Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
77.900 exploits
GitHub PoC10
C# PrintNightmare (CVE-2021-1675)
CVE-2021-1675HIGHsob ataqueransomware26 set 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC209
Python implementation for PrintNightmare (CVE-2021-1675 / CVE-2021-34527)
CVE-2021-1675HIGHsob ataqueransomware26 set 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
AmesianX/CVE-2021-21220
CVE-2021-21220HIGHsob ataque26 set 2021
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
98RISCO
abrir
GitHub PoC1
Python script to obtain RCE on Mantis Bug Tracker prior to version 1.2.x Check CVE-2008-4687 for additional information
CVE-2008-468725 set 2021
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-22005CRITICALsob ataqueransomware25 set 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
GitHub PoC17
CVE-2021-3156 - sudo exploit for ubuntu 18.04 & 20.04
CVE-2021-3156HIGHsob ataque25 set 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC13
CVE-2021-22005批量验证python脚本
CVE-2021-22005CRITICALsob ataqueransomware25 set 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
GitHub PoC
CVE-2021-22005
CVE-2021-22005CRITICALsob ataqueransomware24 set 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
GitHub PoC1
CVE-2021-38647 is an unauthenticated RCE vulnerability effecting the OMI agent as root.
CVE-2021-38647CRITICALsob ataqueransomware24 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALsob ataqueransomware24 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
Windows Kernel Registry Elevation of Privilege Vulnerability
CVE-2018-841024 set 2021
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory
23RISCO
abrir
GitHub PoC1
BeneficialCode/CVE-2021-1732
CVE-2021-1732HIGHsob ataqueransomware24 set 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
CVE 2021 40444 Windows Exploit services.dll
CVE-2021-40444HIGHsob ataqueransomware24 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC5
CVE-2021-33739 PoC Analysis
CVE-2021-33739HIGHsob ataque24 set 2021
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHsob ataqueransomware24 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-33739HIGHsob ataque24 set 2021
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC1
pisut4152/Sigma-Rule-for-CVE-2021-22005-scanning-activity
CVE-2021-22005CRITICALsob ataqueransomware23 set 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
GitHub PoC8
1ZRR4H/CVE-2021-22005
CVE-2021-22005CRITICALsob ataqueransomware23 set 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
Exploit-DB
WordPress Plugin Fitness Calculators 1.9.5 - Cross-Site Request Forgery (CSRF)
CVE-2021-24272webappsphp23 set 2021
Fitness Calculators < 1.9.6 - Cross-Site Request Forgery to Cross-Site Scripting (XSS)
23RISCO
abrir
Metasploit600
Microsoft Office Word Malicious MSHTML RCE
CVE-2021-40444HIGHsob ataqueransomware23 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
Exploit-DB
Gurock Testrail 7.2.0.3014 - 'files.md5' Improper Access Control
CVE-2021-40875webappsmultiple23 set 2021
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat ac
50RISCO
abrir
Exploit-DB
WordPress Plugin Advanced Order Export For WooCommerce 3.1.7 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24169webappsphp23 set 2021
Advanced Order Export For WooCommerce < 3.1.8 - Reflected Cross-Site Scripting (XSS)
43RISCO
abrir
Exploit-DB
OpenCats 0.9.4-2 - 'docx ' XML External Entity Injection (XXE)
CVE-2019-13358webappsphp22 set 2021
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying opera
28RISCO
abrir
Exploit-DB
Cloudron 6.2 - 'returnTo ' Cross Site Scripting (Reflected)
CVE-2021-40868webappsmultiple22 set 2021
In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
38RISCO
abrir
GitHub PoC
https://github.com/corelight/CVE-2021-38647 without the bloat
CVE-2021-38647CRITICALsob ataqueransomware22 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
Metasploit0
VMware vCenter vScalation Priv Esc
CVE-2021-2201521 set 2021
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and
18RISCO
abrir
Metasploit600
VMware vCenter Server Analytics (CEIP) Service File Upload
CVE-2021-22005CRITICALsob ataqueransomware21 set 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-30632HIGHsob ataque20 set 2021
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISCO
abrir
GitHub PoC68
CVE-2021-38647 - POC to exploit unauthenticated RCE #OMIGOD
CVE-2021-38647CRITICALsob ataqueransomware20 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALsob ataqueransomware20 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
anteriorpágina 653 / 2.597próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.