Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.258exploits catalogados
36.019CVEs com exploração pública
24.695testados em laboratório
78.214 exploits
VulnCheck XDB
initial-access
CVE-2017-10271HIGHsob ataqueransomware31 mai 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC
rnnsz/CVE-2017-15950
CVE-2017-1595031 mai 2021
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary co
23RISCO
abrir
GitHub PoC
rnnsz/CVE-2008-4654
CVE-2008-465431 mai 2021
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RISCO
abrir
GitHub PoC3
python3 POC for CVE-2019-2729 WebLogic Deserialization Vulnerability and CVE-2017-10271 amongst others
CVE-2017-10271HIGHsob ataqueransomware31 mai 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC59
arbitrary kernel read/write in dbutil_2_3.sys, Proof of Concept Local Privilege Escalation to nt authority/system
CVE-2021-21551HIGHsob ataque30 mai 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISCO
abrir
GitHub PoC
JBoss CVE-2017-12149 (Insecure Deserialization - RCE) Exploitation Lab.
CVE-2017-12149CRITICALsob ataqueransomware30 mai 2021
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir
GitHub PoC213
alt3kx/CVE-2021-21985_PoC
CVE-2021-21985CRITICALsob ataqueransomware29 mai 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-21985CRITICALsob ataqueransomware29 mai 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-881328 mai 2021
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISCO
abrir
Exploit-DB
Trixbox 2.8.0.4 - 'lang' Path Traversal
CVE-2017-14537webappsphp28 mai 2021
trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter
50RISCO
abrir
Exploit-DB
Trixbox 2.8.0.4 - 'lang' Remote Code Execution (Unauthenticated)
CVE-2017-14535webappsphp28 mai 2021
trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php
50RISCO
abrir
GitHub PoC
Proof of Concept for CVE-2020-14295.
CVE-2020-1429528 mai 2021
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RISCO
abrir
Exploit-DB
WordPress Plugin LifterLMS 4.21.0 - Stored Cross-Site Scripting (XSS)
CVE-2021-24308webappsphp28 mai 2021
LifterLMS < 4.21.1 - Authenticated Stored XSS in Edit Profile
23RISCO
abrir
Exploit-DBVexDay Proof
PHPFusion 9.03.50 - Remote Code Execution
CVE-2020-24949webappsphp28 mai 2021
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr
50RISCO
abrir
GitHub PoC1
Script to patch your domain computers about the CVE-2021-21551. Privesc on machines that have the driver dbutil_2_3.sys, installed by some DELL tools (BIOS updater, SupportAssist...)
CVE-2021-21551HIGHsob ataque28 mai 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISCO
abrir
GitHub PoC3
My notes for CVE-2004-1561 IceCast exploitation
CVE-2004-156128 mai 2021
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISCO
abrir
GitHub PoC1
Cacti v1.2.8 Unauthenticated Remote Code Execution
CVE-2020-881328 mai 2021
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISCO
abrir
Metasploit300
Squid Proxy Range Header DoS
CVE-2021-3180727 mai 2021
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to
23RISCO
abrir
GitHub PoC
Detect vulns liferay CVE-2020-7961 by Nattroc (EOG Team)
CVE-2020-7961CRITICALsob ataque27 mai 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir
Metasploit300
Squid Proxy Range Header DoS
CVE-2021-3180627 mai 2021
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a
40RISCO
abrir
GitHub PoC1
Multiple vulnerabilities in the vSphere Client (HTML5) were privately reported to VMware. Updates and workarounds are available to address these vulnerabilities in affected VMware products.
CVE-2021-21985CRITICALsob ataqueransomware27 mai 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3356427 mai 2021
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write
60RISCO
abrir
GitHub PoC
ykg88/OHTS_IE6052-CVE-2020-17087
CVE-2020-17087HIGHsob ataque27 mai 2021
Windows Kernel Local Elevation of Privilege Vulnerability
71RISCO
abrir
Exploit-DB
Codiad 2.8.4 - Remote Code Execution (Authenticated) (3)
CVE-2018-19423webappsmultiple26 mai 2021
Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.
28RISCO
abrir
Exploit-DBVexDay Proof
ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution (2)
CVE-2015-3306remotelinux26 mai 2021
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir
GitHub PoC
POC-CVE-2020-7961-Token-iterate
CVE-2020-7961CRITICALsob ataque26 mai 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir
Exploit-DBVexDay Proof
Pluck CMS 4.7.13 - File Upload Remote Code Execution (Authenticated)
CVE-2020-29607webappsphp26 mai 2021
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-3355825 mai 2021
Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, previe
43RISCO
abrir
GitHub PoC
DarkFlameMaster-bit/CVE-2018-8174_EXP
CVE-2018-8174HIGHsob ataqueransomware25 mai 2021
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3356425 mai 2021
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write
60RISCO
abrir
anteriorpágina 683 / 2.608próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.