Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
14.096 exploits
GitHub PoC
towelroot
CVE-2014-3153HIGHsob ataque29 mai 2016
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISCO
abrir
GitHub PoC6
Magento Unauthorized Remote Code Execution (CVE-2016-4010)
CVE-2016-401025 mai 2016
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary
60RISCO
abrir
GitHub PoC86
Local privilege escalation for OS X 10.10.5 via CVE-2016-1828.
CVE-2016-182818 mai 2016
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISCO
abrir
GitHub PoC
Test modified buggy poc
CVE-2016-080115 mai 2016
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01
35RISCO
abrir
GitHub PoC15
Microsoft Office / COM Object DLL Planting
CVE-2015-613214 mai 2016
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
60RISCO
abrir
GitHub PoC78
abdsec/CVE-2016-0801
CVE-2016-080111 mai 2016
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01
35RISCO
abrir
GitHub PoC41
hexx0r/CVE-2016-0051
CVE-2016-005108 mai 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RISCO
abrir
GitHub PoC
NSE plugin for Nmap that scans a DotNetNuke (DNN) web application for an Administration Authentication Bypass vulnerability (CVE-2015-2794, EDB-ID: 39777).
CVE-2015-279407 mai 2016
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain S
60RISCO
abrir
GitHub PoC69
ImaegMagick Code Execution (CVE-2016-3714)
CVE-2016-3714HIGHsob ataque07 mai 2016
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RISCO
abrir
GitHub PoC1
Fix ImageMagick Command Injection (CVE-2016-3714) with Ansible.
CVE-2016-3714HIGHsob ataque05 mai 2016
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RISCO
abrir
GitHub PoC18
jpeanut/ImageTragick-CVE-2016-3714-RShell
CVE-2016-3714HIGHsob ataque05 mai 2016
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RISCO
abrir
GitHub PoC
Blind SQL injection brute force.
CVE-2008-697005 mai 2016
SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbi
23RISCO
abrir
GitHub PoC
tommiionfire/CVE-2016-3714
CVE-2016-3714HIGHsob ataque04 mai 2016
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RISCO
abrir
GitHub PoC
a puppet module in response to CVE-2016-3714
CVE-2016-3714HIGHsob ataque04 mai 2016
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RISCO
abrir
GitHub PoC193
Simple test for the May 2016 OpenSSL padding oracle (CVE-2016-2107)
CVE-2016-210703 mai 2016
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a
45RISCO
abrir
GitHub PoC125
QSEE Privilege Escalation Exploit using PRDiag* commands (CVE-2015-6639)
CVE-2015-663902 mai 2016
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to
23RISCO
abrir
GitHub PoC85
Exploit code for CVE-2016-1757
CVE-2016-175727 abr 2016
Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code
28RISCO
abrir
GitHub PoC1
b0b0505/CVE-2016-0846-PoC
CVE-2016-084619 abr 2016
libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.
23RISCO
abrir
GitHub PoC3
这个代码包含了CVE-2015-8660漏洞的利用代码,还有注释,出现问题的源代码,打了补丁后的代码
CVE-2015-866014 abr 2016
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RISCO
abrir
GitHub PoC36
arbitrary memory read/write by IMemroy OOB
CVE-2016-084608 abr 2016
libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.
23RISCO
abrir
GitHub PoC10
PoC attack server for CVE-2015-7547 buffer overflow vulnerability in glibc DNS stub resolver (public version)
CVE-2015-754705 abr 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISCO
abrir
GitHub PoC55
Exploitation Training -- CVE-2013-2028: Nginx Stack Based Buffer Overflow
CVE-2013-202823 mar 2016
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RISCO
abrir
GitHub PoC
must run this native binary with system privilege
CVE-2014-432223 mar 2016
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RISCO
abrir
GitHub PoC
Cve-2015-1538-1
CVE-2015-153820 mar 2016
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISCO
abrir
GitHub PoC
dachidahu/CVE-2016-0752
CVE-2016-0752HIGHsob ataque18 mar 2016
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.
100RISCO
abrir
GitHub PoC7
a exploit for cve-2016-0728
CVE-2016-072815 mar 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir
GitHub PoC8
PoC exploit server for CVE-2015-7547
CVE-2015-754710 mar 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISCO
abrir
GitHub PoC
JBoss Autopwn as featured at BlackHat Europe 2010 - this version incorporates CVE-2010-0738 the JBoss authentication bypass VERB manipulation vulnerability as discovered by Minded Security
CVE-2010-0738MEDIUMsob ataqueransomware08 mar 2016
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISCO
abrir
GitHub PoC
Script to test vulnarability for CVE-2015-0235
CVE-2015-023507 mar 2016
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RISCO
abrir
GitHub PoC31
Python script to exploit CVE-2015-4852.
CVE-2015-4852CRITICALsob ataque03 mar 2016
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISCO
abrir
anteriorpágina 462 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.