Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
14.096 exploits
GitHub PoC
homjxi0e/CVE-2017-9430
CVE-2017-943008 jun 2017
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RISCO
abrir
GitHub PoC
homjxi0e/CVE-2017-7472
CVE-2017-747208 jun 2017
The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumptio
23RISCO
abrir
GitHub PoC
smancke/CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware07 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC84
Motorola Untethered Jailbreak: Exploiting CVE-2016-10277 for Secure Boot and Device Locking bypass
CVE-2016-1027706 jun 2017
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute
23RISCO
abrir
GitHub PoC259
Remote root exploit for the SAMBA CVE-2017-7494 vulnerability
CVE-2017-7494CRITICALsob ataqueransomware05 jun 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
GitHub PoC1
homjxi0e/CVE-2017-1000367
CVE-2017-100036704 jun 2017
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RISCO
abrir
GitHub PoC56
Exploiting CVE-2016-4657 to JailBreak the Nintendo Switch
CVE-2016-4657HIGHsob ataque02 jun 2017
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISCO
abrir
GitHub PoC114
c0d3z3r0/sudo-CVE-2017-1000367
CVE-2017-100036730 mai 2017
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RISCO
abrir
GitHub PoC119
Exploits for CVE-2017-6008, a kernel pool buffer overflow leading to privilege escalation.
CVE-2017-600830 mai 2017
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in
23RISCO
abrir
GitHub PoC57
It is a simple script to exploit RCE for Samba (CVE-2017-7494 ).
CVE-2017-7494CRITICALsob ataqueransomware30 mai 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
GitHub PoC1
An exploit (and library) for CVE-2017-5638 - Apache Struts2 S2-045 bug.
CVE-2017-5638CRITICALsob ataqueransomware28 mai 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
An exploit for CVE-2017-5638 Remote Code Execution (RCE) Vulnerability in Apache Struts 2
CVE-2017-5638CRITICALsob ataqueransomware28 mai 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware27 mai 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC63
CVE-2017-7494 - Detection Scripts
CVE-2017-7494CRITICALsob ataqueransomware26 mai 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
GitHub PoC381
SambaCry exploit and vulnerable container (CVE-2017-7494)
CVE-2017-7494CRITICALsob ataqueransomware26 mai 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
GitHub PoC
homjxi0e/CVE-2017-7494
CVE-2017-7494CRITICALsob ataqueransomware25 mai 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
GitHub PoC181
Proof-of-Concept exploit for CVE-2017-7494(Samba RCE from a writable share)
CVE-2017-7494CRITICALsob ataqueransomware25 mai 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
GitHub PoC21
k0keoyo/CVE-2015-2546-Exploit
CVE-2015-2546HIGHsob ataqueransomware25 mai 2017
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
76RISCO
abrir
GitHub PoC3
Admidio 3.2.8 Cross-Site Request Forgery Assigned CVE Number: CVE-2017-8382
CVE-2017-838221 mai 2017
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user acc
23RISCO
abrir
GitHub PoC
WordPress 4.6 - Remote Code Execution (RCE) PoC Exploit
CVE-2016-10033CRITICALsob ataque19 mai 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
GitHub PoC7
Joomla 3.7 SQL injection (CVE-2017-8917)
CVE-2017-891719 mai 2017
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISCO
abrir
GitHub PoC
Install patch for CVE-2017-0145 AKA WannaCry.
CVE-2017-0145HIGHsob ataqueransomware19 mai 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC3
Simple script using nmap to detect CVE-2017-0143 MS17-010 in your network
CVE-2017-0143HIGHsob ataqueransomware16 mai 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC
cve-2016-0728 exploit and summary
CVE-2016-072816 mai 2017
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir
GitHub PoC88
CVE-2017-7269 to webshell or shellcode loader
CVE-2017-7269CRITICALsob ataque16 mai 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC1
Honeypot for Intel's AMT Firmware Vulnerability CVE-2017-5689
CVE-2017-5689CRITICALsob ataque12 mai 2017
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RISCO
abrir
GitHub PoC1
Cisco Catalyst Remote Code Execution PoC
CVE-2017-3881CRITICALsob ataque11 mai 2017
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RISCO
abrir
GitHub PoC
homjxi0e/CVE-2017-0290-
CVE-2017-029011 mai 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
45RISCO
abrir
GitHub PoC1
Code and vulnerable WordPress container for exploiting CVE-2016-10033
CVE-2016-10033CRITICALsob ataque10 mai 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
GitHub PoC9
RCE against WordPress 4.6; Python port of https://exploitbox.io/vuln/WordPress-Exploit-4-6-RCE-CODE-EXEC-CVE-2016-10033.html
CVE-2016-10033CRITICALsob ataque10 mai 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
anteriorpágina 455 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.