Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.231exploits catalogados
35.420CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.266GitHub PoC 14.131VulnCheck XDB 8.635Nuclei 4.274Metasploit 3.474✓ só verificadosrecentespopularesrisco
14.131 exploits
GitHub PoC★ 2
cinno/CVE-2015-7755-POC
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r
100RISCO
abrir ↗GitHub PoC★ 8
All versions of the Joomla! below 3.4.6 are known to be vulnerable. But exploitation is possible with PHP versions below 5.5.29, 5.6.13 and below 5.5.
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISCO
abrir ↗GitHub PoC★ 2
A proof of concept for Joomla's CVE-2015-8562 vulnerability
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISCO
abrir ↗GitHub PoC★ 3
ockeghem/CVE-2015-6835-checker
The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_
35RISCO
abrir ↗GitHub PoC★ 105
Notes, binaries, and related information from analysis of the CVE-2015-7755 & CVE-2015-7756 issues within Juniper ScreenOS
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r
100RISCO
abrir ↗GitHub PoC★ 3
Crash PoC
Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7
23RISCO
abrir ↗GitHub PoC★ 17
Python script to generate a malicious MP4 file and start a CherryPy web server hosting a simple HTML page with the embedded file. Exploits another Stagefright vulnerability, the integer overflow (CVE-2015-3864).
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RISCO
abrir ↗GitHub PoC★ 5
Estudo e apresentação do bug CVE-2014-4943 para a disciplina MAC0448
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by
23RISCO
abrir ↗GitHub PoC★ 5
My exploit for kernel exploitation
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISCO
abrir ↗GitHub PoC★ 1
PoC code for vBulletin PreAuth vulnerability
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RISCO
abrir ↗GitHub PoC★ 1
Joomla! 3.2 to 3.4.4 - SQL Injection (CVE-2015-7297, CVE-2015-7857, and CVE-2015-7858)
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISCO
abrir ↗GitHub PoC★ 23
Script to extract malicious payload and decoy document from CVE-2015-1641 exploit documents
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Comp
93RISCO
abrir ↗GitHub PoC
Dockerfile for testing CVE-2014-0160 Heartbleed exploitation.
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗GitHub PoC
Quick and dirty .py for checking (CVE-2015-1635) MS15-034 + DoS attack option
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir ↗GitHub PoC
gina-alaska/bash-cve-2014-7169-cookbook
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISCO
abrir ↗GitHub PoC★ 11
CVE-2015-3073 PoC
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass inten
28RISCO
abrir ↗GitHub PoC★ 11
Network Scanner for OpenSSL Memory Leak (CVE-2014-0160)
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗GitHub PoC★ 1
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISCO
abrir ↗GitHub PoC★ 12
Archive from the article CVE-2015-5119 Flash ByteArray UaF: A beginner's walkthrough
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RISCO
abrir ↗GitHub PoC★ 205
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISCO
abrir ↗GitHub PoC★ 3
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISCO
abrir ↗GitHub PoC★ 1
drone789/CVE-2012-1823
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISCO
abrir ↗GitHub PoC★ 1
Just an attempt to adapt for Note 4, I do not know what I am doing.
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RISCO
abrir ↗GitHub PoC★ 2
An implementation of the CVE-2015-2153 exploit.
The rpki_rtr_pdu_print function in print-rpki-rtr.c in the TCP printer in tcpdump before 4.7.2 allows remote attackers t
28RISCO
abrir ↗GitHub PoC
Windows 2k3 tcpip.sys Privilege Escalation
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RISCO
abrir ↗GitHub PoC★ 1
PoC exploit for CVE-2015-5477 in php
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISCO
abrir ↗GitHub PoC★ 3
PoC - Binary patches for CVE-2015-3864 (NOT for production, use at your own risk)
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RISCO
abrir ↗GitHub PoC★ 24
CVE-2014-4322 Exploit
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RISCO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2015-4495 / mfsa2015-78
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
98RISCO
abrir ↗GitHub PoC★ 1
PoC for BIND9 TKEY assert DoS (CVE-2015-5477)
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.