Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.602exploits catalogados
34.985CVEs com exploração pública
24.695testados em laboratório
13.972 exploits
GitHub PoC1
收集网上CVE-2018-0708的poc和exp(目前没有找到exp)
CVE-2018-070825 jul 2019
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo
28RISCO
abrir
GitHub PoC10
CVE-2019–11581 PoC
CVE-2019-11581CRITICALsob ataque25 jul 2019
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RISCO
abrir
GitHub PoC3
Exim Honey Pot for CVE-2019-10149 exploit attempts.
CVE-2019-10149CRITICALsob ataque25 jul 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir
GitHub PoC14
POC for CVE-2019-14339 Canon PRINT 2.5.5
CVE-2019-1433925 jul 2019
The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly res
23RISCO
abrir
GitHub PoC1
收集网上CVE-2018-0708的poc和exp(目前没有找到exp)
CVE-2019-0708CRITICALsob ataqueransomware25 jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC6
cve-2016-6187
CVE-2016-618723 jul 2019
The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buff
23RISCO
abrir
GitHub PoC293
Public work for CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware23 jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC1
My old sysret / ptrace PoC
CVE-2014-469923 jul 2019
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved
23RISCO
abrir
GitHub PoC2
cve-2014-4014
CVE-2014-401423 jul 2019
The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inappli
23RISCO
abrir
GitHub PoC1
CVE-2017-16995 eBPF PoC for Ubuntu 16.04
CVE-2017-1699523 jul 2019
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
GitHub PoC1
perf_swevent_init
CVE-2013-2094HIGHsob ataque23 jul 2019
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RISCO
abrir
GitHub PoC
Y0n0Y/cve-2018-8120-exp
CVE-2018-8120HIGHsob ataqueransomware20 jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC
CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware18 jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC3
Scanner PoC for CVE-2019-0708 RDP RCE vuln
CVE-2019-0708CRITICALsob ataqueransomware18 jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC18
CVE-2019-0708 Exploit Tool
CVE-2019-0708CRITICALsob ataqueransomware18 jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC1
Proof of calc for CVE-2019-6453
CVE-2019-645318 jul 2019
mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The a
35RISCO
abrir
GitHub PoC6
A fix for CVE-2019-11358 (prototype pollution in jquery)
CVE-2019-1135818 jul 2019
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISCO
abrir
GitHub PoC105
CVE-2019-11580 Atlassian Crowd and Crowd Data Center RCE
CVE-2019-11580CRITICALsob ataqueransomware17 jul 2019
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RISCO
abrir
GitHub PoC1
软件系统安全结课作业:[漏洞复现] CVE-2018-4878 Flash 0day
CVE-2018-4878HIGHsob ataqueransomware17 jul 2019
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
GitHub PoC1
CVE-2019-2107
CVE-2019-210717 jul 2019
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th
23RISCO
abrir
GitHub PoC92
Atlassian JIRA Template injection vulnerability RCE
CVE-2019-11581CRITICALsob ataque16 jul 2019
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RISCO
abrir
GitHub PoC
Proof of concept tool to exploit the directory traversal and local file inclusion vulnerability that resides in the Sahi-pro web application CVE-2019-13063
CVE-2019-1306315 jul 2019
Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the sc
28RISCO
abrir
GitHub PoC23
Metasploit module for massive Denial of Service using #Bluekeep vector.
CVE-2019-0708CRITICALsob ataqueransomware14 jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC1
CVE-2019-9766 React
CVE-2019-976614 jul 2019
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RISCO
abrir
GitHub PoC4
R/W
CVE-2019-053912 jul 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISCO
abrir
GitHub PoC14
thepwnrip/leHACK-Analysis-of-CVE-2018-8453
CVE-2018-8453HIGHsob ataqueransomware08 jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC4
PHP-CGI-REMOTE_CVE-2012-1823, UnrealIRCd, MySQL, PostgreSQL and SSH bruteforce, VSFTPD2.3.4, samba CVE-2007-2447, JAVA RMI Server, distcc daemon, misconfigured NFS files, etc.
CVE-2012-1823CRITICALsob ataque05 jul 2019
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISCO
abrir
GitHub PoC4
PHP-CGI-REMOTE_CVE-2012-1823, UnrealIRCd, MySQL, PostgreSQL and SSH bruteforce, VSFTPD2.3.4, samba CVE-2007-2447, JAVA RMI Server, distcc daemon, misconfigured NFS files, etc.
CVE-2007-244705 jul 2019
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC12
ze0r/CVE-2019-0708-exp
CVE-2019-0708CRITICALsob ataqueransomware04 jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
https://github.com/Yt1g3r/CVE-2019-3396_EXP.git
CVE-2019-3396CRITICALsob ataqueransomware01 jul 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
anteriorpágina 419 / 466próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.