Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
78.794 exploits
GitHub PoC
F5 BIG-IP/BIG-IQ iControl Rest API SSRF to RCE
CVE-2021-22986CRITICALsob ataqueransomware22 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
Exploit-DB
MyBB 1.8.25 - Chained Remote Command Execution
CVE-2021-27890webappsphp22 mar 2021
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
28RISCO
abrir
GitHub PoC
Bypass bludit mitigation login form and upload malicious to call a rev shell
CVE-2019-17240LOW22 mar 2021
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISCO
abrir
Exploit-DB
MyBB 1.8.25 - Chained Remote Command Execution
CVE-2021-27889webappsphp22 mar 2021
Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALsob ataqueransomware22 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
GitHub PoC18
EEsshq/CVE-2017-0144---EtneralBlue-MS17-010-Remote-Code-Execution
CVE-2017-0144HIGHsob ataqueransomware22 mar 2021
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Exploit-DB
WordPress Plugin Delightful Downloads Jquery File Tree 1.6.6 - Path Traversal
CVE-2017-1000170webappsphp22 mar 2021
jqueryFileTree 2.1.5 and older Directory Traversal
50RISCO
abrir
GitHub PoC
kiri-48/CVE-2021-22986
CVE-2021-22986CRITICALsob ataqueransomware22 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
GitHub PoC91
CVE-2021-22986 & F5 BIG-IP RCE
CVE-2021-22986CRITICALsob ataqueransomware22 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
Metasploit600
Apache OFBiz SOAP Java Deserialization
CVE-2021-2629522 mar 2021
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
60RISCO
abrir
GitHub PoC4
CVE-2021-22986 F5 BIG-IP iControl 命令执行漏洞
CVE-2021-22986CRITICALsob ataqueransomware21 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALsob ataqueransomware21 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-26855CRITICALsob ataqueransomware21 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Microsoft Exchange Proxylogon Exploit Chain EXP分析
CVE-2021-26855CRITICALsob ataqueransomware21 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
A vulnerability scanner that detects CVE-2021-22986 vulnerabilities.
CVE-2021-22986CRITICALsob ataqueransomware20 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
GitHub PoC1
Exploiting CVE-2016-2555 enumerating and dumping the underlying Database.
CVE-2016-255520 mar 2021
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RISCO
abrir
GitHub PoC4
Jquery File Tree 1.6.6 Path Traversal exploit (CVE-2017-1000170)
CVE-2017-100017019 mar 2021
jqueryFileTree 2.1.5 and older Directory Traversal
50RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALsob ataqueransomware19 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
GitHub PoC4
Exploit generator for sudo CVE-2021-3156
CVE-2021-3156HIGHsob ataque19 mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
Exploit-DB
LiveZilla Server 8.0.1.0 - 'Accept-Language' Reflected XSS
CVE-2019-12962webappsphp19 mar 2021
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.
38RISCO
abrir
GitHub PoC3
Zoho ManageEngine ServiceDesk Plus MSP - Active Directory User Enumeration (CVE-2021-31159) - https://ricardojoserf.github.io/CVE-2021-31159/
CVE-2021-3115919 mar 2021
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-messag
28RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque19 mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque19 mar 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC28
Whatsapp remote code execution CVE-2019-11932 https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/
CVE-2019-1193219 mar 2021
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALsob ataqueransomware19 mar 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2017-100017019 mar 2021
jqueryFileTree 2.1.5 and older Directory Traversal
50RISCO
abrir
GitHub PoC26
cve-2021-22986 f5 rce 漏洞批量检测 poc
CVE-2021-22986CRITICALsob ataqueransomware19 mar 2021
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
GitHub PoC1
PoC Python script as an exercice from tryhackme.
CVE-2012-298218 mar 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALsob ataqueransomware18 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
CVE-2019-20361HIGH18 mar 2021
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b
78RISCO
abrir
anteriorpágina 715 / 2.627próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.