Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
14.096 exploits
GitHub PoC1
This is a container built for demonstration purposes that has a version of the sudo command which is vulnerable to CVE-2019-14287
CVE-2019-1428715 out 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC13
Sudo exploit
CVE-2019-1428715 out 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC70
Directory transversal to remote code execution
CVE-2019-16278CRITICALsob ataque15 out 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir
GitHub PoC9
CVE-2019-16728 Proof of Concept
CVE-2019-16278CRITICALsob ataque15 out 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir
GitHub PoC134
Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215
CVE-2019-2215HIGHsob ataque14 out 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC12
CVE-2018-13379 Script for Nmap NSE.
CVE-2018-13379CRITICALsob ataqueransomware14 out 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
GitHub PoC
Spring Security OAuth 2.3 Open Redirection 分析复现篇
CVE-2019-377814 out 2019
Open Redirect in spring-security-oauth2
28RISCO
abrir
GitHub PoC
h-wookie/cve-2019-5736-poc
CVE-2019-573612 out 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC4
Interactive-Like Command-Line Console for CVE-2019-16759
CVE-2019-16759CRITICALsob ataque12 out 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC16
Critical Remote Code Execution Vulnerability (CVE-2018-11776) Found in Apache Struts.
CVE-2018-11776HIGHsob ataque10 out 2019
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC10
PoC materials to exploit CVE-2018-6789
CVE-2018-6789CRITICALsob ataqueransomware10 out 2019
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir
GitHub PoC1
CVE-2018-7600 and CVE-2018-7602 Mass Exploiter
CVE-2018-7600CRITICALsob ataqueransomware10 out 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC2
KRAMER VIAware 2.5.0719.1034 - Remote Code Execution
CVE-2019-1712409 out 2019
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
28RISCO
abrir
GitHub PoC2
The study of vulnerability CVE-2017-3066. Java deserialization
CVE-2017-3066CRITICALsob ataque09 out 2019
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RISCO
abrir
GitHub PoC
Investigation of CVE-2018-11776 vulnerability that allows attackers to remotely execute code and gain control over Apache Struts-based applications.
CVE-2018-11776HIGHsob ataque08 out 2019
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC4
infiniteLoopers/CVE-2019-11932
CVE-2019-1193206 out 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC4
Double-Free BUG in WhatsApp exploit poc.
CVE-2019-1193205 out 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC4
This is a Automated Generate Payload for CVE-2019-11932 (WhatsApp Remote Code Execution)
CVE-2019-1193204 out 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC
Rails 3 PoC of CVE-2019-5418
CVE-2019-5418HIGHsob ataque04 out 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
GitHub PoC77
timwr/CVE-2019-2215
CVE-2019-2215HIGHsob ataque04 out 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC208
Simple POC for exploiting WhatsApp double-free bug in DDGifSlurp in decoding.c in libpl_droidsonroids_gif
CVE-2019-1193204 out 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC
Remediation task for CVE-2018-15686, CVE-2018-16866, and CVE-2018-16888 affecting SystemD in EL7
CVE-2018-15686HIGH03 out 2019
systemd: reexec state injection: fgets() on overlong lines leads to line splitting
41RISCO
abrir
GitHub PoC8
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 | XSS to RCE
CVE-2019-1256203 out 2019
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the mali
23RISCO
abrir
GitHub PoC267
double-free bug in WhatsApp exploit poc
CVE-2019-1193203 out 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC1
CVE-2019-17080
CVE-2019-1708002 out 2019
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by a
23RISCO
abrir
GitHub PoC20
CVE-2019-16759 vbulletin 5.0.0 till 5.5.4 pre-auth rce
CVE-2019-16759CRITICALsob ataque02 out 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
GitHub PoC246
ispy V1.0 - Eternalblue(ms17-010)/Bluekeep(CVE-2019-0708) Scanner and exploit ( Metasploit automation )
CVE-2019-0708CRITICALsob ataqueransomware30 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
A simple exploit for CVE-2007-2447
CVE-2007-244730 set 2019
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC21
PoC of CVE-2018-14847 Mikrotik Vulnerability using simple script
CVE-2018-14847CRITICALsob ataque29 set 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
GitHub PoC75
it works on xp (all version sp2 sp3)
CVE-2019-0708CRITICALsob ataqueransomware29 set 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
anteriorpágina 419 / 470próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.