Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
77.866 exploits
GitHub PoC
Metabase 任意文件读取
CVE-2021-41277CRITICALsob ataque22 nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISCO
abrir
GitHub PoC
MetaBase 任意文件读取漏洞 fofa批量poc
CVE-2021-41277CRITICALsob ataque22 nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISCO
abrir
GitHub PoC2
CrackerCat/CVE-2021-26411
CVE-2021-26411HIGHsob ataqueransomware22 nov 2021
Internet Explorer Memory Corruption Vulnerability
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-1676322 nov 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-41277CRITICALsob ataque22 nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISCO
abrir
GitHub PoC4
Druva inSync Windows Client 6.6.3 - Local Privilege Escalation (PowerShell) RCE
CVE-2020-575221 nov 2021
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RISCO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHsob ataque21 nov 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
GitHub PoC11
PoC for CVE-2021-41277
CVE-2021-41277CRITICALsob ataque21 nov 2021
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHsob ataque21 nov 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware19 nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-22555HIGHsob ataque19 nov 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISCO
abrir
GitHub PoC
CVE-2021-43617 bypass CRF
CVE-2021-4361719 nov 2021
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Val
28RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALsob ataqueransomware18 nov 2021
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC1
CVE-2013-2171
CVE-2013-217118 nov 2021
The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEAS
38RISCO
abrir
Exploit-DB
GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2021-22205CRITICALsob ataqueransomwarewebappsruby17 nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
GitHub PoC
cve-2020-35314,一个带phpcode的zip文件
CVE-2020-3531417 nov 2021
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, al
28RISCO
abrir
Exploit-DBVexDay Proof
SuiteCRM 7.11.18 - Remote Code Execution (RCE) (Authenticated) (Metasploit)
CVE-2021-42840webappsphp17 nov 2021
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumsta
50RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-17562HIGHsob ataque17 nov 2021
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISCO
abrir
GitHub PoC1
PoC for CVE-2017-17562 written in bash
CVE-2017-17562HIGHsob ataque17 nov 2021
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALsob ataqueransomware17 nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3758017 nov 2021
Apache ShenYu Admin bypass JWT authentication
50RISCO
abrir
Exploit-DB
Bludit 3.13.1 - 'username' Cross Site Scripting (XSS)
CVE-2021-35323webappsphp17 nov 2021
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
38RISCO
abrir
GitHub PoC
Confluence server webwork OGNL injection
CVE-2021-26086MEDIUMsob ataque16 nov 2021
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RISCO
abrir
GitHub PoC
Demonstration of CVE-2018-19571: GitLab SSRF CVE
CVE-2018-1957116 nov 2021
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RISCO
abrir
VulnCheck XDB
local
CVE-2020-0787HIGHsob ataqueransomware16 nov 2021
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISCO
abrir
Exploit-DB
Online Learning System 2.0 - Remote Code Execution (RCE)
CVE-2021-42580webappsphp16 nov 2021
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/adm
23RISCO
abrir
GitHub PoC34
CVE-2020-0787的简单回显
CVE-2020-0787HIGHsob ataqueransomware16 nov 2021
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISCO
abrir
GitHub PoC117
Exploit for command injection vulnerability found in uhttpd binary from TP-Link Tapo c200 IP camera
CVE-2021-4045CRITICAL15 nov 2021
TP-LINK Tapo C200 remote code execution vulnerability
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-4045CRITICAL15 nov 2021
TP-LINK Tapo C200 remote code execution vulnerability
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-2883CRITICALsob ataque15 nov 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISCO
abrir
anteriorpágina 638 / 2.596próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.