Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
24.460 exploits
Exploit-DB
htmly 2.8.0 - 'description' Stored Cross-Site Scripting (XSS)
CVE-2021-30637webappsmultiple15 abr 2021
htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.
23RISCO
abrir
Exploit-DB
Horde Groupware Webmail 5.2.22 - Stored XSS
CVE-2021-26929webappsmultiple15 abr 2021
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library befor
23RISCO
abrir
Exploit-DB
Tileserver-gl 3.0.0 - 'key' Reflected Cross-Site Scripting (XSS)
CVE-2020-15500webappsmultiple15 abr 2021
An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected u
43RISCO
abrir
Exploit-DB
MariaDB 10.2 - 'wsrep_provider' OS Command Execution
CVE-2021-27928locallinux14 abr 2021
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
35RISCO
abrir
Exploit-DB
jQuery 1.2 - Cross-Site Scripting (XSS)
CVE-2020-11022MEDIUMwebappsmultiple14 abr 2021
jQuery has a potential XSS vulnerability
55RISCO
abrir
Exploit-DB
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 - RCE
CVE-2021-29003webappshardware14 abr 2021
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacter
35RISCO
abrir
Exploit-DB
CITSmart ITSM 9.1.2.27 - 'query' Time-based Blind SQL Injection (Authenticated)
CVE-2021-28142webappsjava14 abr 2021
CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."
23RISCO
abrir
Exploit-DB
CITSmart ITSM 9.1.2.22 - LDAP Injection
CVE-2020-35775webappsjava14 abr 2021
CITSmart before 9.1.2.23 allows LDAP Injection.
28RISCO
abrir
Exploit-DB
jQuery 1.0.3 - Cross-Site Scripting (XSS)
CVE-2020-11023MEDIUMsob ataquewebappsmultiple14 abr 2021
Potential XSS vulnerability in jQuery
85RISCO
abrir
Exploit-DB
ExpressVPN VPN Router 1.0 - Router Login Panel's Integer Overflow
CVE-2020-29238webappsmultiple13 abr 2021
An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensi
28RISCO
abrir
Exploit-DBVexDay Proof
vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-2523remoteunix12 abr 2021
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
Exploit-DB
PrestaShop 1.7.6.7 - 'location' Blind Sql Injection
CVE-2020-15160webappsphp09 abr 2021
Blind SQL Injection in PrestaShop
28RISCO
abrir
Exploit-DB
DMA Radius Manager 4.4.0 - Cross-Site Request Forgery (CSRF)
CVE-2021-30147webappsmultiple08 abr 2021
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
23RISCO
abrir
Exploit-DB
Composr 10.0.36 - Remote Code Execution
CVE-2021-30149webappsphp08 abr 2021
Composr 10.0.36 allows upload and execution of PHP files.
28RISCO
abrir
Exploit-DB
Linux Kernel 5.4 - 'BleedingTooth' Bluetooth Zero-Click Remote Code Execution
CVE-2020-12352remotelinux08 abr 2021
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adja
23RISCO
abrir
Exploit-DB
Linux Kernel 5.4 - 'BleedingTooth' Bluetooth Zero-Click Remote Code Execution
CVE-2020-12351remotelinux08 abr 2021
Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via a
23RISCO
abrir
Exploit-DB
Atlassian Jira Service Desk 4.9.1 - Unrestricted File Upload to XSS
CVE-2020-14166webappsmultiple07 abr 2021
The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remo
23RISCO
abrir
Exploit-DB
Dell OpenManage Server Administrator 9.4.0.0 - Arbitrary File Read
CVE-2020-5377CRITICALwebappswindows07 abr 2021
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
60RISCO
abrir
Exploit-DB
Composr CMS 10.0.36 - Cross Site Scripting
CVE-2021-30150webappsphp07 abr 2021
Composr 10.0.36 allows XSS in an XML script.
23RISCO
abrir
Exploit-DB
Google Chrome 86.0.4240 V8 - Remote Code Execution
CVE-2020-16040remotemultiple06 abr 2021
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RISCO
abrir
Exploit-DB
Google Chrome 81.0.4044 V8 - Remote Code Execution
CVE-2020-6507remotemultiple06 abr 2021
Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap
28RISCO
abrir
Exploit-DB
F5 BIG-IP 16.0.x - iControl REST Remote Code Execution (Unauthenticated)
CVE-2021-22986CRITICALsob ataqueransomwarewebappshardware02 abr 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
Exploit-DB
Concrete5 8.5.4 - 'name' Stored XSS
CVE-2021-3111webappsphp29 mar 2021
The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.p
23RISCO
abrir
Exploit-DB
SyncBreeze 10.1.16 - XML Parsing Stack-based Buffer Overflow
CVE-2017-15950webappswindows29 mar 2021
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary co
23RISCO
abrir
Exploit-DB
Dolibarr ERP 11.0.4 - File Upload Restrictions Bypass (Authenticated RCE)
CVE-2020-14209webappsphp25 mar 2021
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code executio
28RISCO
abrir
Exploit-DB
Linksys EA7500 2.0.8.194281 - Cross-Site Scripting
CVE-2012-6708webappshardware25 mar 2021
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differen
23RISCO
abrir
Exploit-DB
MyBB 1.8.25 - Poll Vote Count SQL Injection
CVE-2021-27946webappsphp23 mar 2021
SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).
23RISCO
abrir
Exploit-DBVexDay Proof
Codiad 2.8.4 - Remote Code Execution (Authenticated)
CVE-2018-14009webappsmultiple23 mar 2021
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.
35RISCO
abrir
Exploit-DB
WordPress Plugin Delightful Downloads Jquery File Tree 1.6.6 - Path Traversal
CVE-2017-1000170webappsphp22 mar 2021
jqueryFileTree 2.1.5 and older Directory Traversal
50RISCO
abrir
Exploit-DB
MyBB 1.8.25 - Chained Remote Command Execution
CVE-2021-27890webappsphp22 mar 2021
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
28RISCO
abrir
anteriorpágina 40 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.