Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
77.900 exploits
GitHub PoC8
CVE-2021-38647 POC for RCE
CVE-2021-38647CRITICALsob ataqueransomware15 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC5
CVE-2021-38647 AKA "OMIGOD" vulnerability in Windows OMI
CVE-2021-38647CRITICALsob ataqueransomware15 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHsob ataqueransomware15 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-33766HIGHsob ataque15 set 2021
Microsoft Exchange Server Information Disclosure Vulnerability
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHsob ataqueransomware14 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
Metasploit600
Microsoft OMI Management Interface Authentication Bypass
CVE-2021-38648HIGHsob ataque14 set 2021
Open Management Infrastructure Elevation of Privilege Vulnerability
91RISCO
abrir
Metasploit600
Microsoft OMI Management Interface Authentication Bypass
CVE-2021-38647CRITICALsob ataqueransomware14 set 2021
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC3
CVE-2018-15473 Exploit
CVE-2018-15473MEDIUM14 set 2021
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC
Malicious document builder for CVE-2021-40444
CVE-2021-40444HIGHsob ataqueransomware14 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC19
k8gege/CVE-2021-40444
CVE-2021-40444HIGHsob ataqueransomware14 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC8
CVE-2021-40875: Tools to Inspect Gurock Testrail Servers for Vulnerabilities related to CVE-2021-40875.
CVE-2021-4087513 set 2021
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat ac
50RISCO
abrir
Exploit-DB
Facebook ParlAI 1.0.0 - Deserialization of Untrusted Data in parlai
CVE-2021-24040localpython13 set 2021
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files c
28RISCO
abrir
VulnCheck XDB
info-leak
CVE-2020-2865313 set 2021
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution v
60RISCO
abrir
GitHub PoC1
POC for CVE-2021-40444
CVE-2021-40444HIGHsob ataqueransomware13 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHsob ataqueransomware13 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHsob ataque12 set 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHsob ataqueransomware12 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHsob ataqueransomware12 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque12 set 2021
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC
W1kyri3/Exploit-PoC-CVE-2021-40444-inject-ma-doc-vao-docx
CVE-2021-40444HIGHsob ataqueransomware12 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC16
Mass exploitation of CVE-2021-24499 unauthenticated upload leading to remote code execution in Workreap theme.
CVE-2021-2449912 set 2021
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISCO
abrir
GitHub PoC1
2021 kernel vulnerability in Ubuntu.
CVE-2021-3493HIGHsob ataque12 set 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
GitHub PoC
CVE-2021-21972 vCenter-6.5-7.0 RCE POC
CVE-2021-21972CRITICALsob ataqueransomware12 set 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC
Reverse engineering the "A Letter Before Court 4.docx" malicious files exploting cve-2021-40444
CVE-2021-40444HIGHsob ataqueransomware12 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC168
This repo contain builders of cab file, html file, and docx file for CVE-2021-40444 exploit
CVE-2021-40444HIGHsob ataqueransomware12 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC4
fengjixuchui/CVE-2021-40444-docx-Generate
CVE-2021-40444HIGHsob ataqueransomware11 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
KnoooW/CVE-2021-40444-docx-Generate
CVE-2021-40444HIGHsob ataqueransomware11 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC11
A malicious .cab creation tool for CVE-2021-40444
CVE-2021-40444HIGHsob ataqueransomware11 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-1960911 set 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISCO
abrir
GitHub PoC
Strapi Remote Code Execution
CVE-2019-1960911 set 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISCO
abrir
anteriorpágina 655 / 2.597próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.