Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.104GitHub PoC 15.075VulnCheck XDB 8.883Nuclei 4.365Metasploit 3.493✓ só verificadosrecentespopularesrisco
79.386 exploits
GitHub PoC★ 11
Script and metasploit module for CVE-2018-15982
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir ↗Exploit-DB✓ VexDay Proof
McAfee True Key - McAfee.TrueKey.Service Privilege Escalation
True Key (TK) Windows Client - Weak Directory Permission Vulnerability
41RISCO
abrir ↗Exploit-DB
Adobe ColdFusion 2018 - Arbitrary File Upload
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
McAfee True Key - McAfee.TrueKey.Service Privilege Escalation
True Key (TK) Windows Client - Privilege Escalation vulnerability
41RISCO
abrir ↗GitHub PoC★ 4
个人整理的Centos7.x + Kubernetes-1.12.3 + Dashboard-1.8.3 无 CVE-2018-1002105 漏洞的master节点全自动快速一键安装部署文件,适用于测试环境,生产环境的快速安装部署
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISCO
abrir ↗GitHub PoC★ 1
CVE-2014-0160
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗VulnCheck XDB
client-side
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir ↗GitHub PoC
Microsoft Equation 3.0/Convert python2 to python3
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir ↗Exploit-DB
Kubernetes - (Unauthenticated) Arbitrary Requests
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISCO
abrir ↗Exploit-DB
Kubernetes - (Authenticated) Arbitrary Requests
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISCO
abrir ↗VulnCheck XDB
client-side
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir ↗Metasploit600
ThinkPHP Multiple PHP Injection RCEs
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISCO
abrir ↗Metasploit600
ThinkPHP Multiple PHP Injection RCEs
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RISCO
abrir ↗GitHub PoC★ 179
exp of CVE-2018-15982
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir ↗Exploit-DB
Adiscon LogAnalyzer < 4.1.7 - Cross-Site Scripting
login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field.
43RISCO
abrir ↗Metasploit600
Cisco Prime Infrastructure Runrshell Privilege Escalation
Cisco Small Business Switches Privileged Access Vulnerability
55RISCO
abrir ↗GitHub PoC★ 2
Proof of consept for CVE-2018-17431
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RISCO
abrir ↗VulnCheck XDB
initial-access
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RISCO
abrir ↗GitHub PoC★ 9
Unrestricted file upload in Adobe ColdFusion
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISCO
abrir ↗VulnCheck XDB
initial-access
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISCO
abrir ↗GitHub PoC★ 13
CVE-2018-15982_PoC
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir ↗GitHub PoC★ 223
PoC for CVE-2018-1002105.
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISCO
abrir ↗GitHub PoC★ 191
Test utility for cve-2018-1002105
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISCO
abrir ↗GitHub PoC
uzzzval/cve-2004-2167
Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary
28RISCO
abrir ↗GitHub PoC
Flash sources for CVE-2018-15982 used by NK
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir ↗Exploit-DB
DomainMOD 4.11.01 - Custom Domain Fields Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Doma
23RISCO
abrir ↗GitHub PoC
CVE-2014-8682
Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow r
50RISCO
abrir ↗Exploit-DB
DomainMOD 4.11.01 - Registrar Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.
38RISCO
abrir ↗Exploit-DB
FreshRSS 1.11.1 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject
23RISCO
abrir ↗Exploit-DB
NEC Univerge Sv9100 WebPro - 6.00 - Predictable Session ID / Clear Text Password Storage
NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure vi
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.