Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
14.096 exploits
GitHub PoC30
这资源是作者复现微软签字证书漏洞CVE-2020-0601,结合相关资源及文章实现。推荐大家结合作者博客,理解ECC算法、Windows验证机制,并尝试自己复现可执行文件签名证书和HTTPS劫持的例子。作为网络安全初学者,自己确实很菜,但希望坚持下去,加油!
CVE-2020-0601HIGHsob ataque17 fev 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC40
Android privilege escalation via an use-after-free in binder.c
CVE-2019-2215HIGHsob ataque17 fev 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC1
这资源是作者复现微软签字证书漏洞CVE-2020-0601,结合相关资源及文章实现。推荐大家结合作者博客,复现了该漏洞和理解恶意软件自启动劫持原理。作为网络安全初学者,自己确实很菜,但希望坚持下去,一起加油!
CVE-2020-0601HIGHsob ataque17 fev 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC3
Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995
CVE-2018-999515 fev 2020
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
GitHub PoC196
SQL Server Reporting Services(CVE-2020-0618)中的RCE
CVE-2020-0618CRITICALsob ataque15 fev 2020
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISCO
abrir
GitHub PoC2
User Enumeration Proof Of Concept Exploit for CVE-2019-8449
CVE-2019-844914 fev 2020
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate username
60RISCO
abrir
GitHub PoC1
POE code for CVE-2017-1000112 adapted to both funtion on a specific VM and Escape a Docker
CVE-2017-100011214 fev 2020
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISCO
abrir
GitHub PoC
exploit for DNS 4.3
CVE-2013-698713 fev 2020
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before
28RISCO
abrir
GitHub PoC2
An Python Exploit for Sudo vulnerability CVE-2019-18634
CVE-2019-1863413 fev 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir
GitHub PoC3
PostgreSQL Remote Code Executuon
CVE-2019-919312 fev 2020
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
GitHub PoC
PoC for CVE-2020-0601 vulnerability (Code Signing)
CVE-2020-0601HIGHsob ataque12 fev 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC336
CVE-2020-0683 - Windows MSI “Installer service” Elevation of Privilege
CVE-2020-0683HIGHsob ataque11 fev 2020
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
71RISCO
abrir
GitHub PoC
N0b1e6/CVE-2018-1335-Python3
CVE-2018-133511 fev 2020
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISCO
abrir
GitHub PoC
https://github.com/awakened1712/CVE-2019-11932
CVE-2019-1193211 fev 2020
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC3
VanillaForum 2.6.3 allows stored XSS.
CVE-2020-882510 fev 2020
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
23RISCO
abrir
GitHub PoC7
Containerized and deployable use of the CVE-2019-14287 vuln. View README.md for more.
CVE-2019-1428709 fev 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC1
Exhaust WordPress <V5.0.1 resources using long passwords (CVE-2014-9016)
CVE-2014-901608 fev 2020
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x
60RISCO
abrir
GitHub PoC
Adapted CVE-2015-8562 payload
CVE-2015-856207 fev 2020
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISCO
abrir
GitHub PoC58
A functional exploit for CVE-2019-18634, a BSS overflow in sudo's pwfeedback feature that allows for for privesc
CVE-2019-1863407 fev 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir
GitHub PoC237
Proof of Concept for CVE-2019-18634
CVE-2019-1863407 fev 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir
GitHub PoC1
Final Project for Security and Privacy CS 600.443
CVE-2011-486206 fev 2020
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISCO
abrir
GitHub PoC5
CVE-2014-2630 exploit for xglance-bin
CVE-2014-263004 fev 2020
Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via u
38RISCO
abrir
GitHub PoC1
CVE-2019-5736 implemented in a self-written container runtime to understand the exploit.
CVE-2019-573604 fev 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC1
PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) POC: https://github.com/ollypwn/CurveBall
CVE-2020-0601HIGHsob ataque03 fev 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC1
Resources related to CurveBall (CVE-2020-0601) detection
CVE-2020-0601HIGHsob ataque03 fev 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC68
CVE-2019-8449 Exploit for Jira v2.1 - v8.3.4
CVE-2019-844902 fev 2020
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate username
60RISCO
abrir
GitHub PoC
A python implementation of CVE-2004-2271 targeting MiniShare 1.4.1.
CVE-2004-227102 fev 2020
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RISCO
abrir
GitHub PoC25
Python exploit of cve-2020-7247
CVE-2020-7247CRITICALsob ataque30 jan 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISCO
abrir
GitHub PoC26
Temproot for Bravia TV via CVE-2019-2215.
CVE-2019-2215HIGHsob ataque30 jan 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC4
TheCyberGeek/CVE-2020-5844
CVE-2020-584429 jan 2020
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators t
35RISCO
abrir
anteriorpágina 411 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.