Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.020exploits catalogados
35.276CVEs com exploração pública
24.695testados em laboratório
14.080 exploits
GitHub PoC
cyberharsh/Groovy-scripting-engine-CVE-2015-1427
CVE-2015-1427CRITICALsob ataque22 jun 2020
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISCO
abrir
GitHub PoC1
Python version of Metasploit exploit for CVE-2004-1561
CVE-2004-156122 jun 2020
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISCO
abrir
GitHub PoC
cdedmondson/Modified-CVE-2019-15107
CVE-2019-15107CRITICALsob ataqueransomware20 jun 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC3
cyberharsh/Nginx-CVE-2013-4547
CVE-2013-454720 jun 2020
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescap
35RISCO
abrir
GitHub PoC60
CVE-2020-8163 - Remote code execution of user-provided local names in Rails
CVE-2020-816319 jun 2020
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
60RISCO
abrir
GitHub PoC
cyberharsh/Libssh-server-CVE-2018-10933
CVE-2018-10933CRITICAL19 jun 2020
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC20
This is an implementation of the CVE-2020-0796 aka SMBGhost vulnerability, compatible with the Metasploit Framework
CVE-2020-0796CRITICALsob ataqueransomware19 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC1
cyberharsh/Apache-couchdb-CVE-2017-12635
CVE-2017-1263519 jun 2020
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISCO
abrir
GitHub PoC
CVE-2018-7600 0-Day Exploit (cyber-warrior.org)
CVE-2018-7600CRITICALsob ataqueransomware18 jun 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC86
LPE for CVE-2020-1054 targeting Windows 7 x64
CVE-2020-1054HIGHsob ataque16 jun 2020
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
98RISCO
abrir
GitHub PoC30
CVE-2020-5410 Spring Cloud Config directory traversal vulnerability
CVE-2020-5410HIGHsob ataque16 jun 2020
Directory Traversal with spring-cloud-config-server
100RISCO
abrir
GitHub PoC721
Support ALL Windows Version
CVE-2020-0787HIGHsob ataqueransomware16 jun 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISCO
abrir
GitHub PoC1
A PoC for CVE-2020-8816 that does not use $PATH but $PWD and globbing
CVE-2020-8816CRITICALsob ataque15 jun 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RISCO
abrir
GitHub PoC
Description and public exploit for CVE-2020-12712
CVE-2020-1271215 jun 2020
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 an
23RISCO
abrir
GitHub PoC
sionnx/cve-2003-0282
CVE-2003-028214 jun 2020
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters bet
28RISCO
abrir
GitHub PoC3
for 供養
CVE-2020-6418HIGHsob ataque13 jun 2020
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISCO
abrir
GitHub PoC
freshdemo/ApacheStruts-CVE-2018-11776
CVE-2018-11776HIGHsob ataque12 jun 2020
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC23
cve-2020-0688 UNIVERSAL Python implementation utilizing ASPX webshell for command output
CVE-2020-0688HIGHsob ataqueransomware12 jun 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC
Struts 2.5 - 2.5.12 REST Plugin XStream RCE
CVE-2017-9805HIGHsob ataque11 jun 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC
批量测试CVE-2020-0796 - SMBv3 RCE
CVE-2020-0796CRITICALsob ataqueransomware11 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC353
SMBGhost (CVE-2020-0796) Automate Exploitation and Detection
CVE-2020-0796CRITICALsob ataqueransomware10 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC
Norton Core Secure WiFi PoC (CVE-2018-5234) on Rust.
CVE-2018-523410 jun 2020
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic
28RISCO
abrir
GitHub PoC5
Bludit >= 3.9.2 - Authenticated RCE (CVE-2019-16113)
CVE-2019-1611309 jun 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISCO
abrir
GitHub PoC3
SMBv3 Ghost (CVE-2020-0796) Vulnerability
CVE-2020-0796CRITICALsob ataqueransomware09 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC
适配12.2.1.3和12.2.1.4版本
CVE-2020-2883CRITICALsob ataque09 jun 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISCO
abrir
GitHub PoC
ratiros01/CVE-2004-1561
CVE-2004-156109 jun 2020
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISCO
abrir
GitHub PoC3
This is the exploit of CVE-2019-17240.
CVE-2019-17240LOW08 jun 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISCO
abrir
GitHub PoC72
Triggering and Analyzing Android Kernel Vulnerability CVE-2019-2215
CVE-2019-2215HIGHsob ataque07 jun 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC13
CVE-2019-16113 - bludit >= 3.9.2 RCE authenticate
CVE-2019-1611304 jun 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISCO
abrir
GitHub PoC5
ynots0ups/CVE-2019-16113
CVE-2019-1611303 jun 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISCO
abrir
anteriorpágina 400 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.