Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.324exploits catalogados
36.054CVEs com exploração pública
24.695testados em laboratório
78.258 exploits
Exploit-DB
DMA Radius Manager 4.4.0 - Cross-Site Request Forgery (CSRF)
CVE-2021-30147webappsmultiple08 abr 2021
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
23RISCO
abrir
GitHub PoC
Buffer Overflow in Seattle Lab Mail (SLmail) 5.5 - POP3
CVE-2003-026408 abr 2021
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISCO
abrir
Exploit-DB
Composr 10.0.36 - Remote Code Execution
CVE-2021-30149webappsphp08 abr 2021
Composr 10.0.36 allows upload and execution of PHP files.
28RISCO
abrir
Exploit-DB
Composr CMS 10.0.36 - Cross Site Scripting
CVE-2021-30150webappsphp07 abr 2021
Composr 10.0.36 allows XSS in an XML script.
23RISCO
abrir
GitHub PoC
CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
CVE-2016-209807 abr 2021
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISCO
abrir
Metasploit600
Cisco Small Business RV Series Authentication Bypass and Command Injection
CVE-2021-1473MEDIUM07 abr 2021
Cisco Small Business RV Series Routers Vulnerabilities
40RISCO
abrir
Exploit-DB
Dell OpenManage Server Administrator 9.4.0.0 - Arbitrary File Read
CVE-2020-5377CRITICALwebappswindows07 abr 2021
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
60RISCO
abrir
Metasploit600
Cisco Small Business RV Series Authentication Bypass and Command Injection
CVE-2021-1472MEDIUM07 abr 2021
Cisco Small Business RV Series Routers Vulnerabilities
50RISCO
abrir
Exploit-DB
Atlassian Jira Service Desk 4.9.1 - Unrestricted File Upload to XSS
CVE-2020-14166webappsmultiple07 abr 2021
The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remo
23RISCO
abrir
Metasploit600
Microsoft Exchange ProxyShell RCE
CVE-2021-34473CRITICALsob ataqueransomware06 abr 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-19781CRITICALsob ataqueransomware06 abr 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALsob ataqueransomware06 abr 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-21975HIGHsob ataqueransomware06 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware06 abr 2021
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
Metasploit600
Microsoft Exchange ProxyShell RCE
CVE-2021-34523CRITICALsob ataqueransomware06 abr 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
Exploit for CVE-2012-2982
CVE-2012-298206 abr 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir
Metasploit600
Microsoft Exchange ProxyShell RCE
CVE-2021-31207MEDIUMsob ataqueransomware06 abr 2021
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISCO
abrir
GitHub PoC6
[CVE-2021-21972] VMware vSphere Client Unauthorized File Upload to Remote Code Execution (RCE)
CVE-2021-21972CRITICALsob ataqueransomware06 abr 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
Exploit-DB
Google Chrome 81.0.4044 V8 - Remote Code Execution
CVE-2020-6507remotemultiple06 abr 2021
Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap
28RISCO
abrir
GitHub PoC
pwn3z/CVE-2019-19781-Citrix
CVE-2019-19781CRITICALsob ataqueransomware06 abr 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC37
vRealize RCE + Privesc (CVE-2021-21975, CVE-2021-21983, CVE-0DAY-?????)
CVE-2021-21975HIGHsob ataqueransomware06 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
Exploit-DB
Google Chrome 86.0.4240 V8 - Remote Code Execution
CVE-2020-16040remotemultiple06 abr 2021
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RISCO
abrir
GitHub PoC1
Exploit Code for CVE-2020-1472 aka Zerologon
CVE-2020-1472MEDIUMsob ataqueransomware06 abr 2021
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
capturingcats/CVE-2021-3156
CVE-2021-3156HIGHsob ataque05 abr 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque05 abr 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC3
Exploiting CVE-2014-7205 by injecting arbitrary JavaScript resulting in Remote Code Execution.
CVE-2014-720505 abr 2021
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t
60RISCO
abrir
GitHub PoC
delina1/CVE-2018-8174
CVE-2018-8174HIGHsob ataqueransomware05 abr 2021
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
GitHub PoC
delina1/CVE-2018-8174_EXP
CVE-2018-8174HIGHsob ataqueransomware05 abr 2021
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
GitHub PoC1
CVE-2017-9805-Exploit
CVE-2017-9805HIGHsob ataque04 abr 2021
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC1
CVE-2017-9805-Exploit
CVE-2017-9805HIGHsob ataque04 abr 2021
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
anteriorpágina 694 / 2.609próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.