Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.175GitHub PoC 14.096VulnCheck XDB 8.607Nuclei 4.255Metasploit 3.474✓ só verificadosrecentespopularesrisco
14.096 exploits
GitHub PoC★ 3
Crash PoC
Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7
23RISCO
abrir ↗GitHub PoC★ 17
Python script to generate a malicious MP4 file and start a CherryPy web server hosting a simple HTML page with the embedded file. Exploits another Stagefright vulnerability, the integer overflow (CVE-2015-3864).
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RISCO
abrir ↗GitHub PoC★ 5
Estudo e apresentação do bug CVE-2014-4943 para a disciplina MAC0448
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by
23RISCO
abrir ↗GitHub PoC★ 5
My exploit for kernel exploitation
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISCO
abrir ↗GitHub PoC★ 1
PoC code for vBulletin PreAuth vulnerability
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RISCO
abrir ↗GitHub PoC★ 1
Joomla! 3.2 to 3.4.4 - SQL Injection (CVE-2015-7297, CVE-2015-7857, and CVE-2015-7858)
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISCO
abrir ↗GitHub PoC★ 23
Script to extract malicious payload and decoy document from CVE-2015-1641 exploit documents
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Comp
93RISCO
abrir ↗GitHub PoC
Dockerfile for testing CVE-2014-0160 Heartbleed exploitation.
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗GitHub PoC
Quick and dirty .py for checking (CVE-2015-1635) MS15-034 + DoS attack option
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir ↗GitHub PoC
gina-alaska/bash-cve-2014-7169-cookbook
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISCO
abrir ↗GitHub PoC★ 11
CVE-2015-3073 PoC
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass inten
28RISCO
abrir ↗GitHub PoC★ 11
Network Scanner for OpenSSL Memory Leak (CVE-2014-0160)
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗GitHub PoC★ 12
Archive from the article CVE-2015-5119 Flash ByteArray UaF: A beginner's walkthrough
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RISCO
abrir ↗GitHub PoC★ 205
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISCO
abrir ↗GitHub PoC★ 1
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISCO
abrir ↗GitHub PoC★ 3
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISCO
abrir ↗GitHub PoC★ 1
drone789/CVE-2012-1823
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISCO
abrir ↗GitHub PoC★ 1
Just an attempt to adapt for Note 4, I do not know what I am doing.
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RISCO
abrir ↗GitHub PoC★ 2
An implementation of the CVE-2015-2153 exploit.
The rpki_rtr_pdu_print function in print-rpki-rtr.c in the TCP printer in tcpdump before 4.7.2 allows remote attackers t
28RISCO
abrir ↗GitHub PoC
Windows 2k3 tcpip.sys Privilege Escalation
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RISCO
abrir ↗GitHub PoC★ 1
PoC exploit for CVE-2015-5477 in php
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISCO
abrir ↗GitHub PoC★ 3
PoC - Binary patches for CVE-2015-3864 (NOT for production, use at your own risk)
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RISCO
abrir ↗GitHub PoC★ 24
CVE-2014-4322 Exploit
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RISCO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2015-4495 / mfsa2015-78
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
98RISCO
abrir ↗GitHub PoC★ 1
PoC for BIND9 TKEY assert DoS (CVE-2015-5477)
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISCO
abrir ↗GitHub PoC★ 1
Vulnerability as a service: showcasing CVS-2015-5447, a DDoS condition in the bind9 software
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISCO
abrir ↗GitHub PoC★ 14
PoC exploit code for CVE-2015-5477 BIND9 TKEY remote DoS vulnerability
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISCO
abrir ↗GitHub PoC★ 64
PoC exploit for CVE-2015-5477 BIND9 TKEY assertion failure
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISCO
abrir ↗GitHub PoC★ 3
A little Python tool for exploiting CVE-2015-1560 and CVE-2015-1561. Quick'n'dirty. Real dirty.
SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis
23RISCO
abrir ↗GitHub PoC★ 11
jvazquez-r7/CVE-2015-5119
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.