Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8.883Nuclei 4.361Metasploit 3.493✓ só verificadosrecentespopularesrisco
79.305 exploits
Exploit-DB✓ VexDay Proof
macOS / iOS NSKeyedUnarchiver - Use-After-Free of ObjC Objects when Unarchiving OITSUIntDictionary Instances
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iMessage - Memory Corruption when Decoding NSKnownKeysDictionary1
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10
28RISCO
abrir ↗Metasploit600
Nagios XI Prior to 5.6.6 getprofile.sh Authenticated Remote Command Execution
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Schneider Electric Pelco Endura NET55XX Encoder - Authentication Bypass (Metasploit)
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 wh
50RISCO
abrir ↗GitHub PoC★ 1
quandqn/cve-2018-14667
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISCO
abrir ↗Exploit-DB
WordPress Plugin Simple Membership 3.8.4 - Cross-Site Request Forgery
The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.
23RISCO
abrir ↗GitHub PoC★ 4
infiniteLoopers/CVE-2019-2107
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
pdfresurrect 0.15 - Buffer Overflow
PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is misha
23RISCO
abrir ↗Exploit-DB
Moodle Filepicker 3.5.2 - Server Side Request Forgery
Moodle 3.x has Server Side Request Forgery in the filepicker.
28RISCO
abrir ↗VulnCheck XDB
initial-access
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISCO
abrir ↗Exploit-DB
Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injection
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL
28RISCO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISCO
abrir ↗Exploit-DB
Ahsay Backup 7.x - 8.1.1.50 - Authenticated Arbitrary File Upload / Remote Code Execution (Metasploit)
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to
60RISCO
abrir ↗GitHub PoC★ 39
Some debug notes and exploit(not blind)
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISCO
abrir ↗GitHub PoC★ 60
EoP POC for CVE-2019-1132
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ahsay Backup 8.1.1.50 - Insecure File Upload and Code Execution (Authenticated)
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to
60RISCO
abrir ↗Exploit-DB
Microsoft Windows 7 build 7601 (x86) - Local Privilege Escalation
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISCO
abrir ↗GitHub PoC★ 3
Exim Honey Pot for CVE-2019-10149 exploit attempts.
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir ↗GitHub PoC★ 1
收集网上CVE-2018-0708的poc和exp(目前没有找到exp)
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗VulnCheck XDB
initial-access
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RISCO
abrir ↗Exploit-DB
Ovidentia 8.4.3 - Cross-Site Scripting
index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=crea
23RISCO
abrir ↗GitHub PoC★ 10
CVE-2019–11581 PoC
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RISCO
abrir ↗GitHub PoC★ 14
POC for CVE-2019-14339 Canon PRINT 2.5.5
The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly res
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - Universal Cross-Site Scripting due to Synchronous Page Loads
A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management
23RISCO
abrir ↗GitHub PoC★ 1
收集网上CVE-2018-0708的poc和exp(目前没有找到exp)
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iMessage - DigitalTouch tap Message Processing Out-of-Bounds Read
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5.3. A remote attacke
23RISCO
abrir ↗Exploit-DB
Linux Kernel 4.10 < 5.1.17 - 'PTRACE_TRACEME' pkexec Local Privilege Escalation
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir ↗Exploit-DB
Android 7 < 9 - Remote Code Execution
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th
23RISCO
abrir ↗Exploit-DB
Cisco Wireless Controller 3.6.10E - Cross-Site Request Forgery
Cisco IOS XE NGWC Legacy Wireless Device Manager GUI Cross-Site Request Forgery Vulnerability
46RISCO
abrir ↗GitHub PoC★ 1
My old sysret / ptrace PoC
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.