Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.647exploits catalogados
34.986CVEs com exploração pública
24.695testados em laboratório
14.014 exploits
GitHub PoC18
1day research effort
CVE-2021-3156HIGHsob ataque28 jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC4
baka9moe/CVE-2021-3156-Exp
CVE-2021-3156HIGHsob ataque28 jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC5
cve-2021-3156;sudo堆溢出漏洞;漏洞检测
CVE-2021-3156HIGHsob ataque28 jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC2
👻CVE-2017-16995
CVE-2017-1699528 jan 2021
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
GitHub PoC79
WebLogic T3/IIOP RCE ExternalizableHelper.class of coherence.jar
CVE-2020-14756CRITICAL27 jan 2021
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versio
70RISCO
abrir
GitHub PoC
nexcess/sudo_cve-2021-3156
CVE-2021-3156HIGHsob ataque27 jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC69
Exploit for CVE-2021-3129
CVE-2021-3129CRITICALsob ataqueransomware27 jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC3
This simple bash script will patch the recently discovered sudo heap overflow vulnerability.
CVE-2021-3156HIGHsob ataque27 jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
CVE-2021-3156
CVE-2021-3156HIGHsob ataque27 jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC1
unauth401/CVE-2021-3156
CVE-2021-3156HIGHsob ataque27 jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC112
CVE-2021-3156
CVE-2021-3156HIGHsob ataque27 jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC18
crisprss/Laravel_CVE-2021-3129_EXP
CVE-2021-3129CRITICALsob ataqueransomware27 jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC35
mr-r3b00t/CVE-2021-3156
CVE-2021-3156HIGHsob ataque26 jan 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC2
CVE-2021-3441 CVE Check is a python script to search targets for indicators of compromise to CVE-2021-3441
CVE-2021-344126 jan 2021
A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross
23RISCO
abrir
GitHub PoC
Quick and dirty bruteforcer for CVE-2018-7669 (Directory Traversal Vulnerability in Sitecore)
CVE-2018-766925 jan 2021
An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application
28RISCO
abrir
GitHub PoC5
用于对WebLogic(10.3.6.0.0 ;12.1.3.0.0 ;12.2.1.3.0; 12.2.1.4.0 ;14.1.1.0.0)进行验证及利用
CVE-2020-14883HIGHsob ataque25 jan 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC6
SignHere is implementation of CVE-2017-11882. SignHere is builder of malicious rtf document and VBScript payloads.
CVE-2017-11882HIGHsob ataqueransomware25 jan 2021
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC78
SecPros-Team/laravel-CVE-2021-3129-EXP
CVE-2021-3129CRITICALsob ataqueransomware25 jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC
killmonday/CVE-2020-17530-s2-061
CVE-2020-17530CRITICALsob ataque24 jan 2021
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir
GitHub PoC6
CVE-2020-8597 in RM2100
CVE-2020-8597CRITICAL24 jan 2021
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RISCO
abrir
GitHub PoC1
findcool/cve-2021-1647
CVE-2021-1647HIGHsob ataque23 jan 2021
Microsoft Defender Remote Code Execution Vulnerability
83RISCO
abrir
GitHub PoC31
CVE-2021-2109 && Weblogic Server RCE via JNDI
CVE-2021-2109HIGH22 jan 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RISCO
abrir
GitHub PoC9
rabbitsafe/CVE-2021-2109
CVE-2021-2109HIGH22 jan 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RISCO
abrir
GitHub PoC135
Laravel debug rce
CVE-2021-3129CRITICALsob ataqueransomware22 jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC4
CVE-2020-17456 & Seowon SLC 130 Router RCE
CVE-2020-1745621 jan 2021
SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi pa
60RISCO
abrir
GitHub PoC
CVE-2019-17137 POC
CVE-2019-17137CRITICAL20 jan 2021
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR AC120
48RISCO
abrir
GitHub PoC18
Zerologon Check and Exploit - Discovered by Tom Tervoort of Secura and expanded on @Dirkjanm's cve-2020-1472 coded example. This tool will check, exploit and restore password to original state
CVE-2020-1472MEDIUMsob ataqueransomware20 jan 2021
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
Eremiel/CVE-2019-5420
CVE-2019-542020 jan 2021
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir
GitHub PoC1
CENG 325 - Principles of Information Security And Privacy
CVE-2018-133518 jan 2021
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISCO
abrir
GitHub PoC1
CVE-2020-17519; Apache Flink 任意文件读取; 批量检测
CVE-2020-17519CRITICALsob ataque18 jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir
anteriorpágina 383 / 468próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.