Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
14.119 exploits
GitHub PoC
MySQL 4.x/5.0 (Linux) - User-Defined Function (UDF) Dynamic Library (2) automation script.
CVE-2012-561314 jun 2018
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RISCO
abrir
GitHub PoC18
empty_list - exploit for p0 issue 1564 (CVE-2018-4243) iOS 11.0 - 11.3.1 kernel r/w
CVE-2018-424313 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
28RISCO
abrir
GitHub PoC
CVE-2018-4878 flash 0day
CVE-2018-4878HIGHsob ataqueransomware12 jun 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
GitHub PoC11
A demonstration of how page tables can be used to run arbitrary code in ring-0 and lead to a privesc. Uses CVE-2016-7255 as an example.
CVE-2016-7255HIGHsob ataque09 jun 2018
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISCO
abrir
GitHub PoC
teawater/CVE-2017-5123
CVE-2017-512308 jun 2018
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RISCO
abrir
GitHub PoC292
CVE-2018-8120 Exploit for Win2003 Win2008 WinXP Win7
CVE-2018-8120HIGHsob ataqueransomware07 jun 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC4
CVE-2018-4241: XNU kernel heap overflow due to bad bounds checking in MPTCP for iOS 11 - 11.3.1released by Ian Beer
CVE-2018-424106 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RISCO
abrir
GitHub PoC3
Exploit for CVE-2018-10562
CVE-2018-10562CRITICALsob ataqueransomware06 jun 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RISCO
abrir
GitHub PoC107
Weblogic 反序列化漏洞(CVE-2018-2628)
CVE-2018-2628CRITICALsob ataque05 jun 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
GitHub PoC5
ne1llee/cve-2018-8120
CVE-2018-8120HIGHsob ataqueransomware05 jun 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC
cve-2018-2628 反弹shell
CVE-2018-2628CRITICALsob ataque05 jun 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
GitHub PoC6
MS Word MS WordPad via IE VBS Engine RCE
CVE-2018-8174HIGHsob ataqueransomware01 jun 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
GitHub PoC9
Tools to exercise the Linux kernel mitigation for CVE-2018-3639 (aka Variant 4) using the Speculative Store Bypass Disable (SSBD) feature of x86 processors
CVE-2018-3639MEDIUM31 mai 2018
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RISCO
abrir
GitHub PoC
My version - CloudMe-Sync-1.10.9---Buffer-Overflow-SEH-DEP-Bypass on Win7 x64 CVE-2018-6892
CVE-2018-689231 mai 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RISCO
abrir
GitHub PoC
My version - [Win10 x64] CloudMe-Sync-1.10.9-Buffer-Overflow-SEH-DEP-Bypass CVE-2018-6892
CVE-2018-689231 mai 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RISCO
abrir
GitHub PoC139
CVE-2018-8174_python
CVE-2018-8174HIGHsob ataqueransomware30 mai 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
GitHub PoC141
编译好的脏牛漏洞(CVE-2016-5195)EXP
CVE-2016-5195HIGHsob ataque27 mai 2018
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC4
Exploit for Remote Code Execution on GPON home routers (CVE-2018-10562) written in Python.
CVE-2018-10562CRITICALsob ataqueransomware26 mai 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RISCO
abrir
GitHub PoC6
Flexense HTTP Server <= 10.6.24 - Denial Of Service Exploit
CVE-2018-806525 mai 2018
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access v
60RISCO
abrir
GitHub PoC
soch4n/CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware25 mai 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC6
Detecion for the vulnerability CVE-2017-15944
CVE-2017-15944CRITICALsob ataque24 mai 2018
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISCO
abrir
GitHub PoC167
CVE-2018-8174 - VBScript memory corruption exploit.
CVE-2018-8174HIGHsob ataqueransomware22 mai 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
GitHub PoC
My version - Easy File Sharing Web Server 7.2 - 'UserID' - Win 7 'DEP' bypass
CVE-2018-905920 mai 2018
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RISCO
abrir
GitHub PoC498
CVE-2018-8120 Windows LPE exploit
CVE-2018-8120HIGHsob ataqueransomware19 mai 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC12
CVE-2018-11311 | mySCADA myPRO 7 Hardcoded FTP Username and Password Vulnerability
CVE-2018-1131119 mai 2018
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attack
28RISCO
abrir
GitHub PoC12
CVE-2018-1111 DynoRoot
CVE-2018-1111HIGH18 mai 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISCO
abrir
GitHub PoC2
Exploit loader for Remote Code Execution w/ Payload on GPON Home Gateway devices (CVE-2018-10562) written in Python.
CVE-2018-10562CRITICALsob ataqueransomware17 mai 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RISCO
abrir
GitHub PoC163
bigric3/cve-2018-8120
CVE-2018-8120HIGHsob ataqueransomware17 mai 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISCO
abrir
GitHub PoC13
Environment for DynoRoot (CVE-2018-1111)
CVE-2018-1111HIGH17 mai 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISCO
abrir
GitHub PoC5
Windows: heap overflow in jscript.dll in Array.sort
CVE-2017-1190716 mai 2018
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
35RISCO
abrir
anteriorpágina 443 / 471próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.