Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
14.119 exploits
GitHub PoC10
PHPMyAdmin v4.8.0 and v.4.8.1 LFI exploit
CVE-2018-1261309 nov 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir
GitHub PoC
matlink/CVE-2018-17456
CVE-2018-1745608 nov 2018
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISCO
abrir
GitHub PoC
来自:https://www.freebuf.com/articles/web/31700.html
CVE-2014-0160HIGHsob ataque08 nov 2018
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC3
beraphin/CVE-2018-6789
CVE-2018-6789CRITICALsob ataqueransomware08 nov 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir
GitHub PoC21
an RCE (remote command execution) approach of CVE-2018-7750
CVE-2018-775006 nov 2018
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x
28RISCO
abrir
GitHub PoC14
Exploit for PlaySMS 1.4 authenticated RCE
CVE-2017-910106 nov 2018
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RISCO
abrir
GitHub PoC
bolonobolo/CVE-2018-14665
CVE-2018-1466502 nov 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISCO
abrir
GitHub PoC2
matlink/CVE-2018-17961
CVE-2018-1796101 nov 2018
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err
23RISCO
abrir
GitHub PoC80
CVE-2018-8440 standalone exploit
CVE-2018-8440HIGHsob ataqueransomware31 out 2018
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
91RISCO
abrir
GitHub PoC2
Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473
CVE-2018-15473MEDIUM31 out 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC
matlink/cve-2017-1000083-atril-nautilus
CVE-2017-100008330 out 2018
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RISCO
abrir
GitHub PoC
matlink/evince-cve-2017-1000083
CVE-2017-100008330 out 2018
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RISCO
abrir
GitHub PoC10
CVE-2018-2628漏洞工具包
CVE-2018-2628CRITICALsob ataque30 out 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
GitHub PoC1
kastellanos/CVE-2018-7602
CVE-2018-7602CRITICALsob ataqueransomware29 out 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISCO
abrir
GitHub PoC4
Exploit for vulnerability CVE-2018-6389 on wordpress sites
CVE-2018-638928 out 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
GitHub PoC17
OpenBsd_CVE-2018-14665
CVE-2018-1466527 out 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISCO
abrir
GitHub PoC
ensimag-security/CVE-2018-10933
CVE-2018-10933CRITICAL25 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC14
CVE-2018-3245
CVE-2018-324525 out 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
45RISCO
abrir
GitHub PoC172
CVE-2018-3245-PoC
CVE-2018-324524 out 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
45RISCO
abrir
GitHub PoC
throwawayaccount12312312/precompiled-CVE-2018-10933
CVE-2018-10933CRITICAL24 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC
Multi-threaded, reliable scanner for CVE-2018-10933.
CVE-2018-10933CRITICAL24 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC1
A libssh CVE-2018-10933 scanner written in rust
CVE-2018-10933CRITICAL24 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC17
OpenSSH 7.7 - Username Enumeration
CVE-2018-15473MEDIUM24 out 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC7
TALOS-2018-0684/cve-2018-4013 poc
CVE-2018-4013CRITICAL24 out 2018
An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server l
48RISCO
abrir
GitHub PoC62
A weaponized version of CVE-2018-9206
CVE-2018-920624 out 2018
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISCO
abrir
GitHub PoC9
CVE-2018-7600 POC (Drupal RCE)
CVE-2018-7600CRITICALsob ataqueransomware23 out 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC
CVE-2018-10933
CVE-2018-10933CRITICAL23 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC1
CVE-2018-10933 POC (LIBSSH)
CVE-2018-10933CRITICAL23 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC
j0lama/CVE-2017-11882
CVE-2017-11882HIGHsob ataqueransomware23 out 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC13
A Python PoC for CVE-2018-9206
CVE-2018-920622 out 2018
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISCO
abrir
anteriorpágina 438 / 471próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.