Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
8.213 exploits
VulnCheck XDB
initial-access
CVE-2020-949607 mai 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3046106 mai 2021
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISCO
abrir
VulnCheck XDB
local
CVE-2019-1388HIGHsob ataqueransomware05 mai 2021
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-11581CRITICALsob ataque04 mai 2021
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-28482HIGH03 mai 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
63RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2015-856203 mai 2021
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISCO
abrir
VulnCheck XDB
local
CVE-2021-1732HIGHsob ataqueransomware02 mai 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-17463HIGHsob ataque02 mai 2021
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHsob ataque02 mai 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-6340HIGHsob ataque01 mai 2021
Drupal core - Highly critical - Remote Code Execution
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALsob ataqueransomware01 mai 2021
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-949630 abr 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-4878HIGHsob ataqueransomware30 abr 2021
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3012829 abr 2021
Unsafe deserialization in Apache OFBiz
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-15982HIGHsob ataqueransomware29 abr 2021
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-2093328 abr 2021
InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.
50RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-13382CRITICALsob ataqueransomware28 abr 2021
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-895827 abr 2021
Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow
35RISCO
abrir
VulnCheck XDB
local
CVE-2018-8611HIGHsob ataque27 abr 2021
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-1272527 abr 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-1389HIGHsob ataque26 abr 2021
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-1732HIGHsob ataqueransomware25 abr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHsob ataque25 abr 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
VulnCheck XDB
client-side
CVE-2018-6065HIGHsob ataque24 abr 2021
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RISCO
abrir
VulnCheck XDB
local
CVE-2021-1732HIGHsob ataqueransomware23 abr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMsob ataqueransomware22 abr 2021
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-0604CRITICALsob ataqueransomware22 abr 2021
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHsob ataque22 abr 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHsob ataque22 abr 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALsob ataqueransomware22 abr 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
anteriorpágina 221 / 274próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.