Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
14.119 exploits
GitHub PoC145
Confluence 未授权 RCE (CVE-2019-3396) 漏洞
CVE-2019-3396CRITICALsob ataqueransomware10 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
GitHub PoC174
CVE-2019-3396 confluence SSTI RCE
CVE-2019-3396CRITICALsob ataqueransomware10 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
GitHub PoC
xiaoshuier/CVE-2019-3396
CVE-2019-3396CRITICALsob ataqueransomware09 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
GitHub PoC
Confluence Widget Connector RCE
CVE-2019-3396CRITICALsob ataqueransomware09 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
GitHub PoC22
Confluence Widget Connector path traversal (CVE-2019-3396)
CVE-2019-3396CRITICALsob ataqueransomware09 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
GitHub PoC239
PoC code for CVE-2019-0841 Privilege Escalation vulnerability
CVE-2019-0841HIGHsob ataqueransomware05 abr 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RISCO
abrir
GitHub PoC1
likekabin/CVE-2019-0604_sharepoint_CVE
CVE-2019-0604CRITICALsob ataqueransomware04 abr 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISCO
abrir
GitHub PoC4
ManageEngine Service Desk Plus 10.0 Privilaged account Hijacking
CVE-2019-1000804 abr 2019
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session
28RISCO
abrir
GitHub PoC
Example and demo setup for Heartbleed vulnerability (CVE-2014-0160). This should be used for testing purposes only!💔
CVE-2014-0160HIGHsob ataque03 abr 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
artofscripting-zz/cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS
CVE-2014-0160HIGHsob ataque02 abr 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC2
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Print Archive System v2015 release 2.6
CVE-2019-1068502 abr 2019
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
23RISCO
abrir
GitHub PoC3
a demo for Ruby on Rails CVE-2019-5418
CVE-2019-5418HIGHsob ataque01 abr 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
GitHub PoC4
Just a PoC tool to extract password using CVE-2019-1653.
CVE-2019-1653HIGHsob ataque01 abr 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir
GitHub PoC36
CVE-2018-9276 PRTG < 18.2.39 Authenticated Command Injection (Reverse Shell)
CVE-2018-9276HIGHsob ataque31 mar 2019
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISCO
abrir
GitHub PoC10
eps漏洞(CVE-2017-0261)漏洞分析
CVE-2017-0261HIGHsob ataque31 mar 2019
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the softwar
93RISCO
abrir
GitHub PoC28
patches for SNYK-JS-JQUERY-174006, CVE-2019-11358, CVE-2019-5428
CVE-2019-1135830 mar 2019
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISCO
abrir
GitHub PoC3
IBM Lotus Domino <= R8 Password Hash Extraction Exploit
CVE-2005-242829 mar 2019
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hid
60RISCO
abrir
GitHub PoC23
ASUS SmartHome Exploit for CVE-2019-11061 and CVE-2019-11063
CVE-2019-11061CRITICAL29 mar 2019
HG100 has a broken access control vulnerability in its Web API Server
48RISCO
abrir
GitHub PoC
stillan00b/CVE-2019-5736
CVE-2019-573627 mar 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC
cve-2016-9838
CVE-2016-983827 mar 2019
An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of
28RISCO
abrir
GitHub PoC
cve-2019-5420
CVE-2019-542027 mar 2019
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir
GitHub PoC8
CVE-2019-9978 - RCE on a Wordpress plugin: Social Warfare < 3.5.3
CVE-2019-9978MEDIUMsob ataque25 mar 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
GitHub PoC47
cve-2019-0808-poc
CVE-2019-0808HIGHsob ataque25 mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISCO
abrir
GitHub PoC67
Array.prototype.slice wrong alias information.
CVE-2019-981025 mar 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISCO
abrir
GitHub PoC1
CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware24 mar 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC129
CVE-2019-0604
CVE-2019-0604CRITICALsob ataqueransomware23 mar 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISCO
abrir
GitHub PoC133
RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)
CVE-2019-5418HIGHsob ataque23 mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
GitHub PoC
PoC Scan. (cve-2011-3368)
CVE-2011-336822 mar 2019
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does
60RISCO
abrir
GitHub PoC
CVE-2017-5638 (PoC Exploits)
CVE-2017-5638CRITICALsob ataqueransomware22 mar 2019
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC8
CVE-2019-5420 (Ruby on Rails)
CVE-2019-542021 mar 2019
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir
anteriorpágina 431 / 471próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.