Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.258exploits catalogados
36.019CVEs com exploração pública
24.695testados em laboratório
78.254 exploits
VulnCheck XDB
local
CVE-2021-21551HIGHsob ataque02 jun 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISCO
abrir
GitHub PoC3
Wordpress XXE injection 구축 자동화 및 PoC
CVE-2021-29447HIGH01 jun 2021
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC2
CVE-2021-21985 Checker.
CVE-2021-21985CRITICALsob ataqueransomware01 jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISCO
abrir
GitHub PoC
This script check the CVE-2021-21985 vulnerability and patch on vCenter Server.
CVE-2021-21985CRITICALsob ataqueransomware01 jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-21985CRITICALsob ataqueransomware01 jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-21985CRITICALsob ataqueransomware01 jun 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISCO
abrir
Exploit-DB
LogonTracer 1.2.0 - Remote Code Execution (Unauthenticated)
CVE-2018-16167webappsmultiple01 jun 2021
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
60RISCO
abrir
GitHub PoC
rnnsz/CVE-2017-15950
CVE-2017-1595031 mai 2021
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary co
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHsob ataqueransomware31 mai 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-21389HIGH31 mai 2021
BuddyPress privilege escalation via REST API
61RISCO
abrir
GitHub PoC3
python3 POC for CVE-2019-2729 WebLogic Deserialization Vulnerability and CVE-2017-10271 amongst others
CVE-2017-10271HIGHsob ataqueransomware31 mai 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC226
PoC for CVE-2021-28476 a guest-to-host "Hyper-V Remote Code Execution Vulnerability" in vmswitch.sys.
CVE-2021-28476CRITICAL31 mai 2021
Windows Hyper-V Remote Code Execution Vulnerability
60RISCO
abrir
GitHub PoC
rnnsz/CVE-2008-4654
CVE-2008-465431 mai 2021
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RISCO
abrir
GitHub PoC3
python3 POC for CVE-2019-2729 WebLogic Deserialization Vulnerability and CVE-2017-10271 amongst others
CVE-2019-2729CRITICAL31 mai 2021
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISCO
abrir
GitHub PoC59
arbitrary kernel read/write in dbutil_2_3.sys, Proof of Concept Local Privilege Escalation to nt authority/system
CVE-2021-21551HIGHsob ataque30 mai 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISCO
abrir
GitHub PoC
JBoss CVE-2017-12149 (Insecure Deserialization - RCE) Exploitation Lab.
CVE-2017-12149CRITICALsob ataqueransomware30 mai 2021
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-21985CRITICALsob ataqueransomware29 mai 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISCO
abrir
GitHub PoC213
alt3kx/CVE-2021-21985_PoC
CVE-2021-21985CRITICALsob ataqueransomware29 mai 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISCO
abrir
GitHub PoC1
Script to patch your domain computers about the CVE-2021-21551. Privesc on machines that have the driver dbutil_2_3.sys, installed by some DELL tools (BIOS updater, SupportAssist...)
CVE-2021-21551HIGHsob ataque28 mai 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISCO
abrir
Exploit-DB
WordPress Plugin LifterLMS 4.21.0 - Stored Cross-Site Scripting (XSS)
CVE-2021-24308webappsphp28 mai 2021
LifterLMS < 4.21.1 - Authenticated Stored XSS in Edit Profile
23RISCO
abrir
GitHub PoC3
My notes for CVE-2004-1561 IceCast exploitation
CVE-2004-156128 mai 2021
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISCO
abrir
Exploit-DB
Trixbox 2.8.0.4 - 'lang' Path Traversal
CVE-2017-14537webappsphp28 mai 2021
trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter
50RISCO
abrir
GitHub PoC1
Cacti v1.2.8 Unauthenticated Remote Code Execution
CVE-2020-881328 mai 2021
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-881328 mai 2021
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISCO
abrir
Exploit-DBVexDay Proof
PHPFusion 9.03.50 - Remote Code Execution
CVE-2020-24949webappsphp28 mai 2021
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr
50RISCO
abrir
Exploit-DB
Trixbox 2.8.0.4 - 'lang' Remote Code Execution (Unauthenticated)
CVE-2017-14535webappsphp28 mai 2021
trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php
50RISCO
abrir
GitHub PoC
Proof of Concept for CVE-2020-14295.
CVE-2020-1429528 mai 2021
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RISCO
abrir
Metasploit300
Squid Proxy Range Header DoS
CVE-2021-3180727 mai 2021
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to
23RISCO
abrir
Metasploit300
Squid Proxy Range Header DoS
CVE-2021-3180627 mai 2021
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a
40RISCO
abrir
GitHub PoC
Detect vulns liferay CVE-2020-7961 by Nattroc (EOG Team)
CVE-2020-7961CRITICALsob ataque27 mai 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir
anteriorpágina 684 / 2.609próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.