Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.647exploits catalogados
34.986CVEs com exploração pública
24.695testados em laboratório
14.014 exploits
GitHub PoC12
CVE-2018-15982_EXP_IE
CVE-2018-15982HIGHsob ataqueransomware12 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
GitHub PoC29
Aggressor Script to launch IE driveby for CVE-2018-15982.
CVE-2018-15982HIGHsob ataqueransomware12 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
GitHub PoC11
Script and metasploit module for CVE-2018-15982
CVE-2018-15982HIGHsob ataqueransomware11 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
GitHub PoC
Just My ports of CVE-2017-8759
CVE-2017-8759HIGHsob ataque11 dez 2018
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISCO
abrir
GitHub PoC1
securifera/CVE-2018-16156-Exploit
CVE-2018-1615611 dez 2018
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes u
23RISCO
abrir
GitHub PoC1
CVE-2014-0160
CVE-2014-0160HIGHsob ataque10 dez 2018
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
Microsoft Equation 3.0/Convert python2 to python3
CVE-2017-11882HIGHsob ataqueransomware10 dez 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC179
exp of CVE-2018-15982
CVE-2018-15982HIGHsob ataqueransomware10 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
GitHub PoC4
个人整理的Centos7.x + Kubernetes-1.12.3 + Dashboard-1.8.3 无 CVE-2018-1002105 漏洞的master节点全自动快速一键安装部署文件,适用于测试环境,生产环境的快速安装部署
CVE-2018-1002105CRITICAL10 dez 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISCO
abrir
GitHub PoC2
Proof of consept for CVE-2018-17431
CVE-2018-1743108 dez 2018
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RISCO
abrir
GitHub PoC9
Unrestricted file upload in Adobe ColdFusion
CVE-2018-15961CRITICALsob ataque06 dez 2018
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISCO
abrir
GitHub PoC13
CVE-2018-15982_PoC
CVE-2018-15982HIGHsob ataqueransomware06 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
GitHub PoC222
PoC for CVE-2018-1002105.
CVE-2018-1002105CRITICAL06 dez 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISCO
abrir
GitHub PoC191
Test utility for cve-2018-1002105
CVE-2018-1002105CRITICAL05 dez 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISCO
abrir
GitHub PoC
uzzzval/cve-2004-2167
CVE-2004-216705 dez 2018
Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary
28RISCO
abrir
GitHub PoC
Flash sources for CVE-2018-15982 used by NK
CVE-2018-15982HIGHsob ataqueransomware05 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
GitHub PoC4
dnsmasq rop exploit with NX bypass
CVE-2017-1449304 dez 2018
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execu
45RISCO
abrir
GitHub PoC
CVE-2014-8682
CVE-2014-868204 dez 2018
Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow r
50RISCO
abrir
GitHub PoC1
A collection of code pertaining to CVE-2016-0728 (various authors)
CVE-2016-072803 dez 2018
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir
GitHub PoC
A VENOM (CVE-2015-3456) Exploit / PoC written in C.
CVE-2015-345603 dez 2018
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a
28RISCO
abrir
GitHub PoC
This is an exploitation guide for CVE-2016-2233
CVE-2016-223303 dez 2018
Stack-based buffer overflow in the inbound_cap_ls function in common/inbound.c in HexChat 2.10.2 allows remote IRC serve
35RISCO
abrir
GitHub PoC
CVE-2014-4511
CVE-2014-451103 dez 2018
Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in
60RISCO
abrir
GitHub PoC104
CVE-2018-8021 Proof-Of-Concept and Exploit
CVE-2018-802102 dez 2018
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to pos
35RISCO
abrir
GitHub PoC
CVE-2016-1240 exploit and patch
CVE-2016-124002 dez 2018
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debia
38RISCO
abrir
GitHub PoC39
PrestaShop (1.6.x <= 1.6.1.23 or 1.7.x <= 1.7.4.4) Back Office Remote Code Execution (CVE-2018-19126)
CVE-2018-1912601 dez 2018
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file u
28RISCO
abrir
GitHub PoC50
All about CVE-2018-14667; From what it is to how to successfully exploit it.
CVE-2018-14667CRITICALsob ataque30 nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISCO
abrir
GitHub PoC
lol-fi/cve-2011-4862
CVE-2011-486228 nov 2018
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISCO
abrir
GitHub PoC1
about CVE-2018-14667 from RichFaces Framework 3.3.4
CVE-2018-14667CRITICALsob ataque28 nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISCO
abrir
GitHub PoC1
The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10
CVE-2018-7691MEDIUM26 nov 2018
MFSBGN03835 rev.1 - Fortify Software Security Center (SSC), Remote Unauthorized Access
33RISCO
abrir
GitHub PoC1
The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10
CVE-2018-7690MEDIUM26 nov 2018
MFSBGN03835 rev.1 - Fortify Software Security Center (SSC), Remote Unauthorized Access
33RISCO
abrir
anteriorpágina 433 / 468próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.