Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.231exploits catalogados
35.420CVEs com exploração pública
24.695testados em laboratório
14.126 exploits
GitHub PoC1
OSX 10.13.2, CVE-2017-5753, Spectre, PoC, C, ASM for OSX, MAC, Intel Arch, Proof of Concept, Hopper.App Output
CVE-2017-5753MEDIUM07 jan 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISCO
abrir
GitHub PoC7
The demo of the speculative execution attack Spectre (CVE-2017-5753, CVE-2017-5715).
CVE-2017-5753MEDIUM06 jan 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISCO
abrir
GitHub PoC1
Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715)
CVE-2017-5753MEDIUM06 jan 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISCO
abrir
GitHub PoC12
2018年1月2日 (CVE-2017-5753 和 CVE-2017-5715) "幽灵" Spectre 漏洞利用
CVE-2017-5753MEDIUM05 jan 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISCO
abrir
GitHub PoC129
Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271)
CVE-2017-10271HIGHsob ataqueransomware05 jan 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC
A Simple PoC for CVE-2012-4681
CVE-2012-4681CRITICALsob ataqueransomware05 jan 2018
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow
100RISCO
abrir
GitHub PoC771
Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715)
CVE-2017-5753MEDIUM04 jan 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISCO
abrir
GitHub PoC4
Spectre (CVE-2017-5753) (CVE-2017-5715). Not By Me. Collected from Book.
CVE-2017-5753MEDIUM04 jan 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISCO
abrir
GitHub PoC
specloli/CVE-2017-17692
CVE-2017-1769204 jan 2018
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
60RISCO
abrir
GitHub PoC3
forked from https://github.com/s3xy/CVE-2017-10271. Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.Modified by hanc00l
CVE-2017-10271HIGHsob ataqueransomware03 jan 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC2
credit to artkond
CVE-2017-3881CRITICALsob ataque02 jan 2018
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RISCO
abrir
GitHub PoC
Exploit for CVE-2003-0264 based on pwntools and metasploit's windows/reverse_tcp
CVE-2003-026401 jan 2018
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISCO
abrir
GitHub PoC15
xyzAsian/Janus-CVE-2017-13156
CVE-2017-1315629 dez 2017
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RISCO
abrir
GitHub PoC29
CVE-2017-10271 POC
CVE-2017-10271HIGHsob ataqueransomware28 dez 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC143
WebLogic Exploit
CVE-2017-10271HIGHsob ataqueransomware28 dez 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC1
CVE-2017-17562 GOAHEAD RCE (Author: Daniel Hodson)
CVE-2017-17562HIGHsob ataque27 dez 2017
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISCO
abrir
GitHub PoC3
CVE-2017-12615 Tomcat RCE (TESTED)
CVE-2017-12615HIGHsob ataqueransomware26 dez 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
GitHub PoC3
Simplified PoC for Weblogic-CVE-2017-10271
CVE-2017-10271HIGHsob ataqueransomware25 dez 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC22
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server.
CVE-2017-10271HIGHsob ataqueransomware25 dez 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC26
CVE-2017-17215 HuaWei Router RCE (NOT TESTED)
CVE-2017-1721525 dez 2017
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could se
45RISCO
abrir
GitHub PoC39
CVE-2017-10271 WEBLOGIC RCE (TESTED)
CVE-2017-10271HIGHsob ataqueransomware23 dez 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC15
CVE-2017-12149 JBOSS RCE (TESTED)
CVE-2017-12149CRITICALsob ataqueransomware22 dez 2017
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir
GitHub PoC2
CVE-2017-15944 Palo Alto Networks firewalls remote root code execution POC
CVE-2017-15944CRITICALsob ataque19 dez 2017
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISCO
abrir
GitHub PoC15
Sudo <= 1.8.14 Local Privilege Escalation and vulnerable container
CVE-2015-560216 dez 2017
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is d
23RISCO
abrir
GitHub PoC3
RTF Cleaner, tries to extract URL from malicious RTF samples using CVE-2017-0199 & CVE-2017-8759
CVE-2017-0199HIGHsob ataqueransomware08 dez 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC
acidburnmi/CVE-2016-5195-master
CVE-2016-5195HIGHsob ataque06 dez 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC21
Better Exploit Code For CVE 2017 9805 apache struts
CVE-2017-9805HIGHsob ataque04 dez 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC
chu1337/CVE-2017-1000117
CVE-2017-100011703 dez 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RISCO
abrir
GitHub PoC
giovannidispoto/CVE-2017-13872-Patch
CVE-2017-1387230 nov 2017
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RISCO
abrir
GitHub PoC200
A POC for the Huge Dirty Cow vulnerability (CVE-2017-1000405)
CVE-2017-100040529 nov 2017
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside
23RISCO
abrir
anteriorpágina 450 / 471próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.