Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.542exploits catalogados
34.971CVEs com exploração pública
24.695testados em laboratório
13.947 exploits
GitHub PoC3
CVE-2007-2447 - Samba usermap script
CVE-2007-244730 jun 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC1
Create your malicious engine in seconds
CVE-2020-711530 jun 2021
The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon succ
35RISCO
abrir
GitHub PoC24
AssassinUKG/Polkit-CVE-2021-3560
CVE-2021-3560HIGHsob ataque29 jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir
GitHub PoC2
CVE-2021-1675 exploit
CVE-2021-1675HIGHsob ataqueransomware29 jun 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1.990
C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527
CVE-2021-1675HIGHsob ataqueransomware29 jun 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC19
Automated bulk IP or domain scanner for CVE 2020 3580. Cisco ASA and FTD XSS hunter.
CVE-2020-3580MEDIUMsob ataqueransomware28 jun 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
100RISCO
abrir
GitHub PoC13
freeide/CVE-2021-31955-POC
CVE-2021-31955MEDIUMsob ataque26 jun 2021
Windows Kernel Information Disclosure Vulnerability
85RISCO
abrir
GitHub PoC
compiled CVE-2015-1328
CVE-2015-132826 jun 2021
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISCO
abrir
GitHub PoC9
Hudi233/CVE-2020-3580
CVE-2020-3580MEDIUMsob ataqueransomware25 jun 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
100RISCO
abrir
GitHub PoC1
donghyunlee00/CVE-2021-3156
CVE-2021-3156HIGHsob ataque25 jun 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
Badbird3/CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware24 jun 2021
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC12
GravCMS Unauthenticated Arbitrary YAML Write/Update leads to Code Execution (CVE-2021-21425)
CVE-2021-21425CRITICAL24 jun 2021
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RISCO
abrir
GitHub PoC1
Remote Command Execution through Unvalidated File Upload in SeedDMS versions <5.1.11
CVE-2019-1274424 jun 2021
SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a differe
28RISCO
abrir
GitHub PoC11
Zeroscan is a Domain Controller vulnerability scanner, that currently includes checks for Zerologon (CVE-2020-1472), MS-PAR/MS-RPRN and SMBv2 Signing.
CVE-2020-1472MEDIUMsob ataqueransomware23 jun 2021
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
m3terpreter/CVE-2016-4437
CVE-2016-4437CRITICALsob ataque22 jun 2021
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISCO
abrir
GitHub PoC
pywc/CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware21 jun 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC1
POC-CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware19 jun 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC126
Privilege escalation with polkit - CVE-2021-3560
CVE-2021-3560HIGHsob ataque19 jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir
GitHub PoC2
PoC exploit for CVE-2020-7247 OpenSMTPD 6.4.0 < 6.6.1 Remote Code Execution
CVE-2020-7247CRITICALsob ataque19 jun 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISCO
abrir
GitHub PoC
h3x0v3rl0rd/CVE-2019-14287
CVE-2019-1428717 jun 2021
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC
Polkit - Local Privilege Escalation (CVE-2021-3560)
CVE-2021-3560HIGHsob ataque15 jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir
GitHub PoC1
spyx/cve-2019-17240
CVE-2019-17240LOW15 jun 2021
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISCO
abrir
GitHub PoC
polkit exploit script v1.0
CVE-2021-3560HIGHsob ataque14 jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir
GitHub PoC124
secnigma/CVE-2021-3560-Polkit-Privilege-Esclation
CVE-2021-3560HIGHsob ataque14 jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir
GitHub PoC8
CVE-2018-19422 Authenticated Remote Code Execution
CVE-2018-1942214 jun 2021
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RISCO
abrir
GitHub PoC
sujaygr8/CVE-2020-3187
CVE-2020-3187CRITICAL14 jun 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISCO
abrir
GitHub PoC2
ZeroShell 3.9.0 Remote Command Injection
CVE-2019-1272513 jun 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir
GitHub PoC19
wpDiscuz 7.0.4 Remote Code Execution
CVE-2020-24186CRITICAL13 jun 2021
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISCO
abrir
GitHub PoC1
CVE-2021–22201 Arbitrary file read on Gitlab
CVE-2021-22201CRITICAL13 jun 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file
48RISCO
abrir
GitHub PoC40
a reliable C based exploit and writeup for CVE-2021-3560.
CVE-2021-3560HIGHsob ataque12 jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir
anteriorpágina 368 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.