Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
24.460 exploits
Exploit-DB
Cibele Thinfinity VirtualUI 2.5.41.0 - User Enumeration
CVE-2021-44848webappsmultiple16 dez 2021
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques
43RISCO
abrir
Exploit-DB
Apache Log4j 2 - Remote Code Execution (RCE)
CVE-2021-44228CRITICALsob ataqueransomwareremotejava14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Exploit-DB
Apache Log4j2 2.14.1 - Information Disclosure
CVE-2021-44228CRITICALsob ataqueransomwareremotejava14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Exploit-DB
Booked Scheduler 2.7.5 - Remote Command Execution (RCE) (Authenticated)
CVE-2019-9581webappsphp14 dez 2021
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitra
28RISCO
abrir
Exploit-DB
HD-Network Real-time Monitoring System 2.0 - Local File Inclusion (LFI)
CVE-2021-45043remotelinux13 dez 2021
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_L
50RISCO
abrir
Exploit-DB
WebHMI 4.0 - Remote Code Execution (RCE) (Authenticated)
CVE-2021-43936CRITICALwebappsphp13 dez 2021
Distributed Data Systems WebHM
60RISCO
abrir
Exploit-DB
Student Management System 1.0 - SQLi Authentication Bypass
CVE-2020-23935webappsphp09 dez 2021
Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (
28RISCO
abrir
Exploit-DB
Raspberry Pi 5.10 - Default Credentials
CVE-2021-38759remotelinux09 dez 2021
Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain a
28RISCO
abrir
Exploit-DB
Grafana 8.3.0 - Directory Traversal and Arbitrary File Read
CVE-2021-43798HIGHsob ataquewebappsmultiple09 dez 2021
Grafana path traversal
100RISCO
abrir
Exploit-DB
Auerswald COMpact 8.0B - Multiple Backdoors
CVE-2021-40859remotehardware06 dez 2021
Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web
60RISCO
abrir
Exploit-DB
Croogo 3.0.2 - Remote Code Execution (Authenticated)
CVE-2021-44673webappsphp06 dez 2021
A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malic
23RISCO
abrir
Exploit-DB
WordPress Plugin DZS Zoomsounds 6.45 - Arbitrary File Read (Unauthenticated)
CVE-2021-39316HIGHwebappsphp03 dez 2021
ZoomSounds <= 6.45 Unauthenticated Directory Traversal and Sensitive Information Dislosure
68RISCO
abrir
Exploit-DB
Online Enrollment Management System in PHP and PayPal 1.0 - 'U_NAME' Stored Cross-Site Scripting
CVE-2021-40577webappsphp01 dez 2021
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP an
23RISCO
abrir
Exploit-DB
Linux Kernel 5.1.x - 'PTRACE_TRACEME' pkexec Local Privilege Escalation (2)
CVE-2019-13272HIGHsob ataquelocallinux23 nov 2021
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
Exploit-DB
GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2021-22205CRITICALsob ataqueransomwarewebappsruby17 nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
Exploit-DB
Bludit 3.13.1 - 'username' Cross Site Scripting (XSS)
CVE-2021-35323webappsphp17 nov 2021
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
38RISCO
abrir
Exploit-DBVexDay Proof
SuiteCRM 7.11.18 - Remote Code Execution (RCE) (Authenticated) (Metasploit)
CVE-2021-42840webappsphp17 nov 2021
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumsta
50RISCO
abrir
Exploit-DB
Online Learning System 2.0 - Remote Code Execution (RCE)
CVE-2021-42580webappsphp16 nov 2021
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/adm
23RISCO
abrir
Exploit-DB
PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF)
CVE-2021-43617webappsphp15 nov 2021
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Val
28RISCO
abrir
Exploit-DB
Simple Subscription Website 1.0 - SQLi Authentication Bypass
CVE-2021-43140webappsphp15 nov 2021
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
23RISCO
abrir
Exploit-DB
WordPress Plugin WPSchoolPress 2.1.16 - 'Multiple' Cross Site Scripting (XSS)
CVE-2021-24664webappsphp15 nov 2021
WPSchoolPress < 2.1.17 - Multiple Admin+ Stored Cross-Site Scripting
23RISCO
abrir
Exploit-DB
FormaLMS 2.4.4 - Authentication Bypass
CVE-2021-43136webappsmultiple11 nov 2021
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain
28RISCO
abrir
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
CVE-2021-41773HIGHsob ataqueransomwarewebappsmultiple11 nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
CVE-2021-42013CRITICALsob ataqueransomwarewebappsmultiple11 nov 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
Exploit-DB
FusionPBX 4.5.29 - Remote Code Execution (RCE) (Authenticated)
CVE-2021-43405webappsphp08 nov 2021
An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained t
35RISCO
abrir
Exploit-DB
OpenAM 13.0 - LDAP Injection
CVE-2021-29156webappsjava03 nov 2021
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacke
60RISCO
abrir
Exploit-DB
Fuel CMS 1.4.1 - Remote Code Execution (3)
CVE-2018-16763webappsphp03 nov 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
Exploit-DB
Eclipse Jetty 11.0.5 - Sensitive File Disclosure
CVE-2021-34429MEDIUMwebappsjava03 nov 2021
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
70RISCO
abrir
Exploit-DB
Ericsson Network Location MPS GMPC21 - Privilege Escalation (Metasploit)
CVE-2021-43338webappsmultiple02 nov 2021
20RISCO
abrir
Exploit-DBVexDay Proof
Movable Type 7 r.5002 - XMLRPC API OS Command Injection (Metasploit)
CVE-2021-20837webappscgi29 out 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISCO
abrir
anteriorpágina 33 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.