Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.231exploits catalogados
35.420CVEs com exploração pública
24.695testados em laboratório
14.123 exploits
GitHub PoC
CVE-2017-7269利用代码(rb文件)
CVE-2017-7269CRITICALsob ataque24 jan 2018
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC20
BMC Bladelogic RSCD exploits including remote code execution - CVE-2016-1542, CVE-2016-1543, CVE-2016-5063
CVE-2016-154224 jan 2018
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U
60RISCO
abrir
GitHub PoC1
dewankpant/CVE-2017-16568
CVE-2017-1656821 jan 2018
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality.
23RISCO
abrir
GitHub PoC1
备忘:flash挂马工具备份 CVE-2018-4878
CVE-2018-4878HIGHsob ataqueransomware20 jan 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
GitHub PoC
WebLogic wls-wsat RCE CVE-2017-10271
CVE-2017-10271HIGHsob ataqueransomware19 jan 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC1
Struts2 Application Vulnerable to CVE-2017-5638. Explains how the exploit of the vulnerability works in relation to OGNL and the JakartaMultiPart parser.
CVE-2017-5638CRITICALsob ataqueransomware18 jan 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC7
cve-2017-10271 POC
CVE-2017-10271HIGHsob ataqueransomware18 jan 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC4
Minishare 1.4.1 Remote Buffer Overflow
CVE-2004-227117 jan 2018
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RISCO
abrir
GitHub PoC
likekabin/CVE-2017-11882
CVE-2017-11882HIGHsob ataqueransomware16 jan 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC11
likekabin/CVE-2018-0802_CVE-2017-11882
CVE-2017-11882HIGHsob ataqueransomware16 jan 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC177
Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler)
CVE-2017-9248CRITICALsob ataque16 jan 2018
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISCO
abrir
GitHub PoC5
CVE-2017-10271 Weblogic 漏洞验证Poc及补丁
CVE-2017-10271HIGHsob ataqueransomware16 jan 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC11
likekabin/CVE-2018-0802_CVE-2017-11882
CVE-2018-0802HIGHsob ataque16 jan 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISCO
abrir
GitHub PoC
Assesses a system for the "speculative execution" vulnerabilities described in CVE-2017-5715, CVE-2017-5753, CVE-2017-5754
CVE-2017-5715MEDIUM15 jan 2018
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RISCO
abrir
GitHub PoC17
a list of BIOS/Firmware fixes adressing CVE-2017-5715, CVE-2017-5753, CVE-2017-5754
CVE-2017-5715MEDIUM14 jan 2018
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RISCO
abrir
GitHub PoC166
PoC for CVE-2018-0802 And CVE-2017-11882
CVE-2017-11882HIGHsob ataqueransomware12 jan 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC166
PoC for CVE-2018-0802 And CVE-2017-11882
CVE-2018-0802HIGHsob ataque12 jan 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISCO
abrir
GitHub PoC270
PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)
CVE-2018-0802HIGHsob ataque11 jan 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISCO
abrir
GitHub PoC68
Exploit the vulnerability to execute the calculator
CVE-2018-0802HIGHsob ataque11 jan 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISCO
abrir
GitHub PoC270
PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)
CVE-2017-11882HIGHsob ataqueransomware11 jan 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC54
Spectre exploit
CVE-2017-5715MEDIUM09 jan 2018
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RISCO
abrir
GitHub PoC180
Telerik UI for ASP.NET AJAX File upload and .NET deserialisation exploit (CVE-2017-11317, CVE-2017-11357, CVE-2019-18935)
CVE-2019-18935CRITICALsob ataqueransomware09 jan 2018
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir
GitHub PoC11
TwonkyMedia Server 7.0.11-8.5 Directory Traversal CVE-2018-7171
CVE-2018-717109 jan 2018
Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of a
28RISCO
abrir
GitHub PoC180
Telerik UI for ASP.NET AJAX File upload and .NET deserialisation exploit (CVE-2017-11317, CVE-2017-11357, CVE-2019-18935)
CVE-2017-11317CRITICALsob ataque09 jan 2018
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RISCO
abrir
GitHub PoC9
8.4.1 Jailbreak using CVE-2016-4655 / CVE-2016-4656
CVE-2016-4655MEDIUMsob ataque09 jan 2018
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RISCO
abrir
GitHub PoC185
Proof of Concept exploit for CVE-2017-8570
CVE-2017-8570HIGHsob ataque09 jan 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISCO
abrir
GitHub PoC1
OSX 10.13.2, CVE-2017-5753, Spectre, PoC, C, ASM for OSX, MAC, Intel Arch, Proof of Concept, Hopper.App Output
CVE-2017-5753MEDIUM07 jan 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISCO
abrir
GitHub PoC
Simply diff for CVE-2017-0785
CVE-2017-078507 jan 2018
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISCO
abrir
GitHub PoC7
The demo of the speculative execution attack Spectre (CVE-2017-5753, CVE-2017-5715).
CVE-2017-5753MEDIUM06 jan 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISCO
abrir
GitHub PoC1
Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715)
CVE-2017-5753MEDIUM06 jan 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISCO
abrir
anteriorpágina 449 / 471próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.