Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.044exploits catalogados
35.296CVEs com exploração pública
24.695testados em laboratório
14.090 exploits
GitHub PoC8
CVE-2014-9322 (a.k.a BadIRET) proof of concept for Linux
CVE-2014-932219 jul 2017
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack S
23RISCO
abrir
GitHub PoC339
An internet scanner for exploit CVE-2017-0144 (Eternal Blue) & CVE-2017-0145 (Eternal Romance)
CVE-2017-0144HIGHsob ataqueransomware16 jul 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC2
Apache struts struts 2 048, CVE-2017-9791.
CVE-2017-9791CRITICALsob ataque07 jul 2017
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RISCO
abrir
GitHub PoC27
CVE-2017-9791
CVE-2017-9791CRITICALsob ataque07 jul 2017
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RISCO
abrir
GitHub PoC24
CVE-2014-1303 (WebKit Heap based BOF) proof of concept for Linux
CVE-2014-130307 jul 2017
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox
35RISCO
abrir
GitHub PoC2
POC for java RMI deserialization vulnerability
CVE-2017-324104 jul 2017
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versi
35RISCO
abrir
GitHub PoC
VideoLAN VLC media player 0.9.4 Media Player ty.c buffer overflow
CVE-2008-465402 jul 2017
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RISCO
abrir
GitHub PoC57
CVE-2017-0213 for command line
CVE-2017-0213HIGHsob ataqueransomware01 jul 2017
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RISCO
abrir
GitHub PoC
sUbc0ol/Microsoft-Word-CVE-2017-0199-
CVE-2017-0199HIGHsob ataqueransomware30 jun 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC
FreeSSHD Remote Authentication Bypass Vulnerability (freeSSHd 2.1.3)
CVE-2012-606630 jun 2017
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demons
50RISCO
abrir
GitHub PoC
sUbc0ol/CVE-2015-0235
CVE-2015-023530 jun 2017
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RISCO
abrir
GitHub PoC13
sUbc0ol/Apache-Struts2-RCE-Exploit-v2-CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware30 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
sUbc0ol/Apache-Struts-CVE-2017-5638-RCE-Mass-Scanner
CVE-2017-5638CRITICALsob ataqueransomware30 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC1
CVE-2015-1635
CVE-2015-1635CRITICALsob ataque29 jun 2017
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir
GitHub PoC
shaheemirza/CVE-2017-0213-
CVE-2017-0213HIGHsob ataqueransomware29 jun 2017
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RISCO
abrir
GitHub PoC
qwertyuiop12138/CVE-2016-10033
CVE-2016-10033CRITICALsob ataque28 jun 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
GitHub PoC
homjxi0e/CVE-2017-3078
CVE-2017-307826 jun 2017
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Text
35RISCO
abrir
GitHub PoC
InSpec profile to verify a node is patched and compliant for CVE-2017-8543
CVE-2017-8543CRITICALsob ataque19 jun 2017
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008
90RISCO
abrir
GitHub PoC2
os experiment 4 CVE-2016-5195
CVE-2016-5195HIGHsob ataque16 jun 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC
CVE-2017-5638 Test environment
CVE-2017-5638CRITICALsob ataqueransomware13 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
homjxi0e/CVE-2017-9430
CVE-2017-943008 jun 2017
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RISCO
abrir
GitHub PoC6
own implementation of the CVE-2017-1000367 sudo privilege escalation vulnerability in python
CVE-2017-100036708 jun 2017
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RISCO
abrir
GitHub PoC
homjxi0e/CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware08 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC1
Struts-RCE CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware08 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
homjxi0e/CVE-2017-7472
CVE-2017-747208 jun 2017
The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumptio
23RISCO
abrir
GitHub PoC
homjxi0e/CVE-2017-2671
CVE-2017-267108 jun 2017
The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock a
23RISCO
abrir
GitHub PoC
smancke/CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware07 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC84
Motorola Untethered Jailbreak: Exploiting CVE-2016-10277 for Secure Boot and Device Locking bypass
CVE-2016-1027706 jun 2017
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute
23RISCO
abrir
GitHub PoC259
Remote root exploit for the SAMBA CVE-2017-7494 vulnerability
CVE-2017-7494CRITICALsob ataqueransomware05 jun 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
GitHub PoC1
homjxi0e/CVE-2017-1000367
CVE-2017-100036704 jun 2017
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RISCO
abrir
anteriorpágina 454 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.