Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
14.096 exploits
GitHub PoC
Proof-of-Concept CVE-2016-0199
CVE-2016-019916 out 2016
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RISCO
abrir
GitHub PoC1
Reproducible exploits for: CVE-2016-1240 CVE-2008-2938 CVE-2014-2064 CVE-2014-1904
CVE-2016-124013 out 2016
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debia
38RISCO
abrir
GitHub PoC1
Reproducible exploits for: CVE-2016-1240 CVE-2008-2938 CVE-2014-2064 CVE-2014-1904
CVE-2008-293813 out 2016
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16,
60RISCO
abrir
GitHub PoC103
OS X 10.11.6 LPE PoC for CVE-2016-4655 / CVE-2016-4656
CVE-2016-4655MEDIUMsob ataque02 out 2016
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RISCO
abrir
GitHub PoC27
CVE-2016-2776
CVE-2016-277630 set 2016
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RISCO
abrir
GitHub PoC
just some research notes
CVE-2015-386430 set 2016
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RISCO
abrir
GitHub PoC
KosukeShimofuji/CVE-2016-2776
CVE-2016-277628 set 2016
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RISCO
abrir
GitHub PoC
whiteHat001/cve-2010-3333
CVE-2010-3333HIGHsob ataque26 set 2016
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2
100RISCO
abrir
GitHub PoC3
这里保存着我学习CVE-2012-1889这个漏洞的利用所用到的文件
CVE-2012-1889HIGHsob ataque25 set 2016
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attacker
100RISCO
abrir
GitHub PoC163
Public repository for improvements to the EXTRABACON exploit
CVE-2016-6366HIGHsob ataque20 set 2016
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Service
100RISCO
abrir
GitHub PoC9
0ldSQL_MySQL_RCE_exploit.py (ver. 1.0) (CVE-2016-6662) MySQL Remote Root Code Execution / Privesc PoC Exploit For testing purposes only. Do no harm.
CVE-2016-666220 set 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISCO
abrir
GitHub PoC
research CVE-2016-6662
CVE-2016-666216 set 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISCO
abrir
GitHub PoC1
Simple ansible playbook to patch mysql servers against CVE-2016-6662
CVE-2016-666215 set 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISCO
abrir
GitHub PoC
MySQL server CVE-2016-6662 patch playbook
CVE-2016-666214 set 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISCO
abrir
GitHub PoC33
Verification tools for CVE-2016-1287
CVE-2016-128708 set 2016
Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0
45RISCO
abrir
GitHub PoC2
CVE-2014-6332 ZeroDay POC - Starts PowerShell
CVE-2014-6332HIGHsob ataque29 ago 2016
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISCO
abrir
GitHub PoC1
linux 提权
CVE-2012-005622 jul 2016
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when
28RISCO
abrir
GitHub PoC11
This is a python-based standalone exploit for CVE-2006-6184. This exploit triggers a stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote attackers to cause a denial of service or execute arbitrary code.
CVE-2006-618421 jul 2016
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RISCO
abrir
GitHub PoC1
CVE-2016-3962-Exploit
CVE-2016-396217 jul 2016
Stack-based buffer overflow in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTI
23RISCO
abrir
GitHub PoC
KosukeShimofuji/CVE-2016-5734
CVE-2016-573408 jul 2016
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RISCO
abrir
GitHub PoC1
JBoss Autopwn CVE-2010-0738 JBoss authentication bypass
CVE-2010-0738MEDIUMsob ataqueransomware02 jul 2016
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISCO
abrir
GitHub PoC
CVE-2016-4971 written in nodejs
CVE-2016-497102 jul 2016
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RISCO
abrir
GitHub PoC364
Exploit that extracts Qualcomm's KeyMaster keys using CVE-2015-6639 and CVE-2016-2431
CVE-2015-663930 jun 2016
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to
23RISCO
abrir
GitHub PoC3
对CVE-2016-0189漏洞补丁的分析
CVE-2016-0189HIGHsob ataque25 jun 2016
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RISCO
abrir
GitHub PoC114
Proof-of-Concept exploit for CVE-2016-0189 (VBScript Memory Corruption in IE11)
CVE-2016-0189HIGHsob ataque22 jun 2016
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RISCO
abrir
GitHub PoC
CVE-2016-0051 样本库
CVE-2016-005116 jun 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RISCO
abrir
GitHub PoC2
Docker container implementing tests for CVE-2016-2107 - LuckyNegative20
CVE-2016-210709 jun 2016
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a
45RISCO
abrir
GitHub PoC1
A PoC of CVE-2016-2098 (rails4.2.5.1 / view render)
CVE-2016-209807 jun 2016
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISCO
abrir
GitHub PoC
thejackerz/scanner-exploit-joomla-CVE-2015-8562
CVE-2015-856207 jun 2016
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISCO
abrir
GitHub PoC4
MySQL DoS in the Procedure Analyse Function – CVE-2015-4870
CVE-2015-487030 mai 2016
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated
35RISCO
abrir
anteriorpágina 461 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.