Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
14.096 exploits
GitHub PoC
patched-bash-4.3 for CVE-2014-6271
CVE-2014-6271CRITICALsob ataque24 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC6
Patch for CVE-2014-6271
CVE-2014-6271CRITICALsob ataque24 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
Collected fixes for bash CVE-2014-6271
CVE-2014-6271CRITICALsob ataque24 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC46
Research of CVE-2014-3153 and its famous exploit towelroot on x86
CVE-2014-3153HIGHsob ataque20 set 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISCO
abrir
GitHub PoC19
CVE-2014-3153 exploit
CVE-2014-3153HIGHsob ataque13 set 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISCO
abrir
GitHub PoC15
Scans NTP servers for CVE-2013-5211 NTP DDOS amplification vulnerability.
CVE-2013-521107 set 2014
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
GitHub PoC15
Annotated FBI exploit for the Tor Browser Bundle from mid-2013 (CVE-2013-1690)
CVE-2013-1690HIGHsob ataque19 ago 2014
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before
98RISCO
abrir
GitHub PoC2
Technicolor TC7200 - Credentials Disclosure CVE : CVE-2014-1677
CVE-2014-167731 jul 2014
Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information.
28RISCO
abrir
GitHub PoC124
CVE-2014-3153 aka towelroot
CVE-2014-3153HIGHsob ataque24 jul 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISCO
abrir
GitHub PoC6
POC Code to exploite CVE-2014-3120
CVE-2014-3120HIGHsob ataque07 jul 2014
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RISCO
abrir
GitHub PoC4
Exploit for cve-2012-3137 Oracle challenge
CVE-2012-313718 jun 2014
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 all
35RISCO
abrir
GitHub PoC1
struts1 CVE-2014-0114 classLoader manipulation vulnerability patch
CVE-2014-011410 jun 2014
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RISCO
abrir
GitHub PoC12
A request parameter filter solution for Struts 1 CVE-2014-0114 based on the work of Alvaro Munoz and the HP Fortify team
CVE-2014-011422 mai 2014
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RISCO
abrir
GitHub PoC
SunRain/CVE-2014-0196
CVE-2014-0196MEDIUMsob ataque13 mai 2014
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver a
68RISCO
abrir
GitHub PoC
Demonstration of CVE-2014-3120
CVE-2014-3120HIGHsob ataque13 mai 2014
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RISCO
abrir
GitHub PoC18
cve-2014-0130 rails directory traversal vuln
CVE-2014-0130HIGHsob ataque08 mai 2014
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in
83RISCO
abrir
GitHub PoC15
CVE-2014-0160 (Heartbeat Buffer over-read bug)
CVE-2014-0160HIGHsob ataque03 mai 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC18
Maltego transform to detect the OpenSSL Heartbleed vulnerability (CVE-2014-0160)
CVE-2014-0160HIGHsob ataque01 mai 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC1
CVE-2014-0094 test program for struts1
CVE-2014-009427 abr 2014
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RISCO
abrir
GitHub PoC4
openssl Heartbleed bug(CVE-2014-0160) check for Node.js
CVE-2014-0160HIGHsob ataque19 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC98
OpenSSL Heartbleed (CVE-2014-0160) vulnerability scanner, data miner and RSA key-restore tools.
CVE-2014-0160HIGHsob ataque15 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC3
A checker (site and tool) for CVE-2014-0160
CVE-2014-0160HIGHsob ataque15 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
A checker (site and tool) for CVE-2014-0160:
CVE-2014-0160HIGHsob ataque15 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
Test script for test 1Password database for SSL Hea(r)t Bleeding (CVE-2014-0160)
CVE-2014-0160HIGHsob ataque13 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC1
A research tool designed to check for OpenSSL CVE-2014-0160 vulnerability
CVE-2014-0160HIGHsob ataque13 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
Nmap NSE script that discovers/exploits Heartbleed/CVE-2014-0160.
CVE-2014-0160HIGHsob ataque13 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC6
Script to find Exit and Guard nodes in the Tor Network, that are still suffering from CVE-2014-0160
CVE-2014-0160HIGHsob ataque12 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC5
POC for CVE-2014-0160 (Heartbleed) for DTLS
CVE-2014-0160HIGHsob ataque12 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC2
OpenSSL Heartbleed (CVE-2014-0160) vulnerability scanner.
CVE-2014-0160HIGHsob ataque11 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
CVE-2014-0160 scanner
CVE-2014-0160HIGHsob ataque11 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
anteriorpágina 468 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.