Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
8.216 exploits
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataque04 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-40449HIGHsob ataqueransomware04 mar 2022
Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALsob ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALsob ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALsob ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-1472MEDIUMsob ataqueransomware03 mar 2022
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALsob ataque03 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataque03 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataque03 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataque03 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataque02 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALsob ataque02 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
VulnCheck XDB
local
CVE-2018-100000101 mar 2022
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-23131CRITICALsob ataque28 fev 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHsob ataque28 fev 2022
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataque28 fev 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
local
CVE-2022-0492HIGHsob ataque28 fev 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-24086CRITICALsob ataque28 fev 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALsob ataqueransomware28 fev 2022
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware27 fev 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2022-21971HIGHsob ataque26 fev 2022
Windows Runtime Remote Code Execution Vulnerability
83RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataque25 fev 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque25 fev 2022
Grafana path traversal
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-2506025 fev 2022
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_sta
35RISCO
abrir
VulnCheck XDB
local
CVE-2021-3560HIGHsob ataque25 fev 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir
VulnCheck XDB
client-side
CVE-2022-22242MEDIUM24 fev 2022
Junos OS: Cross-site Scripting (XSS) vulnerability in J-Web
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-23131CRITICALsob ataque24 fev 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-44228CRITICALsob ataqueransomware24 fev 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-23131CRITICALsob ataque23 fev 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-24112CRITICALsob ataque22 fev 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISCO
abrir
anteriorpágina 196 / 274próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.