Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
24.460 exploits
Exploit-DBVexDay Proof
Movable Type 7 r.5002 - XMLRPC API OS Command Injection (Metasploit)
CVE-2021-20837webappscgi29 out 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISCO
abrir
Exploit-DB
Hikvision Web Server Build 210702 - Command Injection
CVE-2021-36260CRITICALsob ataquewebappshardware25 out 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 4.8.1 - Remote Code Execution (RCE)
CVE-2018-12613webappsphp25 out 2021
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir
Exploit-DB
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2)
CVE-2021-42013CRITICALsob ataqueransomwarewebappsmultiple25 out 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
Exploit-DB
WordPress Plugin TaxoPress 3.0.7.1 - Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-24444webappsphp25 out 2021
TaxoPress < 3.0.7.2 - Authenticated Stored Cross-Site Scripting (XSS)
23RISCO
abrir
Exploit-DB
Jetty 9.4.37.v20210219 - Information Disclosure
CVE-2021-28164MEDIUMwebappsjava22 out 2021
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai
70RISCO
abrir
Exploit-DB
SonicWall SMA 10.2.1.0-17sv - Password Reset
CVE-2021-20034webappshardware20 out 2021
An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal
45RISCO
abrir
Exploit-DB
WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24719webappsphp19 out 2021
Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS)
23RISCO
abrir
Exploit-DB
myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
CVE-2021-42566webappsmultiple19 out 2021
myfactory.FMS before 7.1-912 allows XSS via the Error parameter.
38RISCO
abrir
Exploit-DB
myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
CVE-2021-42565webappsmultiple19 out 2021
myfactory.FMS before 7.1-912 allows XSS via the UID parameter.
38RISCO
abrir
Exploit-DB
Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
CVE-2018-16061webappshardware18 out 2021
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
23RISCO
abrir
Exploit-DB
Plastic SCM 10.0.16.5622 - WebAdmin Server Access
CVE-2021-41382webappsmultiple18 out 2021
Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
23RISCO
abrir
Exploit-DB
Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure
CVE-2018-16060webappshardware18 out 2021
Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listi
28RISCO
abrir
Exploit-DB
Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read
CVE-2020-11738HIGHsob ataquewebappsphp18 out 2021
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traver
100RISCO
abrir
Exploit-DB
i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS)
CVE-2021-41878webappsphp15 out 2021
A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enable
38RISCO
abrir
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE)
CVE-2021-42013CRITICALsob ataqueransomwarewebappsmultiple13 out 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
Exploit-DB
Sonicwall SonicOS 7.0 - Host Header Injection
CVE-2021-20031webappshardware13 out 2021
A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management
43RISCO
abrir
Exploit-DB
Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
CVE-2020-10770webappsjava13 out 2021
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RISCO
abrir
Exploit-DB
Maian-Cart 3.8 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2021-32172webappsphp08 out 2021
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the
50RISCO
abrir
Exploit-DB
django-unicorn 0.35.3 - Stored Cross-Site Scripting (XSS)
CVE-2021-42053webappspython08 out 2021
The Unicorn framework through 0.35.3 for Django allows XSS via component.name.
23RISCO
abrir
Exploit-DBVexDay Proof
Google SLO-Generator 2.0.0 - Code Execution
CVE-2021-22557MEDIUMlocallinux07 out 2021
Code execution in SLO Generator via YAML Payload
33RISCO
abrir
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.49 - Path Traversal & Remote Code Execution (RCE)
CVE-2021-41773HIGHsob ataqueransomwarewebappsmultiple06 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
Exploit-DB
Atlassian Jira Server Data Center 8.16.0 - Arbitrary File Read
CVE-2021-26086MEDIUMsob ataquewebappsmultiple06 out 2021
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RISCO
abrir
Exploit-DB
Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Read
CVE-2021-26085MEDIUMsob ataqueransomwarewebappsjava05 out 2021
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RISCO
abrir
Exploit-DB
WhatsUpGold 21.0.3 - Stored Cross-Site Scripting (XSS)
CVE-2021-41318webappsmultiple01 out 2021
In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input.
23RISCO
abrir
Exploit-DB
WordPress Plugin Select All Categories and Taxonomies 1.3.1 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24287webappsphp29 set 2021
Select All Categories and Taxonomies < 1.3.2 - Reflected Cross-Site Scripting (XSS)
43RISCO
abrir
Exploit-DB
WordPress Plugin Redirect 404 to Parent 1.3.0 - Reflected Cross-Site Scripting
CVE-2021-24286webappsphp29 set 2021
Redirect 404 to Parent < 1.3.1 - Reflected Cross-Site Scripting (XSS)
43RISCO
abrir
Exploit-DB
WordPress Plugin TranslatePress 2.0.8 - Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-24610webappsphp28 set 2021
TranslatePress < 2.0.9 - Authenticated Stored Cross-Site Scripting
23RISCO
abrir
Exploit-DB
WordPress Plugin Popup 1.10.4 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24275webappsphp28 set 2021
Popup by Supsystic < 1.10.5 - Reflected Cross-Site scripting (XSS)
43RISCO
abrir
Exploit-DB
WordPress Plugin Ultimate Maps 1.2.4 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24274webappsphp28 set 2021
Ultimate Maps by Supsystic < 1.2.5 - Reflected Cross-Site scripting (XSS)
43RISCO
abrir
anteriorpágina 34 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.