Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
14.096 exploits
GitHub PoC724
Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft Office RCE. It could generate a malicious RTF/PPSX file and deliver metasploit / meterpreter / other payload to victim without any complex configuration.
CVE-2017-0199HIGHsob ataqueransomware17 abr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC
homjxi0e/CVE-2016-7255
CVE-2016-7255HIGHsob ataque15 abr 2017
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISCO
abrir
GitHub PoC2
homjxi0e/CVE-2017-0108
CVE-2017-010815 abr 2017
The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 20
35RISCO
abrir
GitHub PoC7
Addressbar spoofing through blob URL (Firefox browser). An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by blob: as the protocol, leading to user confusion and further spoofing attacks.
CVE-2017-541514 abr 2017
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leadin
28RISCO
abrir
GitHub PoC
homjxi0e/cve-2017-7269
CVE-2017-7269CRITICALsob ataque13 abr 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC12
SyFi/cve-2017-0199
CVE-2017-0199HIGHsob ataqueransomware13 abr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC
ryhanson/CVE-2017-0199
CVE-2017-0199HIGHsob ataqueransomware13 abr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC4
Exploit for CVE-2017-6971 remote command execution in nfsen 1.3.7.
CVE-2017-697110 abr 2017
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary comma
28RISCO
abrir
GitHub PoC213
CVE-2017-3881 Cisco Catalyst Remote Code Execution PoC
CVE-2017-3881CRITICALsob ataque10 abr 2017
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RISCO
abrir
GitHub PoC10
Strutsy - Mass exploitation of Apache Struts (CVE-2017-5638) vulnerability
CVE-2017-5638CRITICALsob ataqueransomware09 abr 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC5
Ruby Exploit for IIS 6.0 Buffer Overflow (CVE-2017-7269)
CVE-2017-7269CRITICALsob ataque06 abr 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC92
iis6 exploit 2017 CVE-2017-7269
CVE-2017-7269CRITICALsob ataque05 abr 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC134
fixed msf module for cve-2017-7269
CVE-2017-7269CRITICALsob ataque30 mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC
whiteHat001/cve-2017-7269picture
CVE-2017-7269CRITICALsob ataque30 mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC
Poc for iis6.0
CVE-2017-7269CRITICALsob ataque30 mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC1
exec 8 bytes command
CVE-2017-7269CRITICALsob ataque29 mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC89
CVE-2017-7269 回显PoC ,用于远程漏洞检测..
CVE-2017-7269CRITICALsob ataque29 mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC22
An exploit for Microsoft IIS 6.0 CVE-2017-7269
CVE-2017-7269CRITICALsob ataque29 mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC2
Struts2 RCE CVE-2017-5638 CLI shell
CVE-2017-5638CRITICALsob ataqueransomware28 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
mcassano/cve-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware26 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware23 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC6
k0keoyo/CVE-2017-0038-EXP-C-JS
CVE-2017-003822 mar 2017
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
45RISCO
abrir
GitHub PoC
ottimo/burp-alfresco-referer-proxy-cve-2014-9301
CVE-2014-930121 mar 2017
Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows
23RISCO
abrir
GitHub PoC21
st2-046-poc CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware21 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC1
S2-046|S2-045: Struts 2 Remote Code Execution vulnerability(CVE-2017-5638)
CVE-2017-5638CRITICALsob ataqueransomware21 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC2
The DGS-1510 Websmart switch series firmware has been found to have security vulneratiblies. The vulnerabilities include unauthenticated command bypass and unauthenticated information disclosure.
CVE-2017-620620 mar 2017
D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devi
28RISCO
abrir
GitHub PoC1
boompig/cve-2016-6662
CVE-2016-666219 mar 2017
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISCO
abrir
GitHub PoC4
CVE-2016-5195 dirtycow by timwr automated multi file patch tool
CVE-2016-5195HIGHsob ataque18 mar 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC3
Apache Struts (CVE-2017-5638) Shell
CVE-2017-5638CRITICALsob ataqueransomware17 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC2
Struts2 RCE CVE-2017-5638 non-intrusive check shell script
CVE-2017-5638CRITICALsob ataqueransomware16 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
anteriorpágina 457 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.