Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.894exploits catalogados
35.202CVEs com exploração pública
24.695testados em laboratório
14.014 exploits
GitHub PoC13
CodeTest信息收集和漏洞利用工具,可在进行渗透测试之时方便利用相关信息收集脚本进行信息的获取和验证工作,漏洞利用模块可选择需要测试的漏洞模块,或者选择所有模块测试,包含CVE-2020-14882, CVE-2020-2555等,可自己收集脚本后按照模板进行修改。
CVE-2020-14882CRITICALsob ataque30 dez 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC4
CyborgSecurity/CVE-2020-17530
CVE-2020-17530CRITICALsob ataque30 dez 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir
GitHub PoC1
Repositorio con un script encargado de explotar la vulnerabilidad CVE-2020-15999
CVE-2020-15999CRITICALsob ataque30 dez 2020
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploi
90RISCO
abrir
GitHub PoC2
Todos los materiales necesarios para la PoC en Chrome y ftview
CVE-2020-15999CRITICALsob ataque30 dez 2020
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploi
90RISCO
abrir
GitHub PoC5
rdoix/CVE-2020-10148-Solarwinds-Orion
CVE-2020-10148CRITICALsob ataque29 dez 2020
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RISCO
abrir
GitHub PoC
cve-2018-1133 moodle athenticated as teacher remote code execution.
CVE-2018-113326 dez 2020
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code exec
35RISCO
abrir
GitHub PoC6
CVE-2020-11652 & CVE-2020-11651
CVE-2020-11652MEDIUMsob ataque25 dez 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
GitHub PoC
wood03mm/CVE-2016-3088
CVE-2016-3088CRITICALsob ataque24 dez 2020
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISCO
abrir
GitHub PoC7
Weblogic Server CVE-2020-14645 EXP for Python (complete in one step)
CVE-2020-14645CRITICAL24 dez 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RISCO
abrir
GitHub PoC
Insecure Folder permission that lead to privilege escalation
CVE-2020-2816924 dez 2020
The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory
23RISCO
abrir
GitHub PoC
Webmin Exploit Scanner CVE-2020-35606 CVE-2019-12840
CVE-2019-1284023 dez 2020
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISCO
abrir
GitHub PoC
Webmin Exploit Scanner CVE-2020-35606 CVE-2019-12840
CVE-2020-3560623 dez 2020
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can ex
28RISCO
abrir
GitHub PoC
SaharAttackit/CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware23 dez 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC4
Supervisord远程命令执行漏洞脚本
CVE-2017-1161022 dez 2020
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISCO
abrir
GitHub PoC35
Laravel RCE exploit. CVE-2018-15133
CVE-2018-15133HIGHsob ataque21 dez 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISCO
abrir
GitHub PoC
https://github.com/awakened1712/CVE-2019-11932://github.com/awakened1712/CVE-2019-11932
CVE-2019-1193220 dez 2020
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC1
POC for CVE-2018-0114 written in Go
CVE-2018-011420 dez 2020
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir
GitHub PoC2
Collection of PoCs created for SmarterMail < Build 6985 RCE
CVE-2019-721420 dez 2020
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RISCO
abrir
GitHub PoC2
DirtyCOW Exploit for Android
CVE-2016-5195HIGHsob ataque20 dez 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC
(cve-2020-17530) struts2_s2-061 freemarker_RCE testscript
CVE-2020-17530CRITICALsob ataque18 dez 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir
GitHub PoC2
edxsh/CVE-2019-0752
CVE-2019-0752HIGHsob ataqueransomware18 dez 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISCO
abrir
GitHub PoC
cve-2019-0708 vulnerablility scanner
CVE-2019-0708CRITICALsob ataqueransomware17 dez 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
Apache Solr 1.4 Injection to get a shell
CVE-2019-17558HIGHsob ataque15 dez 2020
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RISCO
abrir
GitHub PoC1
GuillaumePetit84/CVE-2020-35488
CVE-2020-3548815 dez 2020
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of
23RISCO
abrir
GitHub PoC7
CVE-2020-17530-strust2-061
CVE-2020-17530CRITICALsob ataque14 dez 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir
GitHub PoC9
Fortinet FortiOS路径遍历漏洞 (CVE-2018-13379)批量检测脚本
CVE-2018-13379CRITICALsob ataqueransomware14 dez 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
GitHub PoC2
CVE-2014-0160 OpenSSL Heartbleed Proof of Concept
CVE-2014-0160HIGHsob ataque13 dez 2020
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC26
cygenta/CVE-2020-3452
CVE-2020-3452HIGHsob ataque13 dez 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC29
S2-061 CVE-2020-17530
CVE-2020-17530CRITICALsob ataque13 dez 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir
GitHub PoC
MasterSploit/CVE-2020-0787
CVE-2020-0787HIGHsob ataqueransomware11 dez 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISCO
abrir
anteriorpágina 385 / 468próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.