Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.020exploits catalogados
35.276CVEs com exploração pública
24.695testados em laboratório
14.080 exploits
GitHub PoC98
This is a Metasploit module which exploits CVE-2017-11882 using the POC released here : https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-didnt-know-about.
CVE-2017-11882HIGHsob ataqueransomware21 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC22
CVE-2017-12149 JBOSS as 6.X反序列化(反弹shell版)
CVE-2017-12149CRITICALsob ataqueransomware21 nov 2017
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir
GitHub PoC494
Proof-of-Concept exploits for CVE-2017-11882
CVE-2017-11882HIGHsob ataqueransomware20 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC67
CVE-2017-8917 - SQL injection Vulnerability Exploit in Joomla 3.7.0
CVE-2017-891719 nov 2017
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISCO
abrir
GitHub PoC3
zhouat/cve-2017-11882
CVE-2017-11882HIGHsob ataqueransomware19 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC2
Exploits CVE-2016-10033 and CVE-2016-10045
CVE-2016-10033CRITICALsob ataque19 nov 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
GitHub PoC2
herbiezimmerman/2017-11-17-Maldoc-Using-CVE-2017-0199
CVE-2017-0199HIGHsob ataqueransomware17 nov 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC160
Chrome < 62 uxss exploit (CVE-2017-5124)
CVE-2017-512413 nov 2017
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject
23RISCO
abrir
GitHub PoC
Python exploit for CVE-2017-16806
CVE-2017-1680613 nov 2017
The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory
60RISCO
abrir
GitHub PoC1
Fork of github.com/spring-projects/spring-data-rest (vulnerable to CVE-2017-8046)
CVE-2017-804608 nov 2017
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISCO
abrir
GitHub PoC4
Unrestricted file upload vulnerability - Web Viewer 1.0.0.193 on Samsung SRN-1670D
CVE-2017-1652405 nov 2017
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_u
50RISCO
abrir
GitHub PoC5
Exploit for the linux kernel vulnerability CVE-2017-5123
CVE-2017-512303 nov 2017
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RISCO
abrir
GitHub PoC2
RTF de-obfuscator for CVE-2017-0199 documents to find URLs statically.
CVE-2017-0199HIGHsob ataqueransomware03 nov 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC2
tomcat-put-cve-2017-12615
CVE-2017-12615HIGHsob ataqueransomware01 nov 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
GitHub PoC1
linux kernel exploit
CVE-2017-512331 out 2017
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RISCO
abrir
GitHub PoC
This is the Apache Struts CVE-2017-5638 struts 2 vulnerability. The same CVE that resulted in the equifax database breach.
CVE-2017-5638CRITICALsob ataqueransomware30 out 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
skyformat99/dnsmasq-2.4.1-fix-CVE-2017-14491
CVE-2017-1449130 out 2017
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut
45RISCO
abrir
GitHub PoC2
This exploit was written to study some concepts, enjoy!
CVE-2010-422128 out 2017
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow rem
60RISCO
abrir
GitHub PoC1
dewankpant/CVE-2017-16567
CVE-2017-1656724 out 2017
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. T
23RISCO
abrir
GitHub PoC
Wordpress Username Enumeration /CVE-2017-5487,WordPress < 4.7.1 -
CVE-2017-548722 out 2017
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISCO
abrir
GitHub PoC1
Dirty COW (CVE-2016-5195) Testing
CVE-2016-5195HIGHsob ataque19 out 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC
An exploit for Apache Struts CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware19 out 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
A simple python shell-like exploit for the Shellschok CVE-2014-6271 bug.
CVE-2014-6271CRITICALsob ataque17 out 2017
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
PHPMailer < 5.2.18 Remote Code Execution
CVE-2016-1003417 out 2017
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.
35RISCO
abrir
GitHub PoC
CVE-2010-3332 Oracle Padding Vulnerability in Microsoft ASP.NET
CVE-2010-333211 out 2017
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Intern
35RISCO
abrir
GitHub PoC1
Ready to use, weaponized dirtycow (CVE-2016-5195)
CVE-2016-5195HIGHsob ataque11 out 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC1
Exploit Safari CVE-2017-7089
CVE-2017-708911 out 2017
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
23RISCO
abrir
GitHub PoC1
Apache HTTP Server 2.4.23 vulnerability study (CVE-2016-8740)
CVE-2016-874011 out 2017
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2
45RISCO
abrir
GitHub PoC138
Blueborne CVE-2017-0781 Android heap overflow vulnerability
CVE-2017-078109 out 2017
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RISCO
abrir
GitHub PoC27
CVE-2017-13868: Information leak of uninitialized kernel heap data in XNU.
CVE-2017-1386807 out 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISCO
abrir
anteriorpágina 450 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.