Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.233GitHub PoC 14.119VulnCheck XDB 8.617Nuclei 4.257Metasploit 3.474✓ só verificadosrecentespopularesrisco
14.119 exploits
GitHub PoC★ 4
POC for CVE-2017-10271. Since java.lang.ProcessBuilder was the original vector for RCE, there are multiple signature based rules that block this particular payload. Added java.lang.Runtime and will add others in the future. This is for educational purposes only: I take no responsibility for how you use this code.
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗GitHub PoC★ 254
FileReader Exploit
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISCO
abrir ↗GitHub PoC★ 6
CVE-2018-11686 - FlexPaper PHP Publish Service RCE <= 2.3.6
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_c
50RISCO
abrir ↗GitHub PoC★ 14
GUI版 EXP
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISCO
abrir ↗GitHub PoC★ 36
A multi-threaded Golang scanner to identify Ruby endpoints vulnerable to CVE-2019-5418
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir ↗GitHub PoC
Herramienta para revisar si es que un payload tiene componente malicioso de acuerdo a CVE-2018-20250
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir ↗GitHub PoC★ 7
xConsoIe/CVE-2019-0193
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISCO
abrir ↗GitHub PoC★ 5
File Content Disclosure on Rails Test Case - CVE-2019-5418
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir ↗GitHub PoC★ 6
thinkphp5.*Rce CVE-2018-20062
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISCO
abrir ↗GitHub PoC★ 201
CVE-2019-5418 - File Content Disclosure on Ruby on Rails
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir ↗GitHub PoC
cve-2018-16283
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
50RISCO
abrir ↗GitHub PoC★ 10
Noodle [Moodle RCE] (v3.4.1) - CVE-2018-1133
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code exec
35RISCO
abrir ↗GitHub PoC
cve-2019-9194
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISCO
abrir ↗GitHub PoC★ 1
原创作者:Bearcat@secfree.com
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗GitHub PoC
The exploit python script for CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗GitHub PoC
cve-2019-9184
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitr
23RISCO
abrir ↗GitHub PoC
Bits generated while analyzing CVE-2019-6340 Drupal RESTful RCE
Drupal core - Highly critical - Remote Code Execution
100RISCO
abrir ↗GitHub PoC★ 16
CVE-2018-19276 - OpenMRS Insecure Object Deserialization RCE
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISCO
abrir ↗GitHub PoC
AeolusTF/CVE-2018-20250
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir ↗GitHub PoC★ 209
A WebKit exploit using CVE-2018-4441 to obtain RCE on PS4 6.20.
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1,
28RISCO
abrir ↗GitHub PoC★ 7
CVE-2018-20250-WINRAR-ACE Exploit with a UI
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir ↗GitHub PoC
Python CVE-2019-1003000 and CVE-2018-1999002 Pre-Auth RCE Jenkins
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISCO
abrir ↗GitHub PoC
Python CVE-2019-1003000 and CVE-2018-1999002 Pre-Auth RCE Jenkins
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framewor
45RISCO
abrir ↗GitHub PoC★ 126
ze0r/CVE-2018-8639-exp
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RISCO
abrir ↗GitHub PoC★ 2
Python tool exploiting CVE-2018-20250 found by CheckPoint folks
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir ↗GitHub PoC★ 1
WinRar is a very widely known software for windows. Previous version of WinRaR was a vulnerability which has been patched in Feb-2019. Most of the people didn't update winrar so they are vulnerable in this Absolute Path Traversal bug [CVE-2018-20250]
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir ↗GitHub PoC
yyqs2008/CVE-2019-5736-PoC-2
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir ↗GitHub PoC★ 2
STP5940/CVE-2018-20250
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir ↗GitHub PoC★ 2
Demonstration of the Heartbleed Bug CVE-2014-0160
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.