Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.647exploits catalogados
34.986CVEs com exploração pública
24.695testados em laboratório
14.014 exploits
GitHub PoC
roninAPT/CVE-2018-0802
CVE-2018-0802HIGHsob ataque20 fev 2021
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISCO
abrir
GitHub PoC1
Nicoslo/Windows-exploitation-Apache-Tomcat-8.5.19-CVE-2019-0232-
CVE-2019-023220 fev 2021
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISCO
abrir
GitHub PoC
Eternit7/CVE-2019-1458
CVE-2019-1458HIGHsob ataqueransomware19 fev 2021
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC
Full exploit code for CVE-2019-25024 an unauthenticated command injection flaw in OpenRepeater.
CVE-2019-2502419 fev 2021
OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_sy
28RISCO
abrir
GitHub PoC1
Nicoslo/Windows-exploitation-BadBlue-2.7-CVE-2007-6377
CVE-2007-637718 fev 2021
Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attacker
50RISCO
abrir
GitHub PoC163
Laravel <= v8.4.2 debug mode: Remote code execution (CVE-2021-3129)
CVE-2021-3129CRITICALsob ataqueransomware18 fev 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC1
PoC for CVE-2015-1769
CVE-2015-1769MEDIUMsob ataque17 fev 2021
Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,
63RISCO
abrir
GitHub PoC2
FunPhishing/Laravel-8.4.2-rce-CVE-2021-3129
CVE-2021-3129CRITICALsob ataqueransomware14 fev 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC3
OpenSSL Heartbleed Bug CVE-2014-0160 Toolkit. Built with ❤ by Christopher Ngo.
CVE-2014-0160HIGHsob ataque14 fev 2021
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC4
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker.
CVE-2021-21014CRITICAL13 fev 2021
Magento Commerce Arbitrary Folder Empty Could Lead To Arbitrary Code Execution
48RISCO
abrir
GitHub PoC11
OpenSMTPD 6.4.0 - 6.6.1 Remote Code Execution PoC exploit
CVE-2020-7247CRITICALsob ataque13 fev 2021
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISCO
abrir
GitHub PoC8
Test for CVE-2000-0649, and return an IP address if vulnerable
CVE-2000-064911 fev 2021
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RISCO
abrir
GitHub PoC40
synacktiv/CVE-2021-1782
CVE-2021-1782HIGHsob ataque10 fev 2021
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-00
71RISCO
abrir
GitHub PoC16
sudo heap overflow to LPE, in Go
CVE-2021-3156HIGHsob ataque09 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
보안취약점 확인
CVE-2021-3156HIGHsob ataque09 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC205
CVE-2021-3156非交互式执行命令
CVE-2021-3156HIGHsob ataque09 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC51
CVE-2021-3156: Sudo heap overflow exploit for Debian 10
CVE-2021-3156HIGHsob ataque08 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
Fixed version of the Python script to exploit CVE-2018-19571 and CVE-2018-19585 (GitLab 11.4.7 - Authenticated Remote Code Execution) that is available at https://www.exploit-db.com/exploits/49263 (Python 3.9).
CVE-2018-1957108 fev 2021
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RISCO
abrir
GitHub PoC10
CVE-2020-7384
CVE-2020-7384HIGH07 fev 2021
Client-Side Command Injection in Rapid7 Metasploit
68RISCO
abrir
GitHub PoC2
Grayhaxor/CVE-2021-21148
CVE-2021-21148HIGHsob ataque07 fev 2021
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap
76RISCO
abrir
GitHub PoC
Apple Safari Remote Code Execution
CVE-2020-27930HIGHsob ataque07 fev 2021
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, wat
76RISCO
abrir
GitHub PoC7
1N53C/CVE-2021-3156-PoC
CVE-2021-3156HIGHsob ataque06 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
DXY0411/CVE-2019-16113
CVE-2019-1611305 fev 2021
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISCO
abrir
GitHub PoC
46o60/CVE-2019-3396_Confluence
CVE-2019-3396CRITICALsob ataqueransomware05 fev 2021
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
GitHub PoC3
Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215
CVE-2019-2215HIGHsob ataque05 fev 2021
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC
Custom version of sudo 1.8.3p1 with CVE-2021-3156 patches applied
CVE-2021-3156HIGHsob ataque05 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC2
Poc for CVE-2020-14181
CVE-2020-1418105 fev 2021
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
60RISCO
abrir
GitHub PoC2
simple bash script of CVE-2020-3452 Cisco ASA / Firepower Read-Only Path Traversal Vulnerability checker
CVE-2020-3452HIGHsob ataque04 fev 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC2
simple bash script of F5 BIG-IP TMUI Vulnerability CVE-2020-5902 checker
CVE-2020-5902CRITICALsob ataqueransomware04 fev 2021
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC67
CVE-2020-3992 & CVE-2019-5544
CVE-2019-5544CRITICALsob ataqueransomware04 fev 2021
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of
100RISCO
abrir
anteriorpágina 381 / 468próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.