Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.020exploits catalogados
35.276CVEs com exploração pública
24.695testados em laboratório
14.055 exploits
GitHub PoC49
Python / scapy module implementing SRVLOC/SLP protocol and scans for enabled OpenSLP services.
CVE-2020-3992CRITICALsob ataqueransomware01 dez 2020
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-
100RISCO
abrir
GitHub PoC49
Python / scapy module implementing SRVLOC/SLP protocol and scans for enabled OpenSLP services.
CVE-2019-5544CRITICALsob ataqueransomware01 dez 2020
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of
100RISCO
abrir
GitHub PoC
wikiZ/cve-2018-8120
CVE-2018-8120HIGHsob ataqueransomware30 nov 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC9
This module massively scan and exploit a path traversal vulnerability in the FortiOS SSL VPN web portal may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests (CVE-2018-13379).
CVE-2018-13379CRITICALsob ataqueransomware30 nov 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
GitHub PoC1
Scanning tool to test for SaltStack vulnerabilities CVE-2020-11651 & CVE-2020-11652.
CVE-2020-11651CRITICALsob ataque30 nov 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
GitHub PoC1
wikiZ/cve-2014-4113
CVE-2014-4113HIGHsob ataque30 nov 2020
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RISCO
abrir
GitHub PoC42
OpenSSH 2.3 < 7.7 - Username Enumeration
CVE-2018-15473MEDIUM29 nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC
Vbulletin RCE Exploits
CVE-2019-16759CRITICALsob ataque29 nov 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC1
Exploit script for Apache Struts2 REST Plugin XStream RCE (‎CVE-2017-9805)
CVE-2017-9805HIGHsob ataque28 nov 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC
Dirty-Racoon/CVE-2018-15473-py3
CVE-2018-15473MEDIUM27 nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC5
CVE-2020-2883
CVE-2020-2883CRITICALsob ataque26 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISCO
abrir
GitHub PoC4
A CVE-2020-17087 PoC.
CVE-2020-17087HIGHsob ataque26 nov 2020
Windows Kernel Local Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC
openssh<7.7 用户名枚举
CVE-2018-15473MEDIUM26 nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC1
www201001/https-github.com-iBearcat-CVE-2018-8174_EXP
CVE-2018-8174HIGHsob ataqueransomware24 nov 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
GitHub PoC1
www201001/https-github.com-iBearcat-CVE-2018-8174_EXP.git-
CVE-2018-8174HIGHsob ataqueransomware24 nov 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
GitHub PoC
1stPeak/CVE-2018-15473
CVE-2018-15473MEDIUM23 nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC1
This container was made to explain and demonstrate how CVE-2019-15813 (Sentrifugo works)
CVE-2019-1581322 nov 2020
Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arb
35RISCO
abrir
GitHub PoC2
MasterSploit/LPE---CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware20 nov 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC6
FortiVuln
CVE-2018-13379CRITICALsob ataqueransomware19 nov 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
GitHub PoC4
CVE-2020-3452
CVE-2020-3452HIGHsob ataque18 nov 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC10
CVE-2017-3506
CVE-2017-3506HIGHsob ataque18 nov 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
GitHub PoC2
CVE-2017-10271
CVE-2017-10271HIGHsob ataqueransomware18 nov 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC4
PHP-FPM Remote Command Execution Exploit
CVE-2019-11043HIGHsob ataqueransomware18 nov 2020
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC
BabyTeam1024/CVE-2020-14882
CVE-2020-14882CRITICALsob ataque17 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC
DHCP exploitation with DynoRoot (CVE-2018-1111)
CVE-2018-1111HIGH17 nov 2020
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISCO
abrir
GitHub PoC9
A Remote Code Execution (RCE) exploit for Huawei HG532d based on CVE-2017-17215 vulnerability. Modded from original PoC code from exploit-db.com
CVE-2017-1721517 nov 2020
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could se
45RISCO
abrir
GitHub PoC
windows.vm
CVE-2019-3396CRITICALsob ataqueransomware17 nov 2020
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
GitHub PoC1
nex1less/CVE-2015-4852
CVE-2015-4852CRITICALsob ataque16 nov 2020
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISCO
abrir
GitHub PoC1
b1ack0wl/CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware16 nov 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC1
CVE-2020-25213 Wordpress File Manager 6.7 Plugin 0day exploit
CVE-2020-25213CRITICALsob ataque13 nov 2020
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir
anteriorpágina 388 / 469próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.