Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.231exploits catalogados
35.420CVEs com exploração pública
24.695testados em laboratório
14.131 exploits
GitHub PoC1
CVE-2000-0170
CVE-2000-017008 nov 2014
Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variabl
23RISCO
abrir
GitHub PoC2
:scream: Python library and utility for CVE-2014-6271 (aka. "shellshock")
CVE-2014-6271CRITICALsob ataque06 nov 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC5
DEPRECATED: Chef cookbook to audit & remediate "Shellshock" (BASH-CVE-2014-7169)
CVE-2014-7169CRITICALsob ataque31 out 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISCO
abrir
GitHub PoC10
Exploit for CVE-2014-7236
CVE-2014-723612 out 2014
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary
50RISCO
abrir
GitHub PoC1
Heartbleed (CVE-2014-0160) SSLv3 Scanner
CVE-2014-0160HIGHsob ataque12 out 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC7
Repository for CVE-2014-4936 POC code.
CVE-2014-493605 out 2014
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE)
43RISCO
abrir
GitHub PoC3
Libsafe - Safety Check Bypass Vulnerability (Proof of Concept Exploit & Time Randomization to Thwart It)
CVE-2005-112504 out 2014
Race condition in libsafe 2.0.16 and earlier, when running in multi-threaded applications, allows attackers to bypass li
23RISCO
abrir
GitHub PoC11
Android app to scan for bash Vulnerability - CVE-2014-6271 also known as Shellshock
CVE-2014-6271CRITICALsob ataque03 out 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
This module determine the vulnerability of a bash binary to the shellshock exploits (CVE-2014-6271 or CVE-2014-7169) and then patch that where possible
CVE-2014-6271CRITICALsob ataque29 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC2
CVE-2014-6271 Remote Interactive Shell - PoC Exploit
CVE-2014-6271CRITICALsob ataque29 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC1
ryeyao/CVE-2014-6271_Test
CVE-2014-6271CRITICALsob ataque29 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC13
shellshock CVE-2014-6271 CGI Exploit, Use like Openssh via CGI
CVE-2014-6271CRITICALsob ataque29 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC1
A script, in C, to check if CGI scripts are vulnerable to CVE-2014-6271 (The Bash Bug)
CVE-2014-6271CRITICALsob ataque28 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC12
A python script to enumerate CGI scripts vulnerable to CVE-2014-6271 on one specific server
CVE-2014-6271CRITICALsob ataque28 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
u20024804/bash-4.3-fixed-CVE-2014-6271
CVE-2014-6271CRITICALsob ataque27 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
u20024804/bash-3.2-fixed-CVE-2014-6271
CVE-2014-6271CRITICALsob ataque27 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
u20024804/bash-4.2-fixed-CVE-2014-6271
CVE-2014-6271CRITICALsob ataque27 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
Debian Lenny Bash packages with cve-2014-6271 patches (i386 and amd64)
CVE-2014-6271CRITICALsob ataque26 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
Ansible role to check the CVE-2014-6271 vulnerability
CVE-2014-6271CRITICALsob ataque26 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC4
CVE-2014-6271 (ShellShock) RCE PoC tool
CVE-2014-6271CRITICALsob ataque26 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC1
Salt recipe for shellshock (CVE-2014-6271)
CVE-2014-6271CRITICALsob ataque26 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC1
An A/V evasion armoring experiment for CVE-2012-4681
CVE-2012-4681CRITICALsob ataqueransomware26 set 2014
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow
100RISCO
abrir
GitHub PoC
scaner for cve-2014-6271
CVE-2014-6271CRITICALsob ataque26 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
a auto script to fix CVE-2014-6271 bash vulnerability
CVE-2014-6271CRITICALsob ataque25 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
mattclegg/CVE-2014-6271
CVE-2014-6271CRITICALsob ataque25 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
rrreeeyyy/cve-2014-6271-spec
CVE-2014-6271CRITICALsob ataque25 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
Chef cookbook that will fail if bash vulnerability found per CVE-2014-6271
CVE-2014-6271CRITICALsob ataque25 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC46
Python Scanner for "ShellShock" (CVE-2014-6271)
CVE-2014-6271CRITICALsob ataque25 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC1
Written fro CVE-2014-6271
CVE-2014-6271CRITICALsob ataque25 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
Quick and dirty nessus .audit file to check is bash is vulnerable to CVE-2014-6271
CVE-2014-6271CRITICALsob ataque25 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
anteriorpágina 468 / 472próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.