Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.290exploits catalogados
36.046CVEs com exploração pública
24.695testados em laboratório
78.258 exploits
GitHub PoC1
0xm4ud/Cacti-CVE-2020-8813
CVE-2020-881311 mai 2021
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMsob ataque11 mai 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir
Metasploit500
Linux eBPF ALU32 32-bit Invalid Bounds Tracking LPE
CVE-2021-3490HIGH11 mai 2021
Linux kernel eBPF bitwise ops ALU32 bounds tracking
41RISCO
abrir
Metasploit600
Microsoft SharePoint Unsafe Control and ViewState RCE
CVE-2021-31181HIGH11 mai 2021
Microsoft SharePoint Remote Code Execution Vulnerability
48RISCO
abrir
Metasploit300
Windows IIS HTTP Protocol Stack DOS
CVE-2021-31166CRITICALsob ataque11 mai 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISCO
abrir
Metasploit300
Apache 2.4.49/2.4.50 Traversal RCE scanner
CVE-2021-42013CRITICALsob ataqueransomware10 mai 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
Metasploit600
Apache 2.4.49/2.4.50 Traversal RCE
CVE-2021-41773HIGHsob ataqueransomware10 mai 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
Metasploit600
Apache 2.4.49/2.4.50 Traversal RCE
CVE-2021-42013CRITICALsob ataqueransomware10 mai 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
Metasploit300
Apache 2.4.49/2.4.50 Traversal RCE scanner
CVE-2021-41773HIGHsob ataqueransomware10 mai 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALsob ataque10 mai 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
Exploit-DB
Microweber CMS 1.1.20 - Remote Code Execution (Authenticated)
CVE-2020-28337webappsphp10 mai 2021
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to g
28RISCO
abrir
GitHub PoC3
Check YouTube - https://youtu.be/O0ZnLXRY5Wo
CVE-2020-14882CRITICALsob ataque10 mai 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC6
CVE-2017-7494 python exploit
CVE-2017-7494CRITICALsob ataqueransomware09 mai 2021
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALsob ataque09 mai 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALsob ataqueransomware09 mai 2021
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-949607 mai 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISCO
abrir
GitHub PoC3
CVE-2019-2215
CVE-2019-2215HIGHsob ataque07 mai 2021
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHsob ataque07 mai 2021
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3046107 mai 2021
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISCO
abrir
Exploit-DB
b2evolution 7-2-2 - 'cf_name' SQL Injection
CVE-2021-28242webappsphp06 mai 2021
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive dat
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3046106 mai 2021
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISCO
abrir
GitHub PoC
ajtech-hue/CVE-2021-3156-Mitigation-ShellScript-Build
CVE-2021-3156HIGHsob ataque05 mai 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
VulnCheck XDB
local
CVE-2019-1388HIGHsob ataqueransomware05 mai 2021
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RISCO
abrir
Metasploit600
Cisco HyperFlex HX Data Platform Command Execution
CVE-2021-1497CRITICALsob ataque05 mai 2021
Cisco HyperFlex HX Command Injection Vulnerabilities
100RISCO
abrir
Metasploit600
Cisco HyperFlex HX Data Platform Command Execution
CVE-2021-1498CRITICALsob ataque05 mai 2021
Cisco HyperFlex HX Command Injection Vulnerabilities
100RISCO
abrir
Metasploit600
Cisco HyperFlex HX Data Platform unauthenticated file upload to RCE (CVE-2021-1499)
CVE-2021-1499MEDIUM05 mai 2021
Cisco HyperFlex HX Data Platform File Upload Vulnerability
50RISCO
abrir
GitHub PoC
cve-2019-8942, cve-2019-8943
CVE-2019-894205 mai 2021
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISCO
abrir
GitHub PoC
exploit
CVE-2019-1863405 mai 2021
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir
GitHub PoC20
CVE-2019-1388 Abuse UAC Windows Certificate Dialog
CVE-2019-1388HIGHsob ataqueransomware05 mai 2021
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RISCO
abrir
GitHub PoC6
Atlassian Jira unauthen template injection
CVE-2019-11581CRITICALsob ataque04 mai 2021
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RISCO
abrir
anteriorpágina 688 / 2.609próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.