Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
14.096 exploits
GitHub PoC1
exploit for sudo CVE-2019-18634
CVE-2019-1863409 mar 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir
GitHub PoC13
PoC of CVE-2019-15126 kr00k vulnerability
CVE-2019-1512609 mar 2020
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal
23RISCO
abrir
GitHub PoC1
Gather a list of Citrix appliances in a country / state pair, and check if they're vulnerable to CVE-2019-19781
CVE-2019-19781CRITICALsob ataqueransomware08 mar 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC177
Weblogic com.tangosol.util.extractor.ReflectionExtractor RCE
CVE-2020-2555CRITICALsob ataque07 mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISCO
abrir
GitHub PoC47
CVE-2020-8597 pppd buffer overflow poc
CVE-2020-8597CRITICAL07 mar 2020
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RISCO
abrir
GitHub PoC
simple poc for CVE-2020-0069
CVE-2020-0069HIGHsob ataque07 mar 2020
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RISCO
abrir
GitHub PoC
CVE-2020-8597
CVE-2020-8597CRITICAL06 mar 2020
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RISCO
abrir
GitHub PoC3
Hu3sky/CVE-2020-2555
CVE-2020-2555CRITICALsob ataque06 mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISCO
abrir
GitHub PoC45
CVE-2020-2555 Python POC
CVE-2020-2555CRITICALsob ataque06 mar 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISCO
abrir
GitHub PoC6
A CVE-2019-11580 shell
CVE-2019-11580CRITICALsob ataqueransomware06 mar 2020
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RISCO
abrir
GitHub PoC
CVE-2019-13272
CVE-2019-13272HIGHsob ataque05 mar 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
GitHub PoC5
PoC for Forgot2kEyXCHANGE (CVE-2020-0688) written in PowerShell
CVE-2020-0688HIGHsob ataqueransomware04 mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC
CVE-2020-1938
CVE-2020-1938CRITICALsob ataque03 mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC
PoC of CVE
CVE-2020-6418HIGHsob ataque03 mar 2020
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISCO
abrir
GitHub PoC
exploitblizzard/CVE-2020-0601-spoofkey
CVE-2020-0601HIGHsob ataque03 mar 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC181
POC for cve-2019-1458
CVE-2019-1458HIGHsob ataqueransomware03 mar 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC17
reversing mtk-su
CVE-2020-0069HIGHsob ataque03 mar 2020
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RISCO
abrir
GitHub PoC132
CVE-2020-2546,CVE-2020-2915 CVE-2020-2801 CVE-2020-2798 CVE-2020-2883 CVE-2020-2884 CVE-2020-2950 WebLogic T3 payload exploit poc python3,
CVE-2020-2546CRITICAL02 mar 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - Java
48RISCO
abrir
GitHub PoC1
CVE-2019-5096(UAF in upload handler) exploit cause Denial of Service
CVE-2019-5096CRITICAL02 mar 2020
An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base Go
60RISCO
abrir
GitHub PoC11
This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works.
CVE-2018-6789CRITICALsob ataqueransomware02 mar 2020
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir
GitHub PoC6
CVE-2020-1938(GhostCat) clean and readable code version
CVE-2020-1938CRITICALsob ataque01 mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC354
Exploit and detect tools for CVE-2020-0688
CVE-2020-0688HIGHsob ataqueransomware01 mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC11
HumanSecurity/CVE-2019-18426
CVE-2019-18426HIGHsob ataque29 fev 2020
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.
83RISCO
abrir
GitHub PoC1
I made this script for conducting CVE-2020-0688 more rapidly. It helps to improve checking the vuln, reducing hugely steps for that
CVE-2020-0688HIGHsob ataqueransomware28 fev 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC37
Quick tool for checking CVE-2020-0688 on multiple hosts with a non-intrusive method.
CVE-2020-0688HIGHsob ataqueransomware28 fev 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC10
CVE-2020-0688
CVE-2020-0688HIGHsob ataqueransomware28 fev 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC337
Weblogic IIOP CVE-2020-2551
CVE-2020-2551CRITICALsob ataque28 fev 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISCO
abrir
GitHub PoC328
cve-2020-0688
CVE-2020-0688HIGHsob ataqueransomware27 fev 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC144
CVE-2020-0688_EXP Auto trigger payload & encrypt method
CVE-2020-0688HIGHsob ataqueransomware27 fev 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC5
Disclosure report of CVE-2020-9038
CVE-2020-903827 fev 2020
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
23RISCO
abrir
anteriorpágina 409 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.