Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
14.096 exploits
GitHub PoC14
CVE-2019-11043 PHP7.x RCE
CVE-2019-11043HIGHsob ataqueransomware06 nov 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC
create12138/CVE-2018-15982
CVE-2018-15982HIGHsob ataqueransomware06 nov 2019
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
GitHub PoC3
CVE-2019-11043 && PHP7.x && RCE EXP
CVE-2019-11043HIGHsob ataqueransomware06 nov 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC13
vesche/CVE-2019-10475
CVE-2019-1047506 nov 2019
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML
50RISCO
abrir
GitHub PoC3
CVE-2017-3506
CVE-2017-3506HIGHsob ataque05 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
GitHub PoC2
CVE-2018-3245
CVE-2018-324505 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
45RISCO
abrir
GitHub PoC3
CVE-2019-2725
CVE-2019-2725HIGHsob ataqueransomware05 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
GitHub PoC1
CVE-2017-0005 POC
CVE-2017-0005HIGHsob ataque05 nov 2019
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
76RISCO
abrir
GitHub PoC
Optional Mitigation Steps
CVE-2019-1231405 nov 2019
Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as
60RISCO
abrir
GitHub PoC4
PoC for Webmin Package Update Authenticated Remote Command Execution
CVE-2019-1284005 nov 2019
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISCO
abrir
GitHub PoC2
(CVE-2017-10271)Java反序列化漏洞
CVE-2017-10271HIGHsob ataqueransomware05 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC
CVE-2017-3248
CVE-2017-324805 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RISCO
abrir
GitHub PoC3
POC for CVE-2019-13720
CVE-2019-13720HIGHsob ataque04 nov 2019
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap
83RISCO
abrir
GitHub PoC
Standalone Python ≥3.6 RCE Unauthenticated exploit for Supervisor 3.0a1 to 3.3.2
CVE-2017-1161002 nov 2019
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISCO
abrir
GitHub PoC
CVE-2018-15473-Exploit
CVE-2018-15473MEDIUM01 nov 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC8
Docker image and commands to check CVE-2019-11043 vulnerability on nginx/php-fpm applications.
CVE-2019-11043HIGHsob ataqueransomware30 out 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC
3rg1s/CVE-2016-2098
CVE-2016-209830 out 2019
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISCO
abrir
GitHub PoC10
Mayter/CVE-2019-1315
CVE-2019-1315HIGHsob ataqueransomware29 out 2019
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka '
71RISCO
abrir
GitHub PoC5
Python exp for CVE-2019-11043
CVE-2019-11043HIGHsob ataqueransomware29 out 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC
huang919/cve-2019-14287-PPT
CVE-2019-1428728 out 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC146
(PoC) Python version of CVE-2019-11043 exploit by neex
CVE-2019-11043HIGHsob ataqueransomware28 out 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC1
CVE-2019-11043 PHP远程代码执行
CVE-2019-11043HIGHsob ataqueransomware28 out 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC
TEST
CVE-2019-3396CRITICALsob ataqueransomware28 out 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
GitHub PoC4
apache axis1.4远程代码执行漏洞
CVE-2019-022727 out 2019
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2
45RISCO
abrir
GitHub PoC7
FUDForum 3.0.9 - XSS / Remote Code Execution (CVE-2019-18873, CVE-2019-18839)
CVE-2019-1887327 out 2019
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An
23RISCO
abrir
GitHub PoC19
CVE-2019-10149 : A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
CVE-2019-10149CRITICALsob ataque27 out 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir
GitHub PoC2
CVE-2000-0979
CVE-2000-097926 out 2019
File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file
35RISCO
abrir
GitHub PoC27
akamajoris/CVE-2019-11043-Docker
CVE-2019-11043HIGHsob ataqueransomware24 out 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC
CVE-2015-7547 initial research.
CVE-2015-754724 out 2019
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISCO
abrir
GitHub PoC4
PHP-FPM Remote Code Execution Vulnerability (CVE-2019-11043) POC in Python
CVE-2019-11043HIGHsob ataqueransomware24 out 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
anteriorpágina 417 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.