Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
77.900 exploits
VulnCheck XDB
initial-access
CVE-2019-398019 out 2021
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to
23RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-21234HIGH19 out 2021
Directory Traversal
61RISCO
abrir
Exploit-DB
WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24719webappsphp19 out 2021
Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS)
23RISCO
abrir
Exploit-DB
Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read
CVE-2020-11738HIGHsob ataquewebappsphp18 out 2021
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traver
100RISCO
abrir
GitHub PoC4
xiaojiangxl/CVE-2021-40438
CVE-2021-40438CRITICALsob ataqueransomware18 out 2021
mod_proxy SSRF
100RISCO
abrir
Exploit-DB
Plastic SCM 10.0.16.5622 - WebAdmin Server Access
CVE-2021-41382webappsmultiple18 out 2021
Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
23RISCO
abrir
Exploit-DB
Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure
CVE-2018-16060webappshardware18 out 2021
Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listi
28RISCO
abrir
GitHub PoC1
Lab setup for CVE-2021-41773 (Apache httpd 2.4.49) and CVE-2021-42013 (Apache httpd 2.4.50).
CVE-2021-41773HIGHsob ataqueransomware18 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC17
CVE-2021-36260
CVE-2021-36260CRITICALsob ataque18 out 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
Exploit-DB
Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
CVE-2018-16061webappshardware18 out 2021
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALsob ataque18 out 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
GitHub PoC3
Dahua IPC/VTH/VTO devices auth bypass exploit
CVE-2021-33044CRITICALsob ataque18 out 2021
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISCO
abrir
GitHub PoC1
Exploit For CVE-2019-17662
CVE-2019-1766218 out 2021
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHsob ataqueransomware17 out 2021
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC11
Scanner for CVE-2022-22948 an Information Disclosure in VMWare vCenter
CVE-2022-22948MEDIUMsob ataque17 out 2021
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious act
83RISCO
abrir
GitHub PoC35
Little thing put together quickly to demonstrate this CVE
CVE-2020-11022MEDIUM16 out 2021
jQuery has a potential XSS vulnerability
55RISCO
abrir
GitHub PoC478
Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)
CVE-2021-40449HIGHsob ataqueransomware16 out 2021
Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
TIC4301 Project - CVE-2021-40444
CVE-2021-40444HIGHsob ataqueransomware16 out 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC2
Simple honeypot for CVE-2021-41773 vulnerability
CVE-2021-41773HIGHsob ataqueransomware16 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALsob ataque16 out 2021
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-11022MEDIUM16 out 2021
jQuery has a potential XSS vulnerability
55RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALsob ataque16 out 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-40449HIGHsob ataqueransomware16 out 2021
Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-25078HIGHsob ataque15 out 2021
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware15 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC5
The first vulnerability with the CVE identifier CVE-2021-41773 is a path traversal flaw that exists in Apache HTTP Server 2.4.49.
CVE-2021-41773HIGHsob ataqueransomware15 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
CVE-2020-25078账号密码信息泄露批量脚本Batch script of D-Link DCS series camera account password information disclosure
CVE-2020-25078HIGHsob ataque15 out 2021
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RISCO
abrir
GitHub PoC
metehangenel/MSHTML-CVE-2021-40444
CVE-2021-40444HIGHsob ataqueransomware15 out 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.
CVE-2021-4207115 out 2021
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharac
50RISCO
abrir
Exploit-DB
i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS)
CVE-2021-41878webappsphp15 out 2021
A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enable
38RISCO
abrir
anteriorpágina 645 / 2.597próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.