Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
77.900 exploits
VulnCheck XDB
client-side
CVE-2021-30632HIGHsob ataque20 set 2021
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISCO
abrir
GitHub PoC102
Modified code so that we don´t need to rely on CAB archives
CVE-2021-40444HIGHsob ataqueransomware19 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2015-5119HIGHsob ataque19 set 2021
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2015-5122HIGHsob ataque19 set 2021
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RISCO
abrir
GitHub PoC1
Converted Metasploit exploits for Adobe Flash vulnerabilities CVE-2015-3090, CVE-2015-3105, CVE-2015-5119, and CVE-2015-5122 to a Python3 script.
CVE-2015-309019 set 2021
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALsob ataqueransomware19 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Modifed ver of the original exploit to save some times on password reseting for unprivileged user
CVE-2021-2291119 set 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISCO
abrir
GitHub PoC3
OMIGod / CVE-2021-38647 POC and Demo environment
CVE-2021-38647CRITICALsob ataqueransomware19 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC11
Scan for evidence of CVE-2021-30860 (FORCEDENTRY) exploit
CVE-2021-30860HIGHsob ataque18 set 2021
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catali
93RISCO
abrir
GitHub PoC3
[CVE-2021-26084] Confluence pre-auth RCE test script
CVE-2021-26084CRITICALsob ataqueransomware18 set 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC1
A Vagrant VM test lab to learn about CVE-2021-38647 in the Open Management Infrastructure agent (aka "omigod").
CVE-2021-38647CRITICALsob ataqueransomware18 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
Metasploit600
Hikvision IP Camera Unauthenticated Command Injection
CVE-2021-36260CRITICALsob ataque18 set 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALsob ataqueransomware18 set 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALsob ataqueransomware18 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALsob ataqueransomware17 set 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC2
CVE-2021-40539 POC
CVE-2021-40539CRITICALsob ataqueransomware17 set 2021
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISCO
abrir
Metasploit300
Wordpress BulletProof Security Backup Disclosure
CVE-2021-39327MEDIUM17 set 2021
BulletProof Security <= 5.1 Sensitive Information Disclosure
70RISCO
abrir
Exploit-DB
WordPress Plugin WooCommerce Booster Plugin 5.4.3 - Authentication Bypass
CVE-2021-34646CRITICALwebappsphp17 set 2021
Booster for WooCommerce <= 5.4.3 Authentication Bypass
60RISCO
abrir
Metasploit600
ManageEngine ServiceDesk Plus CVE-2021-44077
CVE-2021-44077CRITICALsob ataque16 set 2021
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RISCO
abrir
GitHub PoC233
Proof on Concept Exploit for CVE-2021-38647 (OMIGOD)
CVE-2021-38647CRITICALsob ataqueransomware16 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC2
A PoC exploit for CVE-2021-38647 RCE in OMI
CVE-2021-38647CRITICALsob ataqueransomware16 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC20
OMIGOD! OM I GOOD? A free scanner to detect VMs vulnerable to one of the "OMIGOD" vulnerabilities discovered by Wiz's threat research team, specifically CVE-2021-38647.
CVE-2021-38647CRITICALsob ataqueransomware16 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-38647CRITICALsob ataqueransomware16 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-38647CRITICALsob ataqueransomware16 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC6
CVE-2021-2456
CVE-2021-2456CRITICAL16 set 2021
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana
70RISCO
abrir
GitHub PoC9
quynhle7821/CVE-2021-2302
CVE-2021-2302CRITICAL16 set 2021
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported
48RISCO
abrir
GitHub PoC824
CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit
CVE-2021-40444HIGHsob ataqueransomware15 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHsob ataqueransomware15 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC10
CVE-2021-33766-poc
CVE-2021-33766HIGHsob ataque15 set 2021
Microsoft Exchange Server Information Disclosure Vulnerability
100RISCO
abrir
GitHub PoC8
CVE-2021-38647 POC for RCE
CVE-2021-38647CRITICALsob ataqueransomware15 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
anteriorpágina 654 / 2.597próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.