Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.559exploits catalogados
34.978CVEs com exploração pública
24.695testados em laboratório
76.313 exploits
VulnCheck XDB
initial-access
CVE-2024-28987CRITICALsob ataque22 out 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISCO
abrir
GitHub PoC2
CVE-2024-6387, also known as RegreSSHion, is a high-severity vulnerability found in OpenSSH servers (sshd) running on glibc-based Linux systems. It is a regression of a previously fixed vulnerability (CVE-2006-5051), which means the issue was reintroduced in newer versions of OpenSSH.
CVE-2024-6387HIGH22 out 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALsob ataqueransomware22 out 2024
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALsob ataque21 out 2024
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-21683HIGH21 out 2024
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and
78RISCO
abrir
GitHub PoC39
Grafana RCE exploit (CVE-2024-9264)
CVE-2024-9264CRITICAL21 out 2024
Grafana SQL Expressions allow for remote code execution
85RISCO
abrir
GitHub PoC
punitdarji/Grafana-CVE-2024-9264
CVE-2024-9264CRITICAL21 out 2024
Grafana SQL Expressions allow for remote code execution
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHsob ataqueransomware21 out 2024
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-536021 out 2024
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
GitHub PoC11
p33d/CVE-2024-23113
CVE-2024-23113CRITICALsob ataque21 out 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISCO
abrir
VulnCheck XDB
local
CVE-2023-32784HIGH21 out 2024
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-47253CRITICAL21 out 2024
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques
68RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-21975HIGHsob ataqueransomware21 out 2024
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALsob ataque21 out 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware21 out 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL21 out 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque21 out 2024
Grafana path traversal
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-23113CRITICALsob ataque21 out 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-16651HIGHsob ataque21 out 2024
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
98RISCO
abrir
VulnCheck XDB
local
CVE-2024-35250HIGHsob ataque21 out 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RISCO
abrir
GitHub PoC5
Arbitrary File Read and DoS in vendure-ecommerce exploit
CVE-2024-48914CRITICAL21 out 2024
Vendure asset server plugin has local file read vulnerability with AssetServerPlugin & LocalAssetStorageStrategy
75RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-48914CRITICAL21 out 2024
Vendure asset server plugin has local file read vulnerability with AssetServerPlugin & LocalAssetStorageStrategy
75RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM21 out 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM20 out 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
GitHub PoC7
File Read Proof of Concept for CVE-2024-9264
CVE-2024-9264CRITICAL20 out 2024
Grafana SQL Expressions allow for remote code execution
85RISCO
abrir
GitHub PoC5
Proof-of-Concept for LFI/Path Traversal vulnerability in Aiohttp =< 3.9.1
CVE-2024-23334MEDIUM20 out 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
GitHub PoC1
Affected versions of this package are vulnerable to Race Condition. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this could potentially allow a malicious user to execute code remotely.
CVE-2021-32708CRITICAL19 out 2024
Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystem
48RISCO
abrir
Metasploit300
OneDev Unauthenticated Arbitrary File Read
CVE-2024-45309HIGH19 out 2024
OneDev vulnerable to arbitrary file reading for unauthenticated user
41RISCO
abrir
GitHub PoC132
Exploit for Grafana arbitrary file-read and RCE (CVE-2024-9264)
CVE-2024-9264CRITICAL19 out 2024
Grafana SQL Expressions allow for remote code execution
85RISCO
abrir
GitHub PoC2
Security Bulletin for CVE-2024-35133 - With PoC
CVE-2024-35133MEDIUM18 out 2024
IBM Security Verify Access HTTP open redirect
33RISCO
abrir
anteriorpágina 338 / 2.544próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.