Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
14.119 exploits
GitHub PoC4
POC for CVE-2017-10271. Since java.lang.ProcessBuilder was the original vector for RCE, there are multiple signature based rules that block this particular payload. Added java.lang.Runtime and will add others in the future. This is for educational purposes only: I take no responsibility for how you use this code.
CVE-2017-10271HIGHsob ataqueransomware20 mar 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC254
FileReader Exploit
CVE-2019-5786MEDIUMsob ataque20 mar 2019
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RISCO
abrir
GitHub PoC6
CVE-2018-11686 - FlexPaper PHP Publish Service RCE <= 2.3.6
CVE-2018-1168620 mar 2019
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_c
50RISCO
abrir
GitHub PoC14
GUI版 EXP
CVE-2018-133520 mar 2019
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISCO
abrir
GitHub PoC36
A multi-threaded Golang scanner to identify Ruby endpoints vulnerable to CVE-2019-5418
CVE-2019-5418HIGHsob ataque19 mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
GitHub PoC
Herramienta para revisar si es que un payload tiene componente malicioso de acuerdo a CVE-2018-20250
CVE-2018-20250HIGHsob ataqueransomware19 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
GitHub PoC7
xConsoIe/CVE-2019-0193
CVE-2019-0193HIGHsob ataque18 mar 2019
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISCO
abrir
GitHub PoC5
File Content Disclosure on Rails Test Case - CVE-2019-5418
CVE-2019-5418HIGHsob ataque18 mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
GitHub PoC6
thinkphp5.*Rce CVE-2018-20062
CVE-2018-20062CRITICALsob ataque17 mar 2019
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISCO
abrir
GitHub PoC201
CVE-2019-5418 - File Content Disclosure on Ruby on Rails
CVE-2019-5418HIGHsob ataque16 mar 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
GitHub PoC
cve-2018-16283
CVE-2018-1628315 mar 2019
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
50RISCO
abrir
GitHub PoC10
Noodle [Moodle RCE] (v3.4.1) - CVE-2018-1133
CVE-2018-113315 mar 2019
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code exec
35RISCO
abrir
GitHub PoC
cve-2019-9194
CVE-2019-919415 mar 2019
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISCO
abrir
GitHub PoC1
原创作者:Bearcat@secfree.com
CVE-2017-10271HIGHsob ataqueransomware15 mar 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC
The exploit python script for CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware15 mar 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC
cve-2019-9184
CVE-2019-918415 mar 2019
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitr
23RISCO
abrir
GitHub PoC
Bits generated while analyzing CVE-2019-6340 Drupal RESTful RCE
CVE-2019-6340HIGHsob ataque12 mar 2019
Drupal core - Highly critical - Remote Code Execution
100RISCO
abrir
GitHub PoC16
CVE-2018-19276 - OpenMRS Insecure Object Deserialization RCE
CVE-2018-19276CRITICAL11 mar 2019
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISCO
abrir
GitHub PoC
AeolusTF/CVE-2018-20250
CVE-2018-20250HIGHsob ataqueransomware11 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
GitHub PoC209
A WebKit exploit using CVE-2018-4441 to obtain RCE on PS4 6.20.
CVE-2018-444108 mar 2019
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1,
28RISCO
abrir
GitHub PoC7
CVE-2018-20250-WINRAR-ACE Exploit with a UI
CVE-2018-20250HIGHsob ataqueransomware08 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
GitHub PoC
Python CVE-2019-1003000 and CVE-2018-1999002 Pre-Auth RCE Jenkins
CVE-2019-100300006 mar 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISCO
abrir
GitHub PoC
Python CVE-2019-1003000 and CVE-2018-1999002 Pre-Auth RCE Jenkins
CVE-2018-199900206 mar 2019
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framewor
45RISCO
abrir
GitHub PoC126
ze0r/CVE-2018-8639-exp
CVE-2018-8639HIGHsob ataqueransomware05 mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RISCO
abrir
GitHub PoC2
Python tool exploiting CVE-2018-20250 found by CheckPoint folks
CVE-2018-20250HIGHsob ataqueransomware05 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
GitHub PoC1
WinRar is a very widely known software for windows. Previous version of WinRaR was a vulnerability which has been patched in Feb-2019. Most of the people didn't update winrar so they are vulnerable in this Absolute Path Traversal bug [CVE-2018-20250]
CVE-2018-20250HIGHsob ataqueransomware04 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
GitHub PoC
yyqs2008/CVE-2019-5736-PoC-2
CVE-2019-573628 fev 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC2
STP5940/CVE-2018-20250
CVE-2018-20250HIGHsob ataqueransomware28 fev 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
GitHub PoC2
Demonstration of the Heartbleed Bug CVE-2014-0160
CVE-2014-0160HIGHsob ataque27 fev 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
cve-2019-6340
CVE-2019-6340HIGHsob ataque26 fev 2019
Drupal core - Highly critical - Remote Code Execution
100RISCO
abrir
anteriorpágina 432 / 471próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.