Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.020exploits catalogados
35.276CVEs com exploração pública
24.695testados em laboratório
14.080 exploits
GitHub PoC1
ctlyz123/CVE-2020-17496
CVE-2020-17496CRITICALsob ataque20 ago 2020
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbe
100RISCO
abrir
GitHub PoC16
[CVE-2019-18935] Telerik UI for ASP.NET AJAX (RadAsyncUpload Handler) .NET JSON Deserialization
CVE-2019-18935CRITICALsob ataqueransomware19 ago 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir
GitHub PoC532
WebLogic利用CVE-2020-2883打Shiro rememberMe反序列化漏洞,一键注册蚁剑filter内存shell
CVE-2020-2883CRITICALsob ataque19 ago 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISCO
abrir
GitHub PoC
Logeirs/CVE-2018-0114
CVE-2018-011418 ago 2020
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir
GitHub PoC
superzerosec/cve-2020-5902
CVE-2020-5902CRITICALsob ataqueransomware18 ago 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC1
cyberharsh/PHP_CVE-2012-1823
CVE-2012-1823CRITICALsob ataque17 ago 2020
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISCO
abrir
GitHub PoC4
[CVE-2020-0688] Microsoft Exchange Server Fixed Cryptographic Key Remote Code Execution (RCE)
CVE-2020-0688HIGHsob ataqueransomware17 ago 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC6
This tools will extracts and dumps Email + SMTP from vBulletin database server
CVE-2019-16759CRITICALsob ataque16 ago 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC3
dwisiswant0/CVE-2020-9496
CVE-2020-949615 ago 2020
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISCO
abrir
GitHub PoC7
[CVE-2020-3452] Cisco Adaptive Security Appliance (ASA) & Cisco Firepower Threat Defense (FTD) Web Service Read-Only Directory Traversal
CVE-2020-3452HIGHsob ataque13 ago 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC15
CVE-2019-0230 Exploit POC
CVE-2019-023013 ago 2020
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISCO
abrir
GitHub PoC2
[CVE-2020-5902] F5 BIG-IP Remote Code Execution (RCE)
CVE-2020-5902CRITICALsob ataqueransomware13 ago 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC2
[CVE-2016-2386] SAP NetWeaver AS JAVA UDDI Component SQL Injection
CVE-2016-2386CRITICALsob ataque13 ago 2020
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC1
Vbulletin RCE Exploit
CVE-2019-16759CRITICALsob ataque13 ago 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC13
[CVE-2020-6287] SAP NetWeaver AS JAVA (LM Configuration Wizard) Authentication Bypass (Create Simple & Administrator Java User)
CVE-2020-6287CRITICALsob ataque13 ago 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISCO
abrir
GitHub PoC
Tobey123/CVE-2020-1472-visualizer
CVE-2020-1472MEDIUMsob ataqueransomware12 ago 2020
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
polar1s7/CVE-2019-16759-bypass
CVE-2019-16759CRITICALsob ataque12 ago 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC17
CVE-2015-4852、CVE-2016-0638、CVE-2016-3510、CVE-2019-2890漏洞POC
CVE-2015-4852CRITICALsob ataque10 ago 2020
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISCO
abrir
GitHub PoC2
CVE-2016-4010
CVE-2016-401010 ago 2020
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary
60RISCO
abrir
GitHub PoC62
j4nn/CVE-2020-0041
CVE-2020-0041HIGHsob ataque10 ago 2020
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISCO
abrir
GitHub PoC
CVE-2018-7600 | Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' RCE
CVE-2018-7600CRITICALsob ataqueransomware10 ago 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC25
PerimeterX/CVE-2020-6519
CVE-2020-651909 ago 2020
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy
28RISCO
abrir
GitHub PoC12
Automated F5 Big IP Remote Code Execution (CVE-2020-5902) Scanner Written In Python 3
CVE-2020-5902CRITICALsob ataqueransomware09 ago 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC3
CVE-2016-2555
CVE-2016-255509 ago 2020
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RISCO
abrir
GitHub PoC6
Webmin <=1.920 RCE
CVE-2019-15107CRITICALsob ataqueransomware08 ago 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC
漏洞复现
CVE-2018-2628CRITICALsob ataque07 ago 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
GitHub PoC
CVE-2013-3214
CVE-2013-321406 ago 2020
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
60RISCO
abrir
GitHub PoC1
CVE-2017-8570 Exp改造及样本分析
CVE-2017-8570HIGHsob ataque06 ago 2020
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISCO
abrir
GitHub PoC1
Educational standalone JavaScript implementation of the public exploit for CVE-2016-9079 (Firefox Use-After-Free), adapted from the original Exploit-DB/Metasploit module.
CVE-2016-9079HIGHsob ataque06 ago 2020
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RISCO
abrir
GitHub PoC6
Pi-hole ( <= 4.3.2) authenticated remote code execution.
CVE-2020-8816CRITICALsob ataque06 ago 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RISCO
abrir
anteriorpágina 395 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.