Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
79.107 exploits
GitHub PoC
Microsoft Windows - 'afd.sys' Local Kernel Privilege Escalation Exploit Report (CVE-2011-1249)
CVE-2011-124913 mai 2020
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vis
23RISCO
abrir
VulnCheck XDB
local
CVE-2020-0796CRITICALsob ataqueransomware13 mai 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC
CVE-2018-20250漏洞利用
CVE-2018-20250HIGHsob ataqueransomware13 mai 2020
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
GitHub PoC15
Proof of concept for Weblogic CVE-2020-2883
CVE-2020-2883CRITICALsob ataque13 mai 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISCO
abrir
GitHub PoC
teddy47/CVE-2019-13272---Documentation
CVE-2019-13272HIGHsob ataque13 mai 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
GitHub PoC1
CVE-2004-1769 // Mass cPanel Reset password
CVE-2004-176913 mai 2020
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x,
35RISCO
abrir
GitHub PoC
SNP Assignment on a Linux vulnerability
CVE-2019-10149CRITICALsob ataque12 mai 2020
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir
GitHub PoC
CVE-2019-5736
CVE-2019-573612 mai 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
Metasploit300
WordPress ChopSlider3 id SQLi Scanner
CVE-2020-1153012 mai 2020
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in
60RISCO
abrir
GitHub PoC
AvishkaSenadheera/CVE-2017-9805---Documentation---IT19143378
CVE-2017-9805HIGHsob ataque12 mai 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC1
Exploit work Privilege Escalation CVE-2017-1000112
CVE-2017-100011212 mai 2020
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISCO
abrir
GitHub PoC
Lumindu/CVE-2017-16995-Linux-Kernel---BPF-Sign-Extension-Local-Privilege-Escalation-
CVE-2017-1699512 mai 2020
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
GitHub PoC
lalishasanduwara/CVE-2018-10933
CVE-2018-10933CRITICAL12 mai 2020
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC3
Local Root vulnerability- CVE-2019-13272 / Security Bypass Vulnerability – CVE-2019-14287/Google Android - 'Stagefright' Remote Code Execution - CVE-2015-1538
CVE-2015-153812 mai 2020
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISCO
abrir
GitHub PoC
Dilith006/CVE-2014-6271
CVE-2014-6271CRITICALsob ataque12 mai 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
This is an individual assignment for secure network programming
CVE-2014-6271CRITICALsob ataque12 mai 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
alokaranasinghe/cve-2019-11043
CVE-2019-11043HIGHsob ataqueransomware12 mai 2020
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC
SachinThanushka/CVE-2018-1160
CVE-2018-1160CRITICAL12 mai 2020
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RISCO
abrir
GitHub PoC
CVE-2017-8759 | .NET Framework Remote Code Execution Vulnerability
CVE-2017-8759HIGHsob ataque12 mai 2020
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISCO
abrir
GitHub PoC
sachinthaBS/Spectre-Vulnerability-CVE-2017-5753-
CVE-2017-5753MEDIUM12 mai 2020
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISCO
abrir
GitHub PoC1
BimsaraMalinda/Linux-Kernel-4.4.0-Ubuntu---DCCP-Double-Free-Privilege-Escalation-CVE-2017-6074
CVE-2017-607412 mai 2020
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST p
23RISCO
abrir
GitHub PoC
This is a Dirty Cow (CVE-2016-5195) privilege escalation vulnerability exploit
CVE-2016-5195HIGHsob ataque12 mai 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC
CVE-2017-8759 || report related with execute code vulnerability
CVE-2017-8759HIGHsob ataque12 mai 2020
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISCO
abrir
GitHub PoC
Dirtycow also is known as CVE-2016-5195
CVE-2016-5195HIGHsob ataque12 mai 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC
Document on Linux Kernal Vulnerability CVE-2016-0728 and Exploitation
CVE-2016-072812 mai 2020
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir
GitHub PoC
SNP Assignment 1 Report - Linux box exploitation ( Vulnerability CVE-2014-0038)
CVE-2014-003812 mai 2020
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque12 mai 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC
Dilan-Diaz/Point-to-Point-Protocol-Daemon-RCE-Vulnerability-CVE-2020-8597-
CVE-2020-8597CRITICAL12 mai 2020
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RISCO
abrir
GitHub PoC
dinidhu96/IT19013756_-CVE-2016-4971-
CVE-2016-497112 mai 2020
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RISCO
abrir
GitHub PoC
Glibc-Vulnerability-Exploit-CVE-2015-7547
CVE-2015-754712 mai 2020
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISCO
abrir
anteriorpágina 771 / 2.637próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.