Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
14.119 exploits
GitHub PoC12
CVE-2019-6340 POC Drupal rce
CVE-2019-6340HIGHsob ataque25 fev 2019
Drupal core - Highly critical - Remote Code Execution
100RISCO
abrir
GitHub PoC2
CVE-2019-6340 Drupal 8.6.9 REST Auth Bypass examples
CVE-2019-6340HIGHsob ataque25 fev 2019
Drupal core - Highly critical - Remote Code Execution
100RISCO
abrir
GitHub PoC73
A simple PoC for WordPress RCE (author priviledge), refer to CVE-2019-8942 and CVE-2019-8943.
CVE-2019-894225 fev 2019
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISCO
abrir
GitHub PoC153
🐱‍💻 Poc of CVE-2019-7238 - Nexus Repository Manager 3 Remote Code Execution 🐱‍💻
CVE-2019-7238CRITICALsob ataque24 fev 2019
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISCO
abrir
GitHub PoC21
Proof of concept code in C# to exploit the WinRAR ACE file extraction path (CVE-2018-20250).
CVE-2018-20250HIGHsob ataqueransomware23 fev 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
GitHub PoC42
Environment for CVE-2019-6340 (Drupal)
CVE-2019-6340HIGHsob ataque23 fev 2019
Drupal core - Highly critical - Remote Code Execution
100RISCO
abrir
GitHub PoC492
exp for https://research.checkpoint.com/extracting-code-execution-from-winrar
CVE-2018-20250HIGHsob ataqueransomware22 fev 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
GitHub PoC30
CVE-2019-6340-Drupal SA-CORE-2019-003
CVE-2019-6340HIGHsob ataque22 fev 2019
Drupal core - Highly critical - Remote Code Execution
100RISCO
abrir
GitHub PoC
A version of the binary patched to address CVE-2018-20250
CVE-2018-20250HIGHsob ataqueransomware22 fev 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
GitHub PoC
nmweizi/CVE-2018-20250-poc-winrar
CVE-2018-20250HIGHsob ataqueransomware22 fev 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
GitHub PoC26
010 Editor template for ACE archive format & CVE-2018-2025[0-3]
CVE-2018-20250HIGHsob ataqueransomware22 fev 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
GitHub PoC1
CVE-2019-6249 Hucart cms 复现环境
CVE-2019-624921 fev 2019
An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/inde
23RISCO
abrir
GitHub PoC86
CVE-2019-5736 POCs
CVE-2019-573620 fev 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC1
An app demo for test android webview security issue: CVE-2012-6636
CVE-2012-663619 fev 2019
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta
50RISCO
abrir
GitHub PoC1
b3d3c/poc-cve-2019-5736
CVE-2019-573619 fev 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC48
Proof of calc for CVE-2019-6453
CVE-2019-645318 fev 2019
mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The a
35RISCO
abrir
GitHub PoC
Easy RM to MP3 Converter es un software que sufre de una vulnerabiliad de desbordamiento de buffer basada en la pila o StackBufferOverflow lo cual puede permite a los atacantes remotos ejecutar código arbitrario a través de un nombre de archivo largo en un archivo de lista de reproducción (.pls)
CVE-2009-133018 fev 2019
Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long fil
28RISCO
abrir
GitHub PoC316
Jenkins RCE Proof-of-Concept: SECURITY-1266 / CVE-2019-1003000 (Script Security), CVE-2019-1003001 (Pipeline: Groovy), CVE-2019-1003002 (Pipeline: Declarative)
CVE-2019-100300015 fev 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISCO
abrir
GitHub PoC7
getshell test
CVE-2019-573615 fev 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC14
runc容器逃逸漏洞预警
CVE-2019-573614 fev 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC1
likekabin/CVE-2019-5736
CVE-2019-573614 fev 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC
likekabin/cve-2019-5736-poc
CVE-2019-573614 fev 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC6
Payload Generator
CVE-2019-7304HIGH14 fev 2019
Local privilege escalation via snapd socket
53RISCO
abrir
GitHub PoC69
exploit for CVE-2018-4193
CVE-2018-419313 fev 2019
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Windows Ser
23RISCO
abrir
GitHub PoC658
PoC for CVE-2019-5736
CVE-2019-573613 fev 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC210
Unweaponized Proof of Concept for CVE-2019-5736 (Docker escape)
CVE-2019-573612 fev 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC681
Linux privilege escalation exploit via snapd (CVE-2019-7304)
CVE-2019-7304HIGH12 fev 2019
Local privilege escalation via snapd socket
53RISCO
abrir
GitHub PoC
Takes advantage of CVE-2018-10933
CVE-2018-10933CRITICAL10 fev 2019
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC67
Programa ideal para robar toda la información de un dispositivo remotamente a través de la aplicación AirDroid. [CVE-2019-9599] (https://www.exploit-db.com/exploits/46337)
CVE-2019-959909 fev 2019
The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash
28RISCO
abrir
GitHub PoC5
VMware NSX SD-WAN command injection vulnerability
CVE-2018-6961HIGHsob ataque08 fev 2019
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RISCO
abrir
anteriorpágina 433 / 471próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.