Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
77.900 exploits
Metasploit300
WordPress WPS Hide Login Login Page Revealer
CVE-2021-2491727 out 2021
WPS Hide Login < 1.9.1 - Protection Bypass with Referer-Header
40RISCO
abrir
GitHub PoC27
cve-2021-42013.py is a python script that will help in finding Path Traversal or Remote Code Execution vulnerability in Apache 2.4.50
CVE-2021-42013CRITICALsob ataqueransomware27 out 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
rafaelcaria/drupalgeddon2-CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware27 out 2021
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC21
VMware vCenter Server任意文件上传漏洞 / Code By:Jun_sheng
CVE-2021-22005CRITICALsob ataqueransomware27 out 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
Metasploit600
Zimbra zmslapd arbitrary module load
CVE-2022-3739327 out 2021
Zimbra zmslapd arbitrary module load
18RISCO
abrir
GitHub PoC298
command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
CVE-2021-36260CRITICALsob ataque27 out 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALsob ataqueransomware27 out 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALsob ataqueransomware27 out 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALsob ataque27 out 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALsob ataqueransomware27 out 2021
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC
b1tg/CVE-2021-34486-exp
CVE-2021-34486HIGHsob ataque27 out 2021
Windows Event Tracing Elevation of Privilege Vulnerability
71RISCO
abrir
VulnCheck XDB
local
CVE-2021-21551HIGHsob ataque27 out 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISCO
abrir
GitHub PoC7
CVE-2021-26084,Atlassian Confluence OGNL注入漏洞
CVE-2021-26084CRITICALsob ataqueransomware26 out 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALsob ataqueransomware26 out 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC11
Remote Code Execution exploit for Apache servers. Affected versions: Apache 2.4.49, Apache 2.4.50
CVE-2021-41773HIGHsob ataqueransomware26 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
MazX0p/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware25 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC45
LPE exploit for a UAF in Windows (CVE-2021-40449).
CVE-2021-40449HIGHsob ataqueransomware25 out 2021
Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
Metasploit600
Apache Storm Nimbus getTopologyHistory Unauthenticated Command Execution
CVE-2021-3829425 out 2021
Shell Command Injection Vulnerability in Nimbus Thrift Server
40RISCO
abrir
GitHub PoC
Script fo testing CVE-2000-0649 for Apache and MS IIS servers
CVE-2000-064925 out 2021
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RISCO
abrir
Exploit-DB
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2)
CVE-2021-42013CRITICALsob ataqueransomwarewebappsmultiple25 out 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
A automatic scanner to apache 2.4.49
CVE-2021-41773HIGHsob ataqueransomware25 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALsob ataqueransomware25 out 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
Exploit-DB
Hikvision Web Server Build 210702 - Command Injection
CVE-2021-36260CRITICALsob ataquewebappshardware25 out 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
GitHub PoC1
confluence远程代码执行RCE / Code By:Jun_sheng
CVE-2021-26084CRITICALsob ataqueransomware25 out 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC18
PoC for the CVE-2021-20837 : RCE in MovableType
CVE-2021-2083725 out 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISCO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 4.8.1 - Remote Code Execution (RCE)
CVE-2018-12613webappsphp25 out 2021
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-2083725 out 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISCO
abrir
VulnCheck XDB
local
CVE-2021-40449HIGHsob ataqueransomware25 out 2021
Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
Exploit-DB
WordPress Plugin TaxoPress 3.0.7.1 - Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-24444webappsphp25 out 2021
TaxoPress < 3.0.7.2 - Authenticated Stored Cross-Site Scripting (XSS)
23RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-40438CRITICALsob ataqueransomware24 out 2021
mod_proxy SSRF
100RISCO
abrir
anteriorpágina 643 / 2.597próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.