Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.056exploits catalogados
35.925CVEs com exploração pública
24.695testados em laboratório
77.900 exploits
GitHub PoC4
alikarimi999/CVE-2021-21315
CVE-2021-21315HIGHsob ataque07 set 2021
Command Injection Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALsob ataqueransomware07 set 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-21315HIGHsob ataque07 set 2021
Command Injection Vulnerability
100RISCO
abrir
GitHub PoC1
A quick and dirty PoC of cve-2021-26084 as none of the existing ones worked for me.
CVE-2021-26084CRITICALsob ataqueransomware07 set 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
Exploit-DB
FlatCore CMS 2.0.7 - Remote Code Execution (RCE) (Authenticated)
CVE-2021-39608webappsphp06 set 2021
Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a rem
35RISCO
abrir
GitHub PoC5
A vulnerability can allow an attacker to guess the automatically generated development mode secret token.
CVE-2019-542006 set 2021
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir
Exploit-DB
OpenEMR 6.0.0 - 'noteid' Insecure Direct Object Reference (IDOR)
CVE-2021-40352webappsphp06 set 2021
OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can re
23RISCO
abrir
Metasploit300
Netgear PNPX_GetShareFolderList Authentication Bypass
CVE-2021-45511MEDIUM06 set 2021
Certain NETGEAR devices are affected by authentication bypass. This affects AC2100 before 2021-08-27, AC2400 before 2021
33RISCO
abrir
Metasploit300
WordPress Plugin Automatic Config Change to RCE
CVE-2021-4374CRITICAL06 set 2021
WordPress Automatic Plugin <= 3.53.2 - Unauthenticated Arbitrary Options Update
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALsob ataqueransomware05 set 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC
Confluence OGNL Injection [CVE-2021-26084].
CVE-2021-26086MEDIUMsob ataque05 set 2021
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RISCO
abrir
GitHub PoC2
CVE-2021-34646 PoC
CVE-2021-34646CRITICAL04 set 2021
Booster for WooCommerce <= 5.4.3 Authentication Bypass
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALsob ataqueransomware04 set 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC42
A Python replicated exploit for Webmin 1.580 /file/show.cgi Remote Code Execution
CVE-2012-298204 set 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALsob ataqueransomware04 set 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-34523CRITICALsob ataqueransomware04 set 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC120
Proof of Concept for CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207
CVE-2021-34473CRITICALsob ataqueransomware04 set 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
Wordpress Plainview Activity Monitor Plugin RCE (20161228)
CVE-2018-1587704 set 2021
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RISCO
abrir
GitHub PoC
BabyTeam1024/cve-2018-2628
CVE-2018-2628CRITICALsob ataque04 set 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir
GitHub PoC2
Anonimo501/SMBGhost_CVE-2020-0796_checker
CVE-2020-0796CRITICALsob ataqueransomware04 set 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-31207MEDIUMsob ataqueransomware04 set 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISCO
abrir
GitHub PoC
Setting up POC for CVE-2021-26084
CVE-2021-26084CRITICALsob ataqueransomware04 set 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC
CVE-2021-26084
CVE-2021-26084CRITICALsob ataqueransomware03 set 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC
cve-2021-26084 EXP
CVE-2021-26084CRITICALsob ataqueransomware03 set 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC4
Exploitation of a vulnerability in Cisco's node-jose, a JavaScript library created to manage JWT.
CVE-2018-011403 set 2021
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALsob ataqueransomware03 set 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC3
CVE-2021-26084 Confluence OGNL injection
CVE-2021-26084CRITICALsob ataqueransomware03 set 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC32
Dell Driver EoP (CVE-2021-21551)
CVE-2021-21551HIGHsob ataque03 set 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISCO
abrir
VulnCheck XDB
local
CVE-2021-22555HIGHsob ataque03 set 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-21551HIGHsob ataque03 set 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISCO
abrir
anteriorpágina 657 / 2.597próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.