Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.183exploits catalogados
37.028CVEs com exploração pública
24.695testados em laboratório
8.970 exploits
VulnCheck XDB
client-side
CVE-2017-8759HIGHsob ataque21 dez 2023
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware21 dez 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHsob ataqueransomware21 dez 2023
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-15961CRITICALsob ataque21 dez 2023
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALsob ataque21 dez 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALsob ataque21 dez 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
VulnCheck XDB
local
CVE-2018-0802HIGHsob ataqueransomware21 dez 2023
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALsob ataqueransomware21 dez 2023
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-21985CRITICALsob ataqueransomware21 dez 2023
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-9276HIGHsob ataque21 dez 2023
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2022-22536CRITICALsob ataque21 dez 2023
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3172821 dez 2023
Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 allows a non-privileged process to
23RISCO
abrir
VulnCheck XDB
local
CVE-2019-573621 dez 2023
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware21 dez 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-26855CRITICALsob ataqueransomware21 dez 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-21661HIGH21 dez 2023
SQL injection in WordPress
78RISCO
abrir
VulnCheck XDB
local
CVE-2020-0796CRITICALsob ataqueransomware21 dez 2023
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALsob ataqueransomware21 dez 2023
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALsob ataqueransomware21 dez 2023
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHsob ataqueransomware21 dez 2023
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHsob ataqueransomware21 dez 2023
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALsob ataque21 dez 2023
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware21 dez 2023
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware21 dez 2023
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2012-486921 dez 2023
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attacke
60RISCO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHsob ataque21 dez 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-10148CRITICALsob ataque21 dez 2023
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALsob ataqueransomware21 dez 2023
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque21 dez 2023
Grafana path traversal
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALsob ataque21 dez 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISCO
abrir
anteriorpágina 164 / 299próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.