Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
14.119 exploits
GitHub PoC5
VMware NSX SD-WAN command injection vulnerability
CVE-2018-6961HIGHsob ataque08 fev 2019
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RISCO
abrir
GitHub PoC5
Exploiting CVE-2016-10277 for Secure Boot and Device Locking bypass
CVE-2016-1027704 fev 2019
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute
23RISCO
abrir
GitHub PoC
cve-2018-3811
CVE-2018-381102 fev 2019
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthentica
35RISCO
abrir
GitHub PoC
cve-2018-3810
CVE-2018-381002 fev 2019
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RISCO
abrir
GitHub PoC16
iOS 12.0 -> 12.1.2 Incomplete Osiris Jailbreak with CVE-2019-6225 by GeoSn0w (FCE365)
CVE-2019-622531 jan 2019
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
28RISCO
abrir
GitHub PoC1
NSE script to scan for Cisco routers vulnerable to CVE-2019-1653
CVE-2019-1653HIGHsob ataque30 jan 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir
GitHub PoC1
Python 3 implementation of an existing CVE-2011-3556 proof of concept (PoC).
CVE-2011-355629 jan 2019
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RISCO
abrir
GitHub PoC
Exploit script for Crossfire 1.9.0
CVE-2006-123629 jan 2019
Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrar
28RISCO
abrir
GitHub PoC2
DVR username password recovery.
CVE-2018-999528 jan 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
GitHub PoC370
CVE-2018-8581
CVE-2018-8581HIGHsob ataqueransomware24 jan 2019
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
76RISCO
abrir
GitHub PoC228
CVE-2019-1652 /CVE-2019-1653 Exploits For Dumping Cisco RV320 Configurations & Debugging Data AND Remote Root Exploit!
CVE-2019-1652HIGHsob ataque24 jan 2019
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RISCO
abrir
GitHub PoC1
This is a exp of CVE-2018-15473
CVE-2018-15473MEDIUM23 jan 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC1
Writeup for CVE-2017-16995 Linux BPF Local Privilege Escalation
CVE-2017-1699522 jan 2019
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
GitHub PoC1
cve-2018-15961
CVE-2018-15961CRITICALsob ataque21 jan 2019
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISCO
abrir
GitHub PoC
CVE-2015-2794 auto finder
CVE-2015-279420 jan 2019
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain S
60RISCO
abrir
GitHub PoC119
cve-2018-8453 exp
CVE-2018-8453HIGHsob ataqueransomware18 jan 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC2
cve-2018-8453 exp
CVE-2018-8453HIGHsob ataqueransomware18 jan 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC6
praveensutar/CVE-2019-6263-Joomla-POC
CVE-2019-626318 jan 2019
An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allo
23RISCO
abrir
GitHub PoC
cve-2018-1273
CVE-2018-1273CRITICALsob ataqueransomware17 jan 2019
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISCO
abrir
GitHub PoC
cve-2017-12615
CVE-2017-12615HIGHsob ataqueransomware17 jan 2019
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
GitHub PoC
cve-2017-1000117
CVE-2017-100011717 jan 2019
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RISCO
abrir
GitHub PoC1
cve-2017-8046
CVE-2017-804617 jan 2019
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISCO
abrir
GitHub PoC
cve-2016-10033
CVE-2016-10033CRITICALsob ataque17 jan 2019
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
GitHub PoC2
Proof of Concept - RCE Exploitation : Web Shell on Apache Tomcat - Ensimag January 2018
CVE-2017-12617HIGHsob ataque14 jan 2019
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISCO
abrir
GitHub PoC
cve-2016-8869
CVE-2016-886911 jan 2019
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before
60RISCO
abrir
GitHub PoC
cve-2018-9206
CVE-2018-920611 jan 2019
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISCO
abrir
GitHub PoC1
cve-2018-15473
CVE-2018-15473MEDIUM11 jan 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC
cve-2017-1000486
CVE-2017-1000486CRITICALsob ataque11 jan 2019
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISCO
abrir
GitHub PoC
cve-2017-10271
CVE-2017-10271HIGHsob ataqueransomware11 jan 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC
cve-2017-8917
CVE-2017-891711 jan 2019
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISCO
abrir
anteriorpágina 434 / 471próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.