Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
14.119 exploits
GitHub PoC331
CVE-2018-8581 | Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2018-8581HIGHsob ataqueransomware27 dez 2018
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
76RISCO
abrir
GitHub PoC5
Flash 2018-15982 UAF
CVE-2018-15982HIGHsob ataqueransomware20 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
GitHub PoC
Weblogic(CVE-2017-10271)
CVE-2017-10271HIGHsob ataqueransomware20 dez 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC
https://github.com/milo2012/CVE-2018-0296.git
CVE-2018-0296HIGHsob ataque19 dez 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISCO
abrir
GitHub PoC
CVE-2012-5106 - Freefloat FTP Server Buffer Overflow Vulnerability. Tested on Windows XP Professional SP3.
CVE-2012-510619 dez 2018
Stack-based buffer overflow in FreeFloat FTP Server 1.0 allows remote authenticated users to execute arbitrary code via
28RISCO
abrir
GitHub PoC
Yable/CVE-2018-4878
CVE-2018-4878HIGHsob ataqueransomware19 dez 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
GitHub PoC
CVE-2003-0264 - SLMail 5.5 POP3 'PASS' Remote Buffer Overflow Vulnerability. Tested on Windows XP Professional SP3.
CVE-2003-026419 dez 2018
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISCO
abrir
GitHub PoC
CVE-2004-2271 - Minishare 1.4.1 HTTP Server Remote Buffer Overflow Vulnerability. Tested on Windows XP Professional SP3.
CVE-2004-227119 dez 2018
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RISCO
abrir
GitHub PoC6
LibSSH Authentication Bypass CVE-2018-10933
CVE-2018-10933CRITICAL19 dez 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC
qiantu88/CVE-2017-12617
CVE-2017-12617HIGHsob ataque19 dez 2018
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISCO
abrir
GitHub PoC
qiantu88/CVE-2018-8120
CVE-2018-8120HIGHsob ataqueransomware19 dez 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC
CVE-2007-1567 - WarFTP 1.65 'USER' Remote Buffer Overflow Vulnerability. Tested on Windows XP Professional SP3.
CVE-2007-156719 dez 2018
Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of s
35RISCO
abrir
GitHub PoC83
An implementation of CVE-2009-0689 for the Nintendo Wii.
CVE-2009-068918 dez 2018
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RISCO
abrir
GitHub PoC30
MikroTik RouterOS Winbox未经身份验证的任意文件读/写漏洞
CVE-2018-14847CRITICALsob ataque15 dez 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
GitHub PoC9
针对类似CVE-2017-10271漏洞的一个java反序列化漏洞扫描器
CVE-2017-10271HIGHsob ataqueransomware13 dez 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC29
Aggressor Script to launch IE driveby for CVE-2018-15982.
CVE-2018-15982HIGHsob ataqueransomware12 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
GitHub PoC12
CVE-2018-15982_EXP_IE
CVE-2018-15982HIGHsob ataqueransomware12 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
GitHub PoC
Just My ports of CVE-2017-8759
CVE-2017-8759HIGHsob ataque11 dez 2018
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISCO
abrir
GitHub PoC11
Script and metasploit module for CVE-2018-15982
CVE-2018-15982HIGHsob ataqueransomware11 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
GitHub PoC1
securifera/CVE-2018-16156-Exploit
CVE-2018-1615611 dez 2018
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes u
23RISCO
abrir
GitHub PoC
Microsoft Equation 3.0/Convert python2 to python3
CVE-2017-11882HIGHsob ataqueransomware10 dez 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC1
CVE-2014-0160
CVE-2014-0160HIGHsob ataque10 dez 2018
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC4
个人整理的Centos7.x + Kubernetes-1.12.3 + Dashboard-1.8.3 无 CVE-2018-1002105 漏洞的master节点全自动快速一键安装部署文件,适用于测试环境,生产环境的快速安装部署
CVE-2018-1002105CRITICAL10 dez 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISCO
abrir
GitHub PoC179
exp of CVE-2018-15982
CVE-2018-15982HIGHsob ataqueransomware10 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
GitHub PoC2
Proof of consept for CVE-2018-17431
CVE-2018-1743108 dez 2018
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RISCO
abrir
GitHub PoC13
CVE-2018-15982_PoC
CVE-2018-15982HIGHsob ataqueransomware06 dez 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
GitHub PoC9
Unrestricted file upload in Adobe ColdFusion
CVE-2018-15961CRITICALsob ataque06 dez 2018
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISCO
abrir
GitHub PoC222
PoC for CVE-2018-1002105.
CVE-2018-1002105CRITICAL06 dez 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISCO
abrir
GitHub PoC191
Test utility for cve-2018-1002105
CVE-2018-1002105CRITICAL05 dez 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISCO
abrir
GitHub PoC
uzzzval/cve-2004-2167
CVE-2004-216705 dez 2018
Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary
28RISCO
abrir
anteriorpágina 436 / 471próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.