Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.647exploits catalogados
34.986CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.899GitHub PoC 14.014VulnCheck XDB 8.571Nuclei 4.248Metasploit 3.472✓ só verificadosrecentespopularesrisco
14.014 exploits
GitHub PoC
okanulkr/CurveBall-CVE-2020-0601-PoC
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir ↗GitHub PoC
1nteger-c/CVE-2019-8605
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RISCO
abrir ↗GitHub PoC
Rust implementation of CVE-2018-16763 with some extra features.
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir ↗GitHub PoC★ 18
Exploit script for CVE-2020-7961
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir ↗GitHub PoC
CVE-2020-17519 EXP
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir ↗GitHub PoC★ 82
PoC for CVE-2020-6207 (Missing Authentication Check in SAP Solution Manager)
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RISCO
abrir ↗GitHub PoC★ 289
Exploit for CVE-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗GitHub PoC
Starry-lord/CVE-2018-0114
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir ↗GitHub PoC★ 1
CVE-2017-12615 任意文件写入exp,写入webshell
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir ↗GitHub PoC
AnasTaoutaou/CVE-2019-5420
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir ↗GitHub PoC★ 8
[CVE-2020-17519] Apache Flink RESTful API Arbitrary File Read
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir ↗GitHub PoC★ 5
ElmouradiAmine/CVE-2020-7048
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any
53RISCO
abrir ↗GitHub PoC
CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir ↗GitHub PoC★ 5
uzzzval/CVE-2020-17530
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir ↗GitHub PoC★ 7
quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual exploitation of CVE-2020-1472. requires admin access to the DCs
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC★ 1
QmF0c3UK/CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir ↗GitHub PoC★ 3
Apache Flink Directory Traversal (CVE-2020-17519) Nmap NSE Script
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir ↗GitHub PoC★ 48
Apache Flink 目录遍历漏洞批量检测 (CVE-2020-17519)
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir ↗GitHub PoC★ 3
Python implementation of Roundcube LFI (CVE-2017-16651)
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
98RISCO
abrir ↗GitHub PoC★ 10
SolarWinds Orion API 远程代码执行漏洞批量检测脚本
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RISCO
abrir ↗GitHub PoC★ 99
CISCO CVE-2020-3452 Scanner & Exploiter
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir ↗GitHub PoC★ 1
andyfeili/CVE-2014-4688
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RISCO
abrir ↗GitHub PoC★ 21
Remote Code Execution on Microsoft Exchange Server through fixed cryptographic keys
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir ↗GitHub PoC★ 16
Scanner for Zyxel products which are potentially vulnerable due to an undocumented user account (CVE-2020-29583)
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The p
100RISCO
abrir ↗GitHub PoC★ 3
AzhariKun/CVE-2018-15133
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISCO
abrir ↗GitHub PoC★ 2
python2.7 script for JWT generation
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir ↗GitHub PoC
andyfeili/CVE-2018-9276
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISCO
abrir ↗GitHub PoC★ 5
A2SV = Auto Scanning to SSL Vulnerability HeartBleed, CCS Injection, SSLv3 POODLE, FREAK... etc Support Vulnerability [CVE-2007-1858] Anonymous Cipher [CVE-2012-4929] CRIME(SPDY) [CVE-2014-0160] CCS Injection [CVE-2014-0224] HeartBleed [CVE-2014-3566] SSLv3 POODLE [CVE-2015-0204] FREAK Attack [CVE-2015-4000] LOGJAM Attack [CVE-2016-0800] SSLv2 DROWN Installation : $ apt update && apt upgrade $ apt install git $ apt install python2 $ apt install python $ git clone https://github.com/hahwul/ a2sv $ cd a2sv $ chmod +x * $ pip2 install -r requirements.txt usage : $ python2 a2sv.py -h It shows all commands how we can use this tool $ python a2sv.py -t 127.0.0.1 127.0.0.1 = target means here own device
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗GitHub PoC★ 2
zerologon script to exploit CVE-2020-1472 CVSS 10/10
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC
Cisco IP Phone 11.7 - Denial of Service (PoC)
Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.