Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.647exploits catalogados
34.986CVEs com exploração pública
24.695testados em laboratório
14.014 exploits
GitHub PoC15
RTSPServer Code Execution Vulnerability CVE-2018-4013
CVE-2018-4013CRITICAL24 nov 2018
An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server l
48RISCO
abrir
GitHub PoC2
zeroto01/CVE-2018-14667
CVE-2018-14667CRITICALsob ataque23 nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISCO
abrir
GitHub PoC1
un4ckn0wl3z/CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware22 nov 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
libSSH bypass
CVE-2018-10933CRITICAL21 nov 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC
tafamace/CVE-2017-17485
CVE-2017-17485CRITICAL19 nov 2018
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o
60RISCO
abrir
GitHub PoC
tafamace/CVE-2016-0793
CVE-2016-079319 nov 2018
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Se
28RISCO
abrir
GitHub PoC83
Tool for CVE-2018-16323
CVE-2018-1632318 nov 2018
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that ha
35RISCO
abrir
GitHub PoC
cve-2018-14667 demo
CVE-2018-14667CRITICALsob ataque18 nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISCO
abrir
GitHub PoC3
CVE-2018-16509 (Ghostscript contains multiple -dSAFER sandbox bypass vulnerabilities)
CVE-2018-1650917 nov 2018
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISCO
abrir
GitHub PoC
Implementation of CVE-2018-10933 with CIDR block scanner
CVE-2018-10933CRITICAL16 nov 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC
My first try to code my own LPE exploit.
CVE-2017-1117613 nov 2018
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISCO
abrir
GitHub PoC9
CVE-2016-4657 web-kit vulnerability for ios 9.3, nintendo switch browser vulnerability
CVE-2016-4657HIGHsob ataque11 nov 2018
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISCO
abrir
GitHub PoC
Setup, exploit and patch for CVE-2009-4092 Simplog CSRF
CVE-2009-409210 nov 2018
Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote atta
23RISCO
abrir
GitHub PoC5
CMS Made Simple 2.2.7 RCE exploit
CVE-2018-1051709 nov 2018
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code ex
28RISCO
abrir
GitHub PoC1
Wordpress plugin Site-Editor v1.1.1 LFI exploit
CVE-2018-742209 nov 2018
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISCO
abrir
GitHub PoC10
PHPMyAdmin v4.8.0 and v.4.8.1 LFI exploit
CVE-2018-1261309 nov 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir
GitHub PoC3
beraphin/CVE-2018-6789
CVE-2018-6789CRITICALsob ataqueransomware08 nov 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir
GitHub PoC
matlink/CVE-2018-17456
CVE-2018-1745608 nov 2018
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISCO
abrir
GitHub PoC
来自:https://www.freebuf.com/articles/web/31700.html
CVE-2014-0160HIGHsob ataque08 nov 2018
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC21
an RCE (remote command execution) approach of CVE-2018-7750
CVE-2018-775006 nov 2018
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x
28RISCO
abrir
GitHub PoC14
Exploit for PlaySMS 1.4 authenticated RCE
CVE-2017-910106 nov 2018
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RISCO
abrir
GitHub PoC
bolonobolo/CVE-2018-14665
CVE-2018-1466502 nov 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISCO
abrir
GitHub PoC2
matlink/CVE-2018-17961
CVE-2018-1796101 nov 2018
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err
23RISCO
abrir
GitHub PoC2
Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473
CVE-2018-15473MEDIUM31 out 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC80
CVE-2018-8440 standalone exploit
CVE-2018-8440HIGHsob ataqueransomware31 out 2018
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
91RISCO
abrir
GitHub PoC
matlink/evince-cve-2017-1000083
CVE-2017-100008330 out 2018
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RISCO
abrir
GitHub PoC
matlink/cve-2017-1000083-atril-nautilus
CVE-2017-100008330 out 2018
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RISCO
abrir
GitHub PoC10
CVE-2018-2628漏洞工具包
CVE-2018-2628CRITICALsob ataque30 out 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
GitHub PoC1
kastellanos/CVE-2018-7602
CVE-2018-7602CRITICALsob ataqueransomware29 out 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISCO
abrir
GitHub PoC4
Exploit for vulnerability CVE-2018-6389 on wordpress sites
CVE-2018-638928 out 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
anteriorpágina 434 / 468próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.