Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
14.096 exploits
GitHub PoC27
akamajoris/CVE-2019-11043-Docker
CVE-2019-11043HIGHsob ataqueransomware24 out 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC
CVE-2015-7547 initial research.
CVE-2015-754724 out 2019
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISCO
abrir
GitHub PoC3
Remote Code Execution Vulnerability in Webmin
CVE-2019-15107CRITICALsob ataqueransomware24 out 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC
melardev/CVE-2019-5418
CVE-2019-5418HIGHsob ataque24 out 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
GitHub PoC
CVE-2019-11043
CVE-2019-11043HIGHsob ataqueransomware23 out 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC16
Double-free vulnerability in DDGifSlurp in decoding.c in libpl_droidsonroids_gif can read more https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/
CVE-2019-1193223 out 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC1
CVE-2019-16278 Python3 Exploit Code
CVE-2019-16278CRITICALsob ataque23 out 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir
GitHub PoC
tinker-li/CVE-2019-11043
CVE-2019-11043HIGHsob ataqueransomware23 out 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC105
php-fpm+Nginx RCE
CVE-2019-11043HIGHsob ataqueransomware23 out 2019
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC
leonardo1101/cve-2017-11176
CVE-2017-1117623 out 2019
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISCO
abrir
GitHub PoC
ictnamanh/CVE-2017-9248
CVE-2017-9248CRITICALsob ataque23 out 2019
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISCO
abrir
GitHub PoC9
脏牛Linux本地提权漏洞复现(CVE-2016-5195)
CVE-2016-5195HIGHsob ataque22 out 2019
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC5
Instructions for installing a vulnerable version of Exim and its expluatation
CVE-2019-10149CRITICALsob ataque21 out 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir
GitHub PoC167
exploit CVE-2019-7609(kibana RCE) on right way by python2 scripts
CVE-2019-7609CRITICALsob ataque21 out 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir
GitHub PoC56
RCE on Kibana versions before 5.6.15 and 6.6.0 in the Timelion visualizer
CVE-2019-7609CRITICALsob ataque21 out 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir
GitHub PoC5
RCE Exploit For CVE-2019-17424 (nipper-ng 0.11.10)
CVE-2019-1742420 out 2019
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows re
28RISCO
abrir
GitHub PoC3
Sudo Security Bypass (CVE-2019-14287)
CVE-2019-1428718 out 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC
CVE-2019-17080
CVE-2019-1708018 out 2019
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by a
23RISCO
abrir
GitHub PoC89
kibana < 6.6.0 未授权远程代码命令执行 (Need Timelion And Canvas),CVE-2019-7609
CVE-2019-7609CRITICALsob ataque18 out 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir
GitHub PoC9
Metasploit module & Python script for CVE-2019-16405
CVE-2019-1640518 out 2019
Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code
28RISCO
abrir
GitHub PoC3
CVE 2019-2215 Android Binder Use After Free
CVE-2019-2215HIGHsob ataque17 out 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC6
Authenticated Stored XSS in LifeRay 7.2.0 GA1 via MyAccountPortlet executed by Search Results
CVE-2020-793417 out 2019
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyA
23RISCO
abrir
GitHub PoC
CVE-2012-5960, CVE-2012-5959 Proof of Concept
CVE-2012-596017 out 2019
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RISCO
abrir
GitHub PoC
gurneesh/CVE-2019-14287-write-up
CVE-2019-1428716 out 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC1
Exploit and Mass Pwn3r for CVE-2019-16920
CVE-2019-16920CRITICALsob ataque16 out 2019
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The i
100RISCO
abrir
GitHub PoC10
Standalone Python 3 exploit for CVE-2017-17562
CVE-2017-17562HIGHsob ataque16 out 2019
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISCO
abrir
GitHub PoC38
This native code file aims to be complementary to the published Whatsapp GIF RCE exploit by Awakened , by calculating the system() function address and ROP gadget address for different types of devices, which then can be used to successfully exploit the vulnerability.
CVE-2019-1193216 out 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC17
Programa para hackear Whatsapp Mediante Gif ,asiendo un exploit con el puerto.
CVE-2019-1193216 out 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC1
FauxFaux/sudo-cve-2019-14287
CVE-2019-1428715 out 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC3
CVE-2019-16278Nostromo httpd命令执行
CVE-2019-16278CRITICALsob ataque15 out 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir
anteriorpágina 418 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.