Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
14.096 exploits
GitHub PoC21
PoC of CVE-2018-14847 Mikrotik Vulnerability using simple script
CVE-2018-14847CRITICALsob ataque29 set 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
GitHub PoC5
Exploit code for CVE-2019-16692
CVE-2019-1669227 set 2019
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is us
28RISCO
abrir
GitHub PoC21
vBulletin 5.x 未授权远程代码执行漏洞
CVE-2019-16759CRITICALsob ataque26 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC3
Nmap NSE Script to Detect vBulletin pre-auth 5.x RCE CVE-2019-16759
CVE-2019-16759CRITICALsob ataque26 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC5
Vbulletin rce exploit CVE-2019-16759
CVE-2019-16759CRITICALsob ataque25 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC1
Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)
CVE-2018-14847CRITICALsob ataque25 set 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
GitHub PoC6
CVE-2018-13379 Exploit
CVE-2018-13379CRITICALsob ataqueransomware24 set 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
GitHub PoC10
PoC for distributed NTP reflection DoS (CVE-2013-5211)
CVE-2013-521124 set 2019
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
GitHub PoC3
CVE-2019-1367
CVE-2019-1367HIGHsob ataqueransomware24 set 2019
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
83RISCO
abrir
GitHub PoC1
Built a custom Virtual Machine, running Ubuntu 18.04.1 and Webmin 1.810. Using CVE-2019-15107 to exploit a backdoor in the Linux machine
CVE-2019-15107CRITICALsob ataqueransomware23 set 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC8
CVE-2018-14667-poc Richfaces漏洞环境及PoC
CVE-2018-14667CRITICALsob ataque23 set 2019
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISCO
abrir
GitHub PoC1.833
Exploit for CVE-2019-11043
CVE-2019-11043HIGHsob ataqueransomware23 set 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC5
Crestron/Barco/Extron/InFocus/TeqAV Remote Command Injection (CVE-2019-3929) Metasploit Module
CVE-2019-3929CRITICALsob ataque17 set 2019
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RISCO
abrir
GitHub PoC
Escape from Docker using CVE-2017-1000112 and CVE-2017-18344, including gaining root privilage, get all capbilities, namespace recovery, filesystem recovery, cgroup limitation bypass and seccomp bypass.
CVE-2017-100011217 set 2019
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISCO
abrir
GitHub PoC1
1aa87148377/CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware17 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC4
Modified standalone exploit ported for Python 3
CVE-2018-1261316 set 2019
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir
GitHub PoC
Tool to exploit CVE-2018-7284 and CVE-2018-19278
CVE-2018-728415 set 2019
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Ce
35RISCO
abrir
GitHub PoC3
CVE-2019-0604: SharePoint RCE detection rules and sample PCAP
CVE-2019-0604CRITICALsob ataqueransomware15 set 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISCO
abrir
GitHub PoC19
AppXSvc Arbitrary File Security Descriptor Overwrite EoP
CVE-2019-1253HIGHsob ataqueransomware11 set 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISCO
abrir
GitHub PoC1
CVE-2019-0708 C#验证漏洞
CVE-2019-0708CRITICALsob ataqueransomware11 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC1
distance-vector/CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware11 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC152
Poc for CVE-2019-1253
CVE-2019-1253HIGHsob ataqueransomware11 set 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISCO
abrir
GitHub PoC
likekabin/CVE-2019-1253
CVE-2019-1253HIGHsob ataqueransomware11 set 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RISCO
abrir
GitHub PoC63
securifera/CVE-2019-1579
CVE-2019-1579HIGHsob ataqueransomware10 set 2019
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with Glob
83RISCO
abrir
GitHub PoC
0x6b7966/CVE-2018-1999002
CVE-2018-199900210 set 2019
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framewor
45RISCO
abrir
GitHub PoC133
Exploit for Pulse Connect Secure SSL VPN arbitrary file read vulnerability (CVE-2019-11510)
CVE-2019-11510CRITICALsob ataqueransomware09 set 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISCO
abrir
GitHub PoC
CVE-2019-0708RDP MSF
CVE-2019-0708CRITICALsob ataqueransomware07 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC12
initial exploit for CVE-2019-0708, BlueKeep CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free The RDP termdd.sys driver improperly handles binds to internal-only channel MS_T120, allowing a malformed Disconnect Provider Indication message to cause use-after-free. With a controllable data/size remote nonpaged pool spray, an indirect call gadget of the freed channel is used to achieve arbitrary code execution.
CVE-2019-0708CRITICALsob ataqueransomware07 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC4
CVE-2019-0708 With Metasploit-Framework Exploit
CVE-2019-0708CRITICALsob ataqueransomware07 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC1
CVE-2019-0708 RCE远程代码执行getshell教程
CVE-2019-0708CRITICALsob ataqueransomware07 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
anteriorpágina 420 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.