Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.966exploits catalogados
35.269CVEs com exploração pública
24.695testados em laboratório
14.014 exploits
GitHub PoC
MasterSploit/CVE-2020-0787
CVE-2020-0787HIGHsob ataqueransomware11 dez 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISCO
abrir
GitHub PoC
MasterSploit/CVE-2020-0787-BitsArbitraryFileMove-master
CVE-2020-0787HIGHsob ataqueransomware11 dez 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISCO
abrir
GitHub PoC46
S2-061 的payload,以及对应简单的PoC/Exp
CVE-2020-17530CRITICALsob ataque10 dez 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir
GitHub PoC
WildfootW/CVE-2007-2447_Samba_3.0.25rc3
CVE-2007-244709 dez 2020
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC1
Apache Struts2框架是一个用于开发Java EE网络应用程序的Web框架。Apache Struts于2020年12月08日披露 S2-061 Struts 远程代码执行漏洞(CVE-2020-17530),在使用某些tag等情况下可能存在OGNL表达式注入漏洞,从而造成远程代码执行,风险极大。提醒我校Apache Struts用户尽快采取安全措施阻止漏洞攻击。
CVE-2020-17530CRITICALsob ataque09 dez 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir
GitHub PoC157
weaponized tool for CVE-2020-17144
CVE-2020-17144HIGHsob ataque09 dez 2020
Microsoft Exchange Remote Code Execution Vulnerability
83RISCO
abrir
GitHub PoC157
Exchange2010 authorized RCE
CVE-2020-17144HIGHsob ataque09 dez 2020
Microsoft Exchange Remote Code Execution Vulnerability
83RISCO
abrir
GitHub PoC
WildfootW/CVE-2018-15473_OpenSSH_7.7
CVE-2018-15473MEDIUM09 dez 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC64
ka1n4t/CVE-2020-17530
CVE-2020-17530CRITICALsob ataque09 dez 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir
GitHub PoC
WildfootW/CVE-2014-0160_OpenSSL_1.0.1f_Heartbleed
CVE-2014-0160HIGHsob ataque09 dez 2020
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
Remote code execution in Mediawiki Score
CVE-2020-29007CRITICAL08 dez 2020
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of
48RISCO
abrir
GitHub PoC1
PoC for CVE: 2017-5638 - Apache Struts2 S2-045
CVE-2017-5638CRITICALsob ataqueransomware06 dez 2020
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
Exploit for the vulnerability CVE-2007-2447
CVE-2007-244706 dez 2020
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC
[qdPM < 9.1 - Remote Code Execution](https://www.exploit-db.com/exploits/48146)
CVE-2020-724605 dez 2020
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir
GitHub PoC14
This small script helps to avoid using MetaSploit (msfconsole) during the Enterprise pentests and OSCP-like exams. Grep included function will help you to get only the important information.
CVE-2006-339204 dez 2020
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISCO
abrir
GitHub PoC1
Scan through given ip list
CVE-2019-0708CRITICALsob ataqueransomware03 dez 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
ActorExpose/CVE-2017-11882
CVE-2017-11882HIGHsob ataqueransomware03 dez 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC
diegojuan/CVE-2019-15107
CVE-2019-15107CRITICALsob ataqueransomware03 dez 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC49
Python / scapy module implementing SRVLOC/SLP protocol and scans for enabled OpenSLP services.
CVE-2019-5544CRITICALsob ataqueransomware01 dez 2020
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of
100RISCO
abrir
GitHub PoC49
Python / scapy module implementing SRVLOC/SLP protocol and scans for enabled OpenSLP services.
CVE-2020-3992CRITICALsob ataqueransomware01 dez 2020
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-
100RISCO
abrir
GitHub PoC34
CVE-2020-27950 exploit
CVE-2020-27950MEDIUMsob ataque01 dez 2020
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RISCO
abrir
GitHub PoC1
Scanning tool to test for SaltStack vulnerabilities CVE-2020-11651 & CVE-2020-11652.
CVE-2020-11651CRITICALsob ataque30 nov 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
GitHub PoC9
This module massively scan and exploit a path traversal vulnerability in the FortiOS SSL VPN web portal may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests (CVE-2018-13379).
CVE-2018-13379CRITICALsob ataqueransomware30 nov 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
GitHub PoC
wikiZ/cve-2018-8120
CVE-2018-8120HIGHsob ataqueransomware30 nov 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC1
wikiZ/cve-2014-4113
CVE-2014-4113HIGHsob ataque30 nov 2020
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RISCO
abrir
GitHub PoC
Vbulletin RCE Exploits
CVE-2019-16759CRITICALsob ataque29 nov 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC42
OpenSSH 2.3 < 7.7 - Username Enumeration
CVE-2018-15473MEDIUM29 nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC1
Exploit script for Apache Struts2 REST Plugin XStream RCE (‎CVE-2017-9805)
CVE-2017-9805HIGHsob ataque28 nov 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC
Dirty-Racoon/CVE-2018-15473-py3
CVE-2018-15473MEDIUM27 nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC
openssh<7.7 用户名枚举
CVE-2018-15473MEDIUM26 nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
anteriorpágina 386 / 468próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.