Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.020exploits catalogados
35.276CVEs com exploração pública
24.695testados em laboratório
14.080 exploits
GitHub PoC
DewmiApsara/CVE-2019-14287
CVE-2019-1428712 mai 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC
janod313/-CVE-2019-14287-SUDO-bypass-vulnerability
CVE-2019-1428712 mai 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC
This is the exploitation of sudo security bypass vulnerability
CVE-2019-1428712 mai 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC
This is a brief exploitation of CVE-2019-14287 Sudo Security Bypass Vulnerability.
CVE-2019-1428712 mai 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC
RashmikaEkanayake/Privilege-Escalation-CVE-2019-13272-
CVE-2019-13272HIGHsob ataque12 mai 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
GitHub PoC3
Local Root vulnerability- CVE-2019-13272 / Security Bypass Vulnerability – CVE-2019-14287/Google Android - 'Stagefright' Remote Code Execution - CVE-2015-1538
CVE-2019-13272HIGHsob ataque12 mai 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
GitHub PoC
ShianTrish/sudo-Security-Bypass-vulnerability-CVE-2019-14287
CVE-2019-1428712 mai 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC
AvishkaSenadheera/CVE-2017-9805---Documentation---IT19143378
CVE-2017-9805HIGHsob ataque12 mai 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC
CVE-2017-8759 | .NET Framework Remote Code Execution Vulnerability
CVE-2017-8759HIGHsob ataque12 mai 2020
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISCO
abrir
GitHub PoC
SachinThanushka/CVE-2018-1160
CVE-2018-1160CRITICAL12 mai 2020
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RISCO
abrir
GitHub PoC
This is about CVE-2020-1938
CVE-2020-1938CRITICALsob ataque12 mai 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC
This document explain Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway [CVE-2019-19781]
CVE-2019-19781CRITICALsob ataqueransomware12 mai 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC
SMBGhost CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware12 mai 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC
CVE-2020-1938 exploit
CVE-2020-1938CRITICALsob ataque12 mai 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC1
Local Root vulnerability- CVE-2019-13272 / Security Bypass Vulnerability – CVE-2019-14287
CVE-2019-13272HIGHsob ataque11 mai 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
GitHub PoC
Sudo Security Policy bypass Vulnerability
CVE-2019-1428711 mai 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC
Documentation for Sudo Security Bypass - CVE 2019-14287
CVE-2019-1428711 mai 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC
Exploit code for CVE-2015-5477 POC
CVE-2015-547711 mai 2020
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISCO
abrir
GitHub PoC
shanuka-ashen/Dirty-Cow-Explanation-CVE-2016-5195-
CVE-2016-5195HIGHsob ataque11 mai 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC1
Google Android - 'Stagefright' Remote Code Execution - CVE-2015-1538
CVE-2015-153811 mai 2020
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISCO
abrir
GitHub PoC
A remote code execution flaw was found in Samba. A malicious authenticated samba client, having write access to the samba share, could use this flaw to execute arbitrary code as root.
CVE-2017-7494CRITICALsob ataqueransomware10 mai 2020
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
GitHub PoC176
Weblogic coherence.jar RCE
CVE-2020-2883CRITICALsob ataque10 mai 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISCO
abrir
GitHub PoC
BBRathnayaka/POC-CVE-2019-5736
CVE-2019-573610 mai 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC10
A Python script to exploit CVE-2020-8816, a remote code execution vulnerability on the Pi-hole
CVE-2020-8816CRITICALsob ataque10 mai 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RISCO
abrir
GitHub PoC
PoC for CVE-2020-11651
CVE-2020-11651CRITICALsob ataque09 mai 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
GitHub PoC
Project with sublist3r, massan, CVE-2018-15473, ssh bruteforce, ftp bruteforce and nikto.
CVE-2018-15473MEDIUM08 mai 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC33
PoC CVE-2017-5123 - LPE - Bypassing SMEP/SMAP. No KASLR
CVE-2017-512308 mai 2020
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RISCO
abrir
GitHub PoC222
This is an exploit for CVE-2020-0674 that runs on the x64 version of IE 8, 9, 10, and 11 on Windows 7.
CVE-2020-0674HIGHsob ataque07 mai 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISCO
abrir
GitHub PoC24
CVE-2020-11651&&CVE-2020-11652 EXP
CVE-2020-11651CRITICALsob ataque07 mai 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
GitHub PoC5
lovelyjuice/cve-2020-11651-exp-plus
CVE-2020-11651CRITICALsob ataque07 mai 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
anteriorpágina 403 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.