Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.020exploits catalogados
35.276CVEs com exploração pública
24.695testados em laboratório
14.080 exploits
GitHub PoC8
(CVE-2020-14882) Oracle Weblogic Unauthorized bypass RCE test script
CVE-2020-14882CRITICALsob ataque01 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC13
Exploiting CVE-2014-3153, AKA Towelroot.
CVE-2014-3153HIGHsob ataque31 out 2020
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISCO
abrir
GitHub PoC12
CVE-2020-14882批量验证工具。
CVE-2020-14882CRITICALsob ataque31 out 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC
alexfrancow/CVE-2020-14882
CVE-2020-14882CRITICALsob ataque30 out 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC1
CuteNews Avatar 2.1.2 Remote Code Execution Vulnerability
CVE-2019-1144730 out 2020
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISCO
abrir
GitHub PoC17
CVE-2020-14882 Weblogic-Exp
CVE-2020-14882CRITICALsob ataque29 out 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC
Un semplice exploit che sfrutta CVE-2015-7297, CVE-2015-7857 and CVE-2015-7858 per elencare gli utenti con la psw del db
CVE-2015-729729 out 2020
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISCO
abrir
GitHub PoC2
Scans for Microsoft Exchange Versions with masscan
CVE-2020-0688HIGHsob ataqueransomware29 out 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC2
Bash script to exploit the Oracle's Weblogic Unauthenticated Remote Command Execution - CVE-2020-14882
CVE-2020-14882CRITICALsob ataque29 out 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC7
CVE-2020-14882 EXP 回显
CVE-2020-14882CRITICALsob ataque29 out 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC
Windows 7 LPE
CVE-2020-1054HIGHsob ataque28 out 2020
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
98RISCO
abrir
GitHub PoC29
CVE-2020–14882 by Jang
CVE-2020-14882CRITICALsob ataque28 out 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC287
CVE-2020–14882、CVE-2020–14883
CVE-2020-14882CRITICALsob ataque28 out 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC14
PoC for old Binder vulnerability (based on P0 exploit)
CVE-2019-2215HIGHsob ataque27 out 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC
datntsec/CVE-2019-12735
CVE-2019-1273526 out 2020
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RISCO
abrir
GitHub PoC8
POC For CVE-2020-1481 - Jira Username Enumerator/Validator
CVE-2020-1418126 out 2020
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
60RISCO
abrir
GitHub PoC2
Python exploit for CVE-2012-2982
CVE-2012-298225 out 2020
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir
GitHub PoC11
CVE-2020-0688 PoC
CVE-2020-0688HIGHsob ataqueransomware23 out 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC1
PoC for apache struts 2 vuln cve-2019-0230
CVE-2019-023022 out 2020
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISCO
abrir
GitHub PoC
puckiestyle/CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware21 out 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
HYWZ36/CVE-2020-14645-code
CVE-2020-14645CRITICAL21 out 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RISCO
abrir
GitHub PoC
Elsfa7-110/CVE-2019-1579
CVE-2019-1579HIGHsob ataqueransomware21 out 2020
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with Glob
83RISCO
abrir
GitHub PoC2
Bludit <= 3.9.2 - Authentication Bruteforce Mitigation Bypass Exploit/PoC
CVE-2019-17240LOW21 out 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISCO
abrir
GitHub PoC2
cve-2020-14644 漏洞环境
CVE-2020-14644CRITICALsob ataque20 out 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISCO
abrir
GitHub PoC
Exploitable target to CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware19 out 2020
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC7
ThinkAdmin CVE-2020-25540 poc
CVE-2020-2554019 out 2020
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RISCO
abrir
GitHub PoC
datntsec/CVE-2019-13272
CVE-2019-13272HIGHsob ataque19 out 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
GitHub PoC
stealth-ronin/CVE-2017-0199-PY-KIT
CVE-2017-0199HIGHsob ataqueransomware18 out 2020
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC
Exploits CuteNews 2.1.2 via poor file upload checks used when uploading an avatar image leading to RCE.
CVE-2019-1144718 out 2020
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISCO
abrir
GitHub PoC5
C# Vulnerability Checker for CVE-2020-1472 Aka Zerologon
CVE-2020-1472MEDIUMsob ataqueransomware17 out 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
anteriorpágina 391 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.