Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.559exploits catalogados
34.978CVEs com exploração pública
24.695testados em laboratório
13.960 exploits
GitHub PoC4
infiniteLoopers/CVE-2019-11932
CVE-2019-1193206 out 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC4
Double-Free BUG in WhatsApp exploit poc.
CVE-2019-1193205 out 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC77
timwr/CVE-2019-2215
CVE-2019-2215HIGHsob ataque04 out 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC
Rails 3 PoC of CVE-2019-5418
CVE-2019-5418HIGHsob ataque04 out 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
GitHub PoC208
Simple POC for exploiting WhatsApp double-free bug in DDGifSlurp in decoding.c in libpl_droidsonroids_gif
CVE-2019-1193204 out 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC4
This is a Automated Generate Payload for CVE-2019-11932 (WhatsApp Remote Code Execution)
CVE-2019-1193204 out 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC
Remediation task for CVE-2018-15686, CVE-2018-16866, and CVE-2018-16888 affecting SystemD in EL7
CVE-2018-15686HIGH03 out 2019
systemd: reexec state injection: fgets() on overlong lines leads to line splitting
41RISCO
abrir
GitHub PoC8
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 | XSS to RCE
CVE-2019-1256203 out 2019
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the mali
23RISCO
abrir
GitHub PoC267
double-free bug in WhatsApp exploit poc
CVE-2019-1193203 out 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC1
CVE-2019-17080
CVE-2019-1708002 out 2019
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by a
23RISCO
abrir
GitHub PoC20
CVE-2019-16759 vbulletin 5.0.0 till 5.5.4 pre-auth rce
CVE-2019-16759CRITICALsob ataque02 out 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC
A simple exploit for CVE-2007-2447
CVE-2007-244730 set 2019
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC246
ispy V1.0 - Eternalblue(ms17-010)/Bluekeep(CVE-2019-0708) Scanner and exploit ( Metasploit automation )
CVE-2019-0708CRITICALsob ataqueransomware30 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC624
Full exploit chain (CVE-2019-11708 & CVE-2019-9810) against Firefox on Windows 64-bit.
CVE-2019-11708CRITICALsob ataque29 set 2019
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
90RISCO
abrir
GitHub PoC75
it works on xp (all version sp2 sp3)
CVE-2019-0708CRITICALsob ataqueransomware29 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC21
PoC of CVE-2018-14847 Mikrotik Vulnerability using simple script
CVE-2018-14847CRITICALsob ataque29 set 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
GitHub PoC5
Exploit code for CVE-2019-16692
CVE-2019-1669227 set 2019
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is us
28RISCO
abrir
GitHub PoC21
vBulletin 5.x 未授权远程代码执行漏洞
CVE-2019-16759CRITICALsob ataque26 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC3
Nmap NSE Script to Detect vBulletin pre-auth 5.x RCE CVE-2019-16759
CVE-2019-16759CRITICALsob ataque26 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC1
Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)
CVE-2018-14847CRITICALsob ataque25 set 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
GitHub PoC5
Vbulletin rce exploit CVE-2019-16759
CVE-2019-16759CRITICALsob ataque25 set 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC10
PoC for distributed NTP reflection DoS (CVE-2013-5211)
CVE-2013-521124 set 2019
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
GitHub PoC3
CVE-2019-1367
CVE-2019-1367HIGHsob ataqueransomware24 set 2019
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
83RISCO
abrir
GitHub PoC6
CVE-2018-13379 Exploit
CVE-2018-13379CRITICALsob ataqueransomware24 set 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
GitHub PoC8
CVE-2018-14667-poc Richfaces漏洞环境及PoC
CVE-2018-14667CRITICALsob ataque23 set 2019
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISCO
abrir
GitHub PoC1.833
Exploit for CVE-2019-11043
CVE-2019-11043HIGHsob ataqueransomware23 set 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC1
Built a custom Virtual Machine, running Ubuntu 18.04.1 and Webmin 1.810. Using CVE-2019-15107 to exploit a backdoor in the Linux machine
CVE-2019-15107CRITICALsob ataqueransomware23 set 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC
Escape from Docker using CVE-2017-1000112 and CVE-2017-18344, including gaining root privilage, get all capbilities, namespace recovery, filesystem recovery, cgroup limitation bypass and seccomp bypass.
CVE-2017-100011217 set 2019
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISCO
abrir
GitHub PoC5
Crestron/Barco/Extron/InFocus/TeqAV Remote Command Injection (CVE-2019-3929) Metasploit Module
CVE-2019-3929CRITICALsob ataque17 set 2019
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RISCO
abrir
GitHub PoC1
1aa87148377/CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware17 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
anteriorpágina 415 / 466próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.