2019-16759
CVE-2019-16759CRITICALsob ataque26 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-16759CRITICALsob ataque26 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-845126 set 2019
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-16759CRITICALsob ataque26 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
Metasploit600
Android Binder Use-After-Free Exploit
CVE-2019-2215HIGHsob ataque26 set 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
Exploit-DB
Microsoft SharePoint 2013 SP1 - 'DestinationFolder' Persistant Cross-Site Scripting
CVE-2019-1262webappsaspx25 set 2019
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall
23RISCO
abrir
Exploit-DB
NPMJS gitlabhook 0.0.17 - 'repository' Remote Command Execution
CVE-2019-5485webappsjson25 set 2019
NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be inje
35RISCO
abrir
GitHub PoC5
Vbulletin rce exploit CVE-2019-16759
CVE-2019-16759CRITICALsob ataque25 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
anteriorpágina 814 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.