Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8.883Nuclei 4.361Metasploit 3.493✓ só verificadosrecentespopularesrisco
79.305 exploits
Exploit-DB✓ VexDay Proof
systemd - DynamicUser can Create setuid Binaries when Assisted by Another Process
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allo
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
systemd - DynamicUser can Create setuid Binaries when Assisted by Another Process
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of
33RISCO
abrir ↗Exploit-DB
Apache Pluto 3.0.0 / 3.0.1 - Persistent Cross-Site Scripting
The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XS
28RISCO
abrir ↗GitHub PoC★ 9
The official exploit code for LibreNMS v1.46 Remote Code Execution CVE-2018-20434
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to htm
60RISCO
abrir ↗GitHub PoC
likekabin/CVE-2018-20250
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RARLAB WinRAR 5.61 - ACE Format Input Validation Remote Code Execution (Metasploit)
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir ↗GitHub PoC★ 1
WebLogic CNVD-C-2019_48814 CVE-2017-10271
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗GitHub PoC★ 105
CVE-2019-2725poc汇总 更新绕过CVE-2017-10271补丁POC
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗Exploit-DB
JioFi 4G M2S 1.0.2 - 'mask' Cross-Site Scripting
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter.
23RISCO
abrir ↗Exploit-DB
JioFi 4G M2S 1.0.2 - Denial of Service
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter.
23RISCO
abrir ↗GitHub PoC★ 114
WebLogic CNVD-C-2019_48814 CVE-2017-10271 Scan By 7kbstorm
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗GitHub PoC★ 105
CVE-2019-2725poc汇总 更新绕过CVE-2017-10271补丁POC
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗GitHub PoC★ 4
A C# module to detect if a Jenkins server is vulnerable to the RCE vulnerability found in CVE-2019-1003000 (chained with CVE-2018-1000861 for pre-auth RCE)
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VirtualBox 6.0.4 r128413 - COM RPC Interface Code Injection Host Privilege Escalation
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISCO
abrir ↗Metasploit600
WP Database Backup RCE
WP Database Backup < 5.2 - Unauthenticated OS Command Injection
68RISCO
abrir ↗VulnCheck XDB
initial-access
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISCO
abrir ↗GitHub PoC
KeyStrOke95/nfsen_1.3.7_CVE-2017-6971
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary comma
28RISCO
abrir ↗Metasploit600
Pulse Secure VPN Arbitrary Command Execution
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISCO
abrir ↗GitHub PoC★ 4
A C# module to detect if a Jenkins server is vulnerable to the RCE vulnerability found in CVE-2019-1003000 (chained with CVE-2018-1000861 for pre-auth RCE)
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISCO
abrir ↗Metasploit300
Pulse Secure VPN Arbitrary File Disclosure
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISCO
abrir ↗VulnCheck XDB
initial-access
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
systemd - Lack of Seat Verification in PAM Module Permits Spoofing Active Session to polkit
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using t
33RISCO
abrir ↗Metasploit600
Oracle Weblogic Server Deserialization RCE - AsyncResponseService
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir ↗Exploit-DB
74CMS 5.0.1 - Cross-Site Request Forgery (Add New Admin User)
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
23RISCO
abrir ↗Exploit-DB
UliCMS 2019.2 / 2019.1 - Multiple Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitra
23RISCO
abrir ↗Exploit-DB
Msvod 10 - Cross-Site Request Forgery (Change User Information)
Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.
23RISCO
abrir ↗Exploit-DB
QNAP myQNAPcloud Connect 1.3.4.0317 - 'Username/Password' Denial of Service
Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the pr
23RISCO
abrir ↗GitHub PoC★ 1
rakesh143/CVE-2019-0808
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISCO
abrir ↗GitHub PoC
cve-2017-17485 PoC
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.