Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.205exploits catalogados
35.417CVEs com exploração pública
24.695testados em laboratório
14.119 exploits
GitHub PoC5
CVE-2017-8570生成脚本(CVE-2017-0199另一种利用方式)
CVE-2017-8570HIGHsob ataque08 abr 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISCO
abrir
GitHub PoC2
Android Blueborne RCE CVE-2017-0781
CVE-2017-078106 abr 2018
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RISCO
abrir
GitHub PoC2
Android Blueborne RCE CVE-2017-0781
CVE-2017-078106 abr 2018
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RISCO
abrir
GitHub PoC7
Flash Exploit Poc
CVE-2018-4878HIGHsob ataqueransomware04 abr 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
GitHub PoC
Airsensor M520 - HTTPd Unauthenticated Remote Denial of Service / Buffer Overflow (PoC)
CVE-2007-503603 abr 2018
Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated
23RISCO
abrir
GitHub PoC
Xerver 2.10 - Multiple Request Denial of Service Vulnerabilities
CVE-2002-044803 abr 2018
Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request
28RISCO
abrir
GitHub PoC
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow.
CVE-2002-020103 abr 2018
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute a
28RISCO
abrir
GitHub PoC
Nortel Wireless LAN Access Point 2200 Series - Denial of Service
CVE-2004-254903 abr 2018
Nortel Wireless LAN (WLAN) Access Point (AP) 2220, 2221, and 2225 allow remote attackers to cause a denial of service (s
28RISCO
abrir
GitHub PoC
Phusion WebServer 1.0 - Directory Traversal
CVE-2002-028803 abr 2018
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (t
23RISCO
abrir
GitHub PoC
March Networks DVR 3204 - Logfile Information Disclosure
CVE-2007-663803 abr 2018
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows r
28RISCO
abrir
GitHub PoC
Phusion WebServer 1.0 - 'URL' Remote Buffer Overflow
CVE-2002-028903 abr 2018
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary cod
28RISCO
abrir
GitHub PoC
Cooolsoft PowerFTP Server 2.0 3/2.10 - Multiple Denial of Service Vulnerabilities
CVE-2001-093203 abr 2018
Buffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly exec
28RISCO
abrir
GitHub PoC267
A code demonstrating CVE-2018-0886
CVE-2018-088602 abr 2018
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 S
45RISCO
abrir
GitHub PoC
Cisco VPN Client - Integer Overflow Denial of Service
CVE-2009-411802 abr 2018
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0
23RISCO
abrir
GitHub PoC49
An implementation of CVE-2016-0974 for the Nintendo Wii.
CVE-2016-097401 abr 2018
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and
35RISCO
abrir
GitHub PoC
tomcat7.x远程命令执行
CVE-2017-12615HIGHsob ataqueransomware01 abr 2018
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
GitHub PoC114
CVE-2018-7600 Drupal RCE
CVE-2018-7600CRITICALsob ataqueransomware30 mar 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC354
💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002
CVE-2018-7600CRITICALsob ataqueransomware30 mar 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC
lucad93/CVE-2018-3810
CVE-2018-381029 mar 2018
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RISCO
abrir
GitHub PoC5
CVE-2017-14322 Interspire Email Marketer (emailmarketer) Exploit
CVE-2017-1432227 mar 2018
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior
35RISCO
abrir
GitHub PoC
likekabin/CVE-2017-0199
CVE-2017-0199HIGHsob ataqueransomware22 mar 2018
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC1
A version of CVE-2017-0213 that I plan to use with an Empire stager
CVE-2017-0213HIGHsob ataqueransomware21 mar 2018
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RISCO
abrir
GitHub PoC1
Apache Struts CVE-2017-5638 RCE exploitation
CVE-2017-5638CRITICALsob ataqueransomware20 mar 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC26
This repository contains the POC of an exploit for node-jose < 0.11.0
CVE-2018-011420 mar 2018
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir
GitHub PoC
likekabin/CVE-2017-0213
CVE-2017-0213HIGHsob ataqueransomware19 mar 2018
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RISCO
abrir
GitHub PoC
Linux Kernel Version 4.14 - 4.4 (Ubuntu && Debian)
CVE-2017-1699519 mar 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
GitHub PoC
CVE-2018-6789
CVE-2018-6789CRITICALsob ataqueransomware16 mar 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir
GitHub PoC2
Golang exploit for CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware14 mar 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC51
PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM
CVE-2018-2380MEDIUMsob ataqueransomware14 mar 2018
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information pr
68RISCO
abrir
GitHub PoC1
PoC for SpringBreak (CVE-2017-8046)
CVE-2017-804612 mar 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISCO
abrir
anteriorpágina 446 / 471próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.