Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
14.119 exploits
GitHub PoC26
lexfo/cve-2017-11176
CVE-2017-1117602 out 2018
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISCO
abrir
GitHub PoC1
likekabin/vmacache_CVE-2018-17182
CVE-2018-1718201 out 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISCO
abrir
GitHub PoC
likekabin/CVE-2018-17182
CVE-2018-1718201 out 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISCO
abrir
GitHub PoC130
Linux 内核VMA-UAF 提权漏洞(CVE-2018-17182),0day
CVE-2018-1718229 set 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISCO
abrir
GitHub PoC
Make CVE-2007-4607 exploitable again!
CVE-2007-460727 set 2018
Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used
50RISCO
abrir
GitHub PoC20
Gain root privilege by exploiting CVE-2014-3153 vulnerability
CVE-2014-3153HIGHsob ataque27 set 2018
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISCO
abrir
GitHub PoC
bkhablenko/CVE-2017-8046
CVE-2017-804626 set 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISCO
abrir
GitHub PoC1
cscli/CVE-2017-5223
CVE-2017-522326 set 2018
An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML docume
23RISCO
abrir
GitHub PoC112
DVR-Exploiter a Bash Script Program Exploit The DVR's Based on CVE-2018-9995
CVE-2018-999523 set 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
GitHub PoC
Exploit SLmail Buffer Overflow CVE-2003-0264
CVE-2003-026416 set 2018
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISCO
abrir
GitHub PoC513
Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。
CVE-2017-10271HIGHsob ataqueransomware13 set 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC513
Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。
CVE-2019-2725HIGHsob ataqueransomware13 set 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
GitHub PoC1
porting CVE-2016-7255 to x86 for educational purposes.
CVE-2016-7255HIGHsob ataque13 set 2018
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISCO
abrir
GitHub PoC1
veloCloud VMWare - Vulnerability
CVE-2018-6961HIGHsob ataque12 set 2018
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RISCO
abrir
GitHub PoC7
C# implementation of BasuCert/WinboxPoC [Winbox Critical Vulnerability (CVE-2018-14847)]
CVE-2018-14847CRITICALsob ataque11 set 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
GitHub PoC2
Simple poc of CVE-2018-8353 Microsoft Scripting Engine Use After Free
CVE-2018-835310 set 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
35RISCO
abrir
GitHub PoC
jezzus/CVE-2018-4121
CVE-2018-412106 set 2018
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RISCO
abrir
GitHub PoC
likekabin/CVE-2018-8174-msf
CVE-2018-8174HIGHsob ataqueransomware06 set 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
GitHub PoC
jezzus/CVE-2018-11776-Python-PoC
CVE-2018-11776HIGHsob ataque06 set 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC5
A remote code execution exploit for WebLogic based on CVE-2018-2628
CVE-2018-2628CRITICALsob ataque04 set 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
GitHub PoC2
Apache Struts version analyzer (Ansible) based on CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware04 set 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC95
Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit
CVE-2017-1000486CRITICALsob ataque03 set 2018
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISCO
abrir
GitHub PoC25
CVE-2017-10366: Oracle PeopleSoft 8.54, 8.55, 8.56 Java deserialization exploit
CVE-2017-1036603 set 2018
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Perform
35RISCO
abrir
GitHub PoC13
Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks
CVE-2018-638930 ago 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
GitHub PoC56
This tool takes advantage of CVE-2018-11776 and Shodan to perform mass exploitation of verified and vulnerable Apache Struts servers.
CVE-2018-11776HIGHsob ataque29 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC16
A simple exploit for Apache Struts RCE S2-057 (CVE-2018-11776)
CVE-2018-11776HIGHsob ataque28 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC3
tuxotron/cve-2018-11776-docker
CVE-2018-11776HIGHsob ataque28 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC2
Tiny script to enumerate users using CVE-2017-9554 (forget_passwd.cgi)
CVE-2017-955428 ago 2018
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RISCO
abrir
GitHub PoC21
Proof of Concept for CVE-2018-11776
CVE-2018-11776HIGHsob ataque27 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC303
An exploit for Apache Struts CVE-2018-11776
CVE-2018-11776HIGHsob ataque25 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
anteriorpágina 440 / 471próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.