Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
77.151 exploits
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALsob ataqueransomware21 dez 2023
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware21 dez 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-19781CRITICALsob ataqueransomware21 dez 2023
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-10148CRITICALsob ataque21 dez 2023
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-578221 dez 2023
Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arb
28RISCO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHsob ataque21 dez 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque21 dez 2023
Grafana path traversal
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2012-486921 dez 2023
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attacke
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2016-4657HIGHsob ataque21 dez 2023
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware21 dez 2023
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware21 dez 2023
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-35587CRITICALsob ataque21 dez 2023
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported ver
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware21 dez 2023
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque21 dez 2023
Grafana path traversal
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-15999CRITICALsob ataque21 dez 2023
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploi
90RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2011-319221 dez 2023
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISCO
abrir
VulnCheck XDB
local
CVE-2017-0213HIGHsob ataqueransomware21 dez 2023
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALsob ataque21 dez 2023
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHsob ataqueransomware21 dez 2023
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-21661HIGH21 dez 2023
SQL injection in WordPress
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-20250HIGHsob ataqueransomware21 dez 2023
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-0199HIGHsob ataqueransomware21 dez 2023
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHsob ataqueransomware21 dez 2023
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-9276HIGHsob ataque21 dez 2023
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISCO
abrir
GitHub PoC1
Directory Traversal and Arbitrary File Read on Grafana
CVE-2021-43798HIGHsob ataque21 dez 2023
Grafana path traversal
100RISCO
abrir
VulnCheck XDB
local
CVE-2018-19320HIGHsob ataqueransomware21 dez 2023
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-21985CRITICALsob ataqueransomware21 dez 2023
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALsob ataque21 dez 2023
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALsob ataque21 dez 2023
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-120721 dez 2023
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute
60RISCO
abrir
anteriorpágina 438 / 2.572próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.