Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.295exploits catalogados
36.048CVEs com exploração pública
24.695testados em laboratório
78.258 exploits
GitHub PoC225
CVE-2021-3156 - Sudo Baron Samedit
CVE-2021-3156HIGHsob ataque29 abr 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
Exploit-DB
Cacti 1.2.12 - 'filter' SQL Injection
CVE-2020-14295webappsphp29 abr 2021
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RISCO
abrir
GitHub PoC1
PoC for CVE-2018-13382, never successfully tested so swim at your own risk
CVE-2018-13382CRITICALsob ataqueransomware28 abr 2021
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISCO
abrir
Exploit-DB
Kirby CMS 3.5.3.1 - 'file' Cross-Site Scripting (XSS)
CVE-2021-29460HIGHwebappsphp28 abr 2021
Cross-site scripting (XSS) from unsanitized uploaded SVG files
41RISCO
abrir
GitHub PoC2
Authenticated SQL injection to command execution on Cacti 1.2.12
CVE-2020-1429528 abr 2021
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-2093328 abr 2021
InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.
50RISCO
abrir
Metasploit400
SuiteCRM Log File Remote Code Execution
CVE-2021-4284028 abr 2021
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumsta
50RISCO
abrir
Metasploit400
SuiteCRM Log File Remote Code Execution
CVE-2020-2832828 abr 2021
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain
50RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-13382CRITICALsob ataqueransomware28 abr 2021
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-895827 abr 2021
Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow
35RISCO
abrir
GitHub PoC10
lsw29475/CVE-2018-8611
CVE-2018-8611HIGHsob ataque27 abr 2021
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
71RISCO
abrir
VulnCheck XDB
local
CVE-2018-8611HIGHsob ataque27 abr 2021
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-1272527 abr 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir
GitHub PoC1
streghstreek/CVE-2020-1938
CVE-2020-1938CRITICALsob ataque27 abr 2021
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC1
CVE-2019-12725 ZeroShell 远程命令执行漏洞
CVE-2019-1272527 abr 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-1389HIGHsob ataque26 abr 2021
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RISCO
abrir
Metasploit600
Git LFS Clone Command Exec
CVE-2021-21300HIGH26 abr 2021
malicious repositories can execute remote code while cloning
58RISCO
abrir
Exploit-DB
SEO Panel 4.8.0 - 'order_col' Blind SQL Injection (2)
CVE-2021-28419webappsphp26 abr 2021
The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads
28RISCO
abrir
GitHub PoC31
Read my blog for more info -
CVE-2021-1732HIGHsob ataqueransomware25 abr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
edsonjt81/sudo-cve-2019-18634
CVE-2019-1863425 abr 2021
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir
GitHub PoC
edsonjt81/CVE-2019-14287-
CVE-2019-1428725 abr 2021
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
VulnCheck XDB
local
CVE-2021-1732HIGHsob ataqueransomware25 abr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC1
rebuild cve
CVE-2021-329125 abr 2021
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod
28RISCO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHsob ataque25 abr 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
GitHub PoC2
b1tg/CVE-2018-6065-exploit
CVE-2018-6065HIGHsob ataque24 abr 2021
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-6065HIGHsob ataque24 abr 2021
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RISCO
abrir
VulnCheck XDB
local
CVE-2021-1732HIGHsob ataqueransomware23 abr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
Exploit-DB
DzzOffice 2.02.1 - 'Multiple' Cross-Site Scripting (XSS)
CVE-2021-3318webappsmultiple23 abr 2021
attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.
23RISCO
abrir
GitHub PoC66
CVE-2021-1732 poc & exp; tested on 20H2
CVE-2021-1732HIGHsob ataqueransomware23 abr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
itssmikefm/CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware22 abr 2021
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
anteriorpágina 690 / 2.609próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.