Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
77.900 exploits
GitHub PoC
pisut4152/Sigma-Rule-for-CVE-2021-41773-and-CVE-2021-42013-exploitation-attempt
CVE-2021-41773HIGHsob ataqueransomware08 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2016-9079HIGHsob ataque08 out 2021
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RISCO
abrir
GitHub PoC1
A Zeek package which raises notices for Path Traversal/RCE in Apache HTTP Server 2.4.49 (CVE-2021-41773) and 2.4.50 (CVE-2021-42013)
CVE-2021-41773HIGHsob ataqueransomware08 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC11
Fast python tool to test apache path traversal CVE-2021-41773 in a List of url
CVE-2021-41773HIGHsob ataqueransomware08 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
This is a simple POC for Apache/2.4.49 Path Traversal Vulnerability
CVE-2021-41773HIGHsob ataqueransomware08 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC3
POC
CVE-2021-41773HIGHsob ataqueransomware08 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1938CRITICALsob ataque08 out 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
Exploit-DB
Maian-Cart 3.8 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2021-32172webappsphp08 out 2021
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the
50RISCO
abrir
Exploit-DB
django-unicorn 0.35.3 - Stored Cross-Site Scripting (XSS)
CVE-2021-42053webappspython08 out 2021
The Unicorn framework through 0.35.3 for Django allows XSS via component.name.
23RISCO
abrir
GitHub PoC2
Unrestricted upload of file with dangerous type in Aviatrix allows an authenticated user to execute arbitrary code
CVE-2021-40870CRITICALsob ataque08 out 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware08 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-40870CRITICALsob ataque08 out 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-40870CRITICALsob ataque07 out 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-41773HIGHsob ataqueransomware07 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware07 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-41773HIGHsob ataqueransomware07 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-40870CRITICALsob ataque07 out 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-40870CRITICALsob ataque07 out 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISCO
abrir
GitHub PoC
Unrestricted upload of file with dangerous type in Aviatrix allows an authenticated user to execute arbitrary code
CVE-2021-40870CRITICALsob ataque07 out 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISCO
abrir
GitHub PoC16
Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file which allows an unauthenticated user to execute arbitrary code via directory traversal
CVE-2021-40870CRITICALsob ataque07 out 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISCO
abrir
GitHub PoC3
Aviatrix allows an authenticated user to execute arbitrary code
CVE-2021-40870CRITICALsob ataque07 out 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISCO
abrir
Exploit-DBVexDay Proof
Google SLO-Generator 2.0.0 - Code Execution
CVE-2021-22557MEDIUMlocallinux07 out 2021
Code execution in SLO Generator via YAML Payload
33RISCO
abrir
GitHub PoC9
Exploit with integrated shodan search
CVE-2021-42013CRITICALsob ataqueransomware07 out 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
ES File Explorer v4.1.9.7.4 Open port vulnerability exploit. CVE-2019-6447
CVE-2019-644707 out 2021
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISCO
abrir
GitHub PoC4
CVE-2021-41773: Path Traversal Zero-Day in Apache HTTP Server Exploited
CVE-2021-41773HIGHsob ataqueransomware07 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC2
Apache HTTPd (2.4.49) – Local File Disclosure (LFI)
CVE-2021-41773HIGHsob ataqueransomware07 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC63
A framework for bug hunting or pentesting targeting websites that have CVE-2021-41773 Vulnerability in public
CVE-2021-41773HIGHsob ataqueransomware07 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
CVE-2021-41773, poc, exploit
CVE-2021-41773HIGHsob ataqueransomware07 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
CVE-2021-41773 exploit PoC with Docker setup.
CVE-2021-41773HIGHsob ataqueransomware07 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
Hattan515/POC-CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware07 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
anteriorpágina 648 / 2.597próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.