Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
8.410 exploits
VulnCheck XDB
local
CVE-2012-005630 mar 2021
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when
28RISCO
abrir
VulnCheck XDB
local
CVE-2014-3153HIGHsob ataque30 mar 2021
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISCO
abrir
VulnCheck XDB
local
CVE-2015-754730 mar 2021
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISCO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHsob ataque30 mar 2021
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
VulnCheck XDB
local
CVE-2016-072830 mar 2021
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHsob ataque30 mar 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
VulnCheck XDB
local
CVE-2018-100000130 mar 2021
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir
VulnCheck XDB
local
CVE-2021-22555HIGHsob ataque30 mar 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISCO
abrir
VulnCheck XDB
local
CVE-2017-100036730 mar 2021
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-7494CRITICALsob ataqueransomware30 mar 2021
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALsob ataqueransomware29 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALsob ataque28 mar 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-133526 mar 2021
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALsob ataqueransomware26 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-023225 mar 2021
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-2551CRITICALsob ataque25 mar 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-2629524 mar 2021
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-27065HIGHsob ataqueransomware24 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALsob ataqueransomware24 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-2629523 mar 2021
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-27065HIGHsob ataqueransomware23 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALsob ataqueransomware23 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALsob ataqueransomware22 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALsob ataqueransomware21 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-26855CRITICALsob ataqueransomware21 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALsob ataqueransomware19 mar 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2017-100017019 mar 2021
jqueryFileTree 2.1.5 and older Directory Traversal
50RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALsob ataqueransomware19 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque19 mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque19 mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
anteriorpágina 230 / 281próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.