Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
8.410 exploits
VulnCheck XDB
initial-access
CVE-2021-21402HIGH09 abr 2021
Unauthenticated Arbitrary File Access in Jellyfin
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALsob ataque09 abr 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque09 abr 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-1938CRITICALsob ataque08 abr 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALsob ataqueransomware06 abr 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-21975HIGHsob ataqueransomware06 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-19781CRITICALsob ataqueransomware06 abr 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware06 abr 2021
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque05 abr 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-9805HIGHsob ataque04 abr 2021
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-1745303 abr 2021
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
43RISCO
abrir
VulnCheck XDB
local
CVE-2021-1732HIGHsob ataqueransomware02 abr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHsob ataqueransomware02 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHsob ataqueransomware01 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-949601 abr 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHsob ataqueransomware31 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHsob ataqueransomware31 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHsob ataqueransomware31 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALsob ataque31 mar 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataque30 mar 2021
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHsob ataque30 mar 2021
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque30 mar 2021
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
VulnCheck XDB
local
CVE-2012-005630 mar 2021
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when
28RISCO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHsob ataque30 mar 2021
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHsob ataque30 mar 2021
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
VulnCheck XDB
local
CVE-2015-754730 mar 2021
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISCO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHsob ataque30 mar 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
VulnCheck XDB
local
CVE-2018-100000130 mar 2021
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir
VulnCheck XDB
local
CVE-2016-072830 mar 2021
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir
VulnCheck XDB
local
CVE-2015-132830 mar 2021
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISCO
abrir
anteriorpágina 229 / 281próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.