Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.231exploits catalogados
35.420CVEs com exploração pública
24.695testados em laboratório
14.119 exploits
GitHub PoC86
Aggressor Script to launch IE driveby for CVE-2018-4878
CVE-2018-4878HIGHsob ataqueransomware10 fev 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
GitHub PoC23
mdsecactivebreach/CVE-2018-4878
CVE-2018-4878HIGHsob ataqueransomware09 fev 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
GitHub PoC
Aggressor Script to just launch IE driveby for CVE-2018-4878
CVE-2018-4878HIGHsob ataqueransomware09 fev 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
GitHub PoC6
PHPMailer < 5.2.18 Remote Code Execution Exploit
CVE-2016-10033CRITICALsob ataque09 fev 2018
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
GitHub PoC8
Exploit for CVE-2017-11826
CVE-2017-11826HIGHsob ataque09 fev 2018
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Serv
93RISCO
abrir
GitHub PoC16
Ruby On Rails unrestricted render() exploit
CVE-2016-209809 fev 2018
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISCO
abrir
GitHub PoC
Code put together from a few peoples ideas credit given don't use maliciously please
CVE-2017-12617HIGHsob ataque09 fev 2018
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISCO
abrir
GitHub PoC2
Metasploit module for WordPress DOS load-scripts.php CVE-2018-638
CVE-2018-638909 fev 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
GitHub PoC2
Modification of Metasploit module for RCE in Ruby-On-Rails Console CVE-2015-3224
CVE-2015-322408 fev 2018
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RISCO
abrir
GitHub PoC57
A low interaction honeypot for the Cisco ASA component capable of detecting CVE-2018-0101, a DoS and remote code execution vulnerability.
CVE-2018-010108 fev 2018
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Softw
45RISCO
abrir
GitHub PoC1
Patch Wordpress DOS breach (CVE-2018-6389) in PHP
CVE-2018-638907 fev 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
GitHub PoC33
WebLogic Honeypot is a low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware. This is a Remote Code Execution vulnerability.
CVE-2017-10271HIGHsob ataqueransomware07 fev 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC10
WordPress DoS (CVE-2018-6389)
CVE-2018-638907 fev 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
GitHub PoC18
MICROS Honeypot is a low interaction honeypot to detect CVE-2018-2636 in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (MICROS). This is a directory traversal vulnerability.
CVE-2018-263607 fev 2018
Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security).
28RISCO
abrir
GitHub PoC14
1337g/CVE-2018-0101-DOS-POC
CVE-2018-010107 fev 2018
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Softw
45RISCO
abrir
GitHub PoC31
glibc getcwd() local privilege escalation compiled binaries
CVE-2018-100000107 fev 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir
GitHub PoC1
To solve CTFS.me problem
CVE-2016-10033CRITICALsob ataque06 fev 2018
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
GitHub PoC1
Apache RewriteRule to mitigate potential DoS attack via Wordpress wp-admin/load-scripts.php file
CVE-2018-638906 fev 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
GitHub PoC82
CVE-2018-6389 Exploit In WordPress DoS
CVE-2018-638906 fev 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
GitHub PoC
A ModSecurity ruleset for detecting potential attacks using CVE-2018-6389
CVE-2018-638906 fev 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
GitHub PoC
malware del lado del cliente de explotacion de vulnerabilidad de internet explorer 6.0 SP1 en windows xp SP2. No requiere de consentimiento por parte del usuario y no descarga ningun archivo
CVE-2006-477706 fev 2018
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) fo
60RISCO
abrir
GitHub PoC90
Test and exploit for CVE-2017-12542
CVE-2017-1254205 fev 2018
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISCO
abrir
GitHub PoC6
phpMyAdmin '/scripts/setup.php' PHP Code Injection RCE PoC (CVE-2009-1151)
CVE-2009-1151CRITICALsob ataque03 fev 2018
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RISCO
abrir
GitHub PoC22
ERPScan Public POC for CVE-2018-2636
CVE-2018-263629 jan 2018
Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security).
28RISCO
abrir
GitHub PoC
Working POC for CVE 2017-5638
CVE-2017-5638CRITICALsob ataqueransomware28 jan 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC39
The Demo for CVE-2018-1000006
CVE-2018-100000625 jan 2018
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro
60RISCO
abrir
GitHub PoC20
BMC Bladelogic RSCD exploits including remote code execution - CVE-2016-1542, CVE-2016-1543, CVE-2016-5063
CVE-2016-154224 jan 2018
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U
60RISCO
abrir
GitHub PoC
CVE-2017-7269利用代码(rb文件)
CVE-2017-7269CRITICALsob ataque24 jan 2018
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC1
dewankpant/CVE-2017-16568
CVE-2017-1656821 jan 2018
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality.
23RISCO
abrir
GitHub PoC1
备忘:flash挂马工具备份 CVE-2018-4878
CVE-2018-4878HIGHsob ataqueransomware20 jan 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
anteriorpágina 448 / 471próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.