Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.647exploits catalogados
34.986CVEs com exploração pública
24.695testados em laboratório
14.014 exploits
GitHub PoC2
Simple poc of CVE-2018-8353 Microsoft Scripting Engine Use After Free
CVE-2018-835310 set 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
35RISCO
abrir
GitHub PoC
jezzus/CVE-2018-11776-Python-PoC
CVE-2018-11776HIGHsob ataque06 set 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC
likekabin/CVE-2018-8174-msf
CVE-2018-8174HIGHsob ataqueransomware06 set 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
GitHub PoC
jezzus/CVE-2018-4121
CVE-2018-412106 set 2018
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RISCO
abrir
GitHub PoC2
Apache Struts version analyzer (Ansible) based on CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware04 set 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC5
A remote code execution exploit for WebLogic based on CVE-2018-2628
CVE-2018-2628CRITICALsob ataque04 set 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
GitHub PoC95
Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit
CVE-2017-1000486CRITICALsob ataque03 set 2018
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISCO
abrir
GitHub PoC25
CVE-2017-10366: Oracle PeopleSoft 8.54, 8.55, 8.56 Java deserialization exploit
CVE-2017-1036603 set 2018
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Perform
35RISCO
abrir
GitHub PoC13
Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks
CVE-2018-638930 ago 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
GitHub PoC56
This tool takes advantage of CVE-2018-11776 and Shodan to perform mass exploitation of verified and vulnerable Apache Struts servers.
CVE-2018-11776HIGHsob ataque29 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC16
A simple exploit for Apache Struts RCE S2-057 (CVE-2018-11776)
CVE-2018-11776HIGHsob ataque28 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC3
tuxotron/cve-2018-11776-docker
CVE-2018-11776HIGHsob ataque28 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC2
Tiny script to enumerate users using CVE-2017-9554 (forget_passwd.cgi)
CVE-2017-955428 ago 2018
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RISCO
abrir
GitHub PoC21
Proof of Concept for CVE-2018-11776
CVE-2018-11776HIGHsob ataque27 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC303
An exploit for Apache Struts CVE-2018-11776
CVE-2018-11776HIGHsob ataque25 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC3
moayadalmalat/CVE-2017-12636
CVE-2017-1263625 ago 2018
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISCO
abrir
GitHub PoC4
Environment for CVE-2018-11776 / S2-057 (Apache Struts 2)
CVE-2018-11776HIGHsob ataque25 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC12
Vulnerable docker container for CVE-2018-11776
CVE-2018-11776HIGHsob ataque25 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC10
CVE-2018-11776(S2-057) EXPLOIT CODE
CVE-2018-11776HIGHsob ataque24 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC123
Working Python test and PoC for CVE-2018-11776, includes Docker lab
CVE-2018-11776HIGHsob ataque24 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC21
Simple poc of CVE-2018-8414 Windows Package Setting RCE Vulnerability
CVE-2018-8414HIGHsob ataque24 ago 2018
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows
93RISCO
abrir
GitHub PoC15
Creating a vulnerable environment and the PoC
CVE-2018-11776HIGHsob ataque23 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC111
PoC for Privilege Escalation in Windows 10 Diagnostics Hub Standard Collector Service
CVE-2018-095221 ago 2018
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary
23RISCO
abrir
GitHub PoC534
Exploit written in Python for CVE-2018-15473 with threading and export formats
CVE-2018-15473MEDIUM21 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC3
dangokyo/CVE-2015-5119
CVE-2015-5119HIGHsob ataque21 ago 2018
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RISCO
abrir
GitHub PoC
a exp for cve-2018-9948/9958 , current shellcode called win-calc
CVE-2018-994821 ago 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RISCO
abrir
GitHub PoC3
CVE-2018-15473 - Opensshenum is an user enumerator exploiting an OpenSsh bug
CVE-2018-15473MEDIUM19 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC159
OpenSSH 2.3 up to 7.4 Mass Username Enumeration (CVE-2018-15473).
CVE-2018-15473MEDIUM17 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC1
CVE-2018-8120 Windows LPE exploit
CVE-2018-8120HIGHsob ataqueransomware16 ago 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC258
PoC for CVE-2018-15133 (Laravel unserialize vulnerability)
CVE-2018-15133HIGHsob ataque14 ago 2018
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISCO
abrir
anteriorpágina 437 / 468próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.