Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
14.119 exploits
GitHub PoC24
Exploit for Mass Remote Code Execution on GPON home routers (CVE-2018-10562) obtained from Shodan.
CVE-2018-10562CRITICALsob ataqueransomware15 mai 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RISCO
abrir
GitHub PoC
ISC INN 2.x - Command-Line Buffer Overflow
CVE-2001-144214 mai 2018
Buffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the "news" group to gain privil
23RISCO
abrir
GitHub PoC4
The exploitation for CVE-2018-8897
CVE-2018-889713 mai 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RISCO
abrir
GitHub PoC423
Arbitrary code execution with kernel privileges using CVE-2018-8897.
CVE-2018-889713 mai 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RISCO
abrir
GitHub PoC16
Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code Execution - Shell Script
CVE-2017-5638CRITICALsob ataqueransomware13 mai 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier
CVE-2002-099111 mai 2018
Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, all
23RISCO
abrir
GitHub PoC
SLRNPull Spool Directory Command Line Parameter Buffer Overflow Vulnerability
CVE-2002-074011 mai 2018
Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges
23RISCO
abrir
GitHub PoC2
gwolfs/CVE-2018-9995-ModifiedByGwolfs
CVE-2018-999511 mai 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
GitHub PoC
CVE-2017-7494 C poc
CVE-2017-7494CRITICALsob ataqueransomware10 mai 2018
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
GitHub PoC81
Implements the POP/MOV SS (CVE-2018-8897) vulnerability by bugchecking the machine (local DoS).
CVE-2018-889710 mai 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RISCO
abrir
GitHub PoC2
DVR系列摄像头批量检测
CVE-2018-999509 mai 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
GitHub PoC4
CVE-2018-9995_Batch_scanning_exp
CVE-2018-999508 mai 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
GitHub PoC
CVE-2017-0411 PoC refered p0
CVE-2017-041108 mai 2018
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RISCO
abrir
GitHub PoC
Python exploit for Remote Code Executuion on GPON home routers (CVE-2018-10562). Initially disclosed by VPNMentor (https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/), kudos for their work.
CVE-2018-10562CRITICALsob ataqueransomware07 mai 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RISCO
abrir
GitHub PoC
CS4238 Computer Security Practices
CVE-2014-6271CRITICALsob ataque05 mai 2018
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC1
WP-DOS-Exploit-CVE-2018-6389
CVE-2018-638904 mai 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
GitHub PoC2
Empire Port of CVE-2017-11882
CVE-2017-11882HIGHsob ataqueransomware04 mai 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC6
Ruby on Rails Web Console (v2) Whitelist Bypass Code Execution implementation in Python
CVE-2015-322403 mai 2018
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RISCO
abrir
GitHub PoC114
Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch
CVE-2018-2628CRITICALsob ataque03 mai 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
GitHub PoC9
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by "xlink:href=file://192.168.0.2/test.jpg" within an "office:document-content" element in a ".odt XML document".
CVE-2018-1058303 mai 2018
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
60RISCO
abrir
GitHub PoC1
Vuln checker for Drupal v7.x + v8.x (CVE-2018-7600 / SA-CORE-2018-002)
CVE-2018-7600CRITICALsob ataqueransomware01 mai 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC31
PoC exploit for CVE-2018-5234
CVE-2018-523401 mai 2018
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic
28RISCO
abrir
GitHub PoC557
(CVE-2018-9995) Get DVR Credentials
CVE-2018-999529 abr 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
GitHub PoC11
Al1ex/CVE-2017-7269
CVE-2017-7269CRITICALsob ataque28 abr 2018
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC6
POC to test/exploit drupal vulnerability SA-CORE-2018-004 / CVE-2018-7602
CVE-2018-7602CRITICALsob ataqueransomware27 abr 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISCO
abrir
GitHub PoC
CVE-2018-9160
CVE-2018-916026 abr 2018
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RISCO
abrir
GitHub PoC13
CVE-2017-16995(Ubuntu本地提权漏洞)
CVE-2017-1699526 abr 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
GitHub PoC2
Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware24 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC
herbiezimmerman/CVE-2017-11882-Possible-Remcos-Malspam
CVE-2017-11882HIGHsob ataqueransomware23 abr 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC
CalderaForms 1.5.9.1 XSS (WordPress plugin) - tutorial
CVE-2018-774720 abr 2018
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow re
23RISCO
abrir
anteriorpágina 444 / 471próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.