Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.020exploits catalogados
35.276CVEs com exploração pública
24.695testados em laboratório
14.080 exploits
GitHub PoC
Phusion WebServer 1.0 - Directory Traversal
CVE-2002-028803 abr 2018
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (t
23RISCO
abrir
GitHub PoC
Phusion WebServer 1.0 - 'URL' Remote Buffer Overflow
CVE-2002-028903 abr 2018
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary cod
28RISCO
abrir
GitHub PoC
Airsensor M520 - HTTPd Unauthenticated Remote Denial of Service / Buffer Overflow (PoC)
CVE-2007-503603 abr 2018
Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated
23RISCO
abrir
GitHub PoC
Cisco VPN Client - Integer Overflow Denial of Service
CVE-2009-411802 abr 2018
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0
23RISCO
abrir
GitHub PoC267
A code demonstrating CVE-2018-0886
CVE-2018-088602 abr 2018
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 S
45RISCO
abrir
GitHub PoC49
An implementation of CVE-2016-0974 for the Nintendo Wii.
CVE-2016-097401 abr 2018
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and
35RISCO
abrir
GitHub PoC
tomcat7.x远程命令执行
CVE-2017-12615HIGHsob ataqueransomware01 abr 2018
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
GitHub PoC354
💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002
CVE-2018-7600CRITICALsob ataqueransomware30 mar 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC114
CVE-2018-7600 Drupal RCE
CVE-2018-7600CRITICALsob ataqueransomware30 mar 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC
lucad93/CVE-2018-3810
CVE-2018-381029 mar 2018
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RISCO
abrir
GitHub PoC5
CVE-2017-14322 Interspire Email Marketer (emailmarketer) Exploit
CVE-2017-1432227 mar 2018
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior
35RISCO
abrir
GitHub PoC
likekabin/CVE-2017-0199
CVE-2017-0199HIGHsob ataqueransomware22 mar 2018
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC1
A version of CVE-2017-0213 that I plan to use with an Empire stager
CVE-2017-0213HIGHsob ataqueransomware21 mar 2018
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RISCO
abrir
GitHub PoC26
This repository contains the POC of an exploit for node-jose < 0.11.0
CVE-2018-011420 mar 2018
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir
GitHub PoC1
Apache Struts CVE-2017-5638 RCE exploitation
CVE-2017-5638CRITICALsob ataqueransomware20 mar 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
likekabin/CVE-2017-0213
CVE-2017-0213HIGHsob ataqueransomware19 mar 2018
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RISCO
abrir
GitHub PoC
Linux Kernel Version 4.14 - 4.4 (Ubuntu && Debian)
CVE-2017-1699519 mar 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
GitHub PoC
CVE-2018-6789
CVE-2018-6789CRITICALsob ataqueransomware16 mar 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir
GitHub PoC51
PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM
CVE-2018-2380MEDIUMsob ataqueransomware14 mar 2018
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information pr
68RISCO
abrir
GitHub PoC2
Golang exploit for CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware14 mar 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC1
PoC for SpringBreak (CVE-2017-8046)
CVE-2017-804612 mar 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISCO
abrir
GitHub PoC95
Exploitation Tool for CVE-2017-3066 targeting Adobe Coldfusion 11/12
CVE-2017-3066CRITICALsob ataque12 mar 2018
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RISCO
abrir
GitHub PoC37
PoC code for CVE-2017-13253
CVE-2017-1325312 mar 2018
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. Thi
23RISCO
abrir
GitHub PoC
fibonascii/CVE-2004-0558
CVE-2004-055810 mar 2018
The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of s
28RISCO
abrir
GitHub PoC17
This is a Java program that exploits Spring Break vulnerability (CVE-2017-8046).
CVE-2017-804609 mar 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISCO
abrir
GitHub PoC2
Exploit iOS 11.2.x by ZIMPERIUM and semi-completed by me. Sandbox escapes on CVE-2018-4087.
CVE-2018-408708 mar 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RISCO
abrir
GitHub PoC14
WARNING: This is a vulnerable application to test the exploit for the Spring Break vulnerability (CVE-2017-8046). Run it at your own risk!
CVE-2017-804608 mar 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISCO
abrir
GitHub PoC2
Tries to exploit a WordPress vulnerability (CVE-2018-6389) which can be used to cause a Denial of Service.
CVE-2018-638904 mar 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
GitHub PoC130
Improved DOS exploit for wordpress websites (CVE-2018-6389)
CVE-2018-638904 mar 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
GitHub PoC8
Joomla - Component Google Map Landkarten <= 4.2.3 - SQL Injection
CVE-2018-639602 mar 2018
SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a l
28RISCO
abrir
anteriorpágina 445 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.