Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.324exploits catalogados
36.054CVEs com exploração pública
24.695testados em laboratório
78.258 exploits
GitHub PoC8
Test for CVE-2000-0649, and return an IP address if vulnerable
CVE-2000-064911 fev 2021
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALsob ataque10 fev 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
Exploit-DB
Node.JS - 'node-serialize' Remote Code Execution (2)
CVE-2017-5941webappsnodejs10 fev 2021
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISCO
abrir
GitHub PoC40
synacktiv/CVE-2021-1782
CVE-2021-1782HIGHsob ataque10 fev 2021
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-00
71RISCO
abrir
VulnCheck XDB
local
CVE-2021-1782HIGHsob ataque10 fev 2021
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-00
71RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque09 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque09 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
Exploit-DB
Adobe Connect 10 - Username Disclosure
CVE-2023-22232MEDIUMwebappsmultiple09 fev 2021
Adobe Connect Improper Access Control Security feature bypass
70RISCO
abrir
GitHub PoC
보안취약점 확인
CVE-2021-3156HIGHsob ataque09 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC205
CVE-2021-3156非交互式执行命令
CVE-2021-3156HIGHsob ataque09 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC16
sudo heap overflow to LPE, in Go
CVE-2021-3156HIGHsob ataque09 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
Metasploit600
Advantech iView Unauthenticated Remote Code Execution
CVE-2021-2265209 fev 2021
Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow a
30RISCO
abrir
Metasploit600
Micro Focus Operations Bridge Reporter Unauthenticated Command Injection
CVE-2021-22502CRITICALsob ataque09 fev 2021
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The
100RISCO
abrir
Metasploit200
Win32k ConsoleControl Offset Confusion
CVE-2022-21882HIGHsob ataqueransomware09 fev 2021
Win32k Elevation of Privilege Vulnerability
98RISCO
abrir
Metasploit200
Win32k ConsoleControl Offset Confusion
CVE-2021-1732HIGHsob ataqueransomware09 fev 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
Exploit-DB
Alt-N MDaemon webmail 20.0.0 - 'Contact name' Stored Cross Site Scripting (XSS)
CVE-2020-18724webappswindows08 fev 2021
Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19
23RISCO
abrir
Metasploit600
NetMotion Mobility Server MvcUtil Java Deserialization
CVE-2021-2691408 fev 2021
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code
40RISCO
abrir
Exploit-DB
Alt-N MDaemon webmail 20.0.0 - 'file name' Stored Cross Site Scripting (XSS)
CVE-2020-18723webappswindows08 fev 2021
Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code
23RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque08 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC51
CVE-2021-3156: Sudo heap overflow exploit for Debian 10
CVE-2021-3156HIGHsob ataque08 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
Fixed version of the Python script to exploit CVE-2018-19571 and CVE-2018-19585 (GitLab 11.4.7 - Authenticated Remote Code Execution) that is available at https://www.exploit-db.com/exploits/49263 (Python 3.9).
CVE-2018-1957108 fev 2021
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RISCO
abrir
GitHub PoC
Apple Safari Remote Code Execution
CVE-2020-27930HIGHsob ataque07 fev 2021
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, wat
76RISCO
abrir
GitHub PoC10
CVE-2020-7384
CVE-2020-7384HIGH07 fev 2021
Client-Side Command Injection in Rapid7 Metasploit
68RISCO
abrir
GitHub PoC2
Grayhaxor/CVE-2021-21148
CVE-2021-21148HIGHsob ataque07 fev 2021
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap
76RISCO
abrir
Metasploit300
NCR Command Center Agent Remote Code Execution
CVE-2021-312207 fev 2021
CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (wit
40RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque07 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-27930HIGHsob ataque07 fev 2021
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, wat
76RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque06 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC7
1N53C/CVE-2021-3156-PoC
CVE-2021-3156HIGHsob ataque06 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
Custom version of sudo 1.8.3p1 with CVE-2021-3156 patches applied
CVE-2021-3156HIGHsob ataque05 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
anteriorpágina 706 / 2.609próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.