Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.649exploits catalogados
34.987CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.899GitHub PoC 14.014VulnCheck XDB 8.571Nuclei 4.250Metasploit 3.472✓ só verificadosrecentespopularesrisco
14.014 exploits
GitHub PoC
kaisaryousuf/CVE-2018-8208
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RISCO
abrir ↗GitHub PoC★ 118
Implements the POP/MOV SS (CVE-2018-8897) vulnerability by leveraging SYSCALL to perform a local privilege escalation (LPE).
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RISCO
abrir ↗GitHub PoC★ 178
Exploit for CVE-2018-4233, a WebKit JIT optimization bug used during Pwn2Own 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
68RISCO
abrir ↗GitHub PoC★ 6
Foxit Reader version 9.0.1.1049 Use After Free with ASLR and DEP bypass on heap
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RISCO
abrir ↗GitHub PoC★ 96
A Burp extension to detect and exploit versions of Telerik Web UI vulnerable to CVE-2017-9248.
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISCO
abrir ↗GitHub PoC★ 61
CVE-2007-2447 - Samba usermap script
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir ↗GitHub PoC★ 2
Crestron AirMedia AM-100 Traversal and Hashdump Metasploit Modules
Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13
28RISCO
abrir ↗GitHub PoC★ 20
on Mac 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RISCO
abrir ↗GitHub PoC★ 7
A demo exploit of CVE-2016-9079 on Ubuntu x64
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RISCO
abrir ↗GitHub PoC
PercussiveElbow/CVE-2004-2271-MiniShare-1.4.1-Buffer-Overflow
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RISCO
abrir ↗GitHub PoC★ 8
CVE-2013-6117
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RISCO
abrir ↗GitHub PoC★ 2
This Python 3 script is for uploading shell (and other files) to Windows Server / Linux via Oracle 11g R2 (CVE-2010-3600).
Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and En
60RISCO
abrir ↗GitHub PoC
likekabin/CVE-2018-4121
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RISCO
abrir ↗GitHub PoC
likekabin/ShareDoc_cve-2015-5477
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISCO
abrir ↗GitHub PoC★ 49
Collection of exploits/POC for PrestaShop cookie vulnerabilities (CVE-2018-13784)
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RISCO
abrir ↗GitHub PoC
Linux Null pointer dereference
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socke
43RISCO
abrir ↗GitHub PoC
happynote3966/CVE-2018-7602
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISCO
abrir ↗GitHub PoC
happynote3966/CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗GitHub PoC★ 1
dd
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir ↗GitHub PoC★ 1
happynote3966/CVE-2014-3704
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISCO
abrir ↗GitHub PoC★ 5
XML external entity (XXE) vulnerability in /ssc/fm-ws/services in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10 (0day CVE-2018-12463)
MFSBGN03811 rev.1 - Fortify Software Security Center (SSC), Multiple vulnerabilities
46RISCO
abrir ↗GitHub PoC★ 30
Analysis of VBS exploit CVE-2018-8174
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir ↗GitHub PoC★ 1
lonehand/Oracle-WebLogic-CVE-2017-10271-master
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗GitHub PoC★ 3
likekabin/CVE-2018-2628
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir ↗GitHub PoC
Aruthw/CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗GitHub PoC
qy1202/https-github.com-Ridter-CVE-2017-11882-
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir ↗GitHub PoC★ 11
Exploitable target to CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir ↗GitHub PoC
stevenlinfeng/CVE-2018-2628
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir ↗GitHub PoC
Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising. In this case, the malvertisements have a hidden iframe that redirects victims to Rig’s landing page, which includes an exploit for CVE-2018-8174 and shellcode. This enables remote code execution of the shellcode obfuscated in the landing page. After successful exploitation, a second-stage downloader is retrieved, which appears to be a variant of SmokeLoader due to the URL. It would then download the final payload, a Monero miner.
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir ↗GitHub PoC★ 1
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Text Annotations. When setting the point attribute, the process does not properly validate the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.