Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
24.466 exploits
Exploit-DB
WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read (Unauthenticated)
CVE-2021-39312HIGHwebappsphp05 jan 2022
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISCO
abrir
Exploit-DB
WordPress Plugin WP Visitor Statistics 4.7 - SQL Injection
CVE-2021-24750webappsphp05 jan 2022
WP Visitor Statistics (Real Time Traffic) < 4.8 - Subscriber+ SQL Injection
50RISCO
abrir
Exploit-DB
Automox Agent 32 - Local Privilege Escalation
CVE-2021-43326localwindows05 jan 2022
Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
23RISCO
abrir
Exploit-DB
ConnectWise Control 19.2.24707 - Username Enumeration
CVE-2019-16516remotemultiple05 jan 2022
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumer
28RISCO
abrir
Exploit-DB
Gerapy 0.9.7 - Remote Code Execution (RCE) (Authenticated)
CVE-2021-43857CRITICALremotepython05 jan 2022
Gerapy may contain remote code execution vulnerability
60RISCO
abrir
Exploit-DB
WBCE CMS 1.5.1 - Admin Password Reset
CVE-2021-3817CRITICALwebappsphp20 dez 2021
SQL Injection in wbce/wbce_cms
60RISCO
abrir
Exploit-DB
Cibele Thinfinity VirtualUI 2.5.41.0 - User Enumeration
CVE-2021-44848webappsmultiple16 dez 2021
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques
43RISCO
abrir
Exploit-DB
Apache Log4j2 2.14.1 - Information Disclosure
CVE-2021-44228CRITICALsob ataqueransomwareremotejava14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Exploit-DB
Booked Scheduler 2.7.5 - Remote Command Execution (RCE) (Authenticated)
CVE-2019-9581webappsphp14 dez 2021
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitra
28RISCO
abrir
Exploit-DB
Apache Log4j 2 - Remote Code Execution (RCE)
CVE-2021-44228CRITICALsob ataqueransomwareremotejava14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Exploit-DB
WebHMI 4.0 - Remote Code Execution (RCE) (Authenticated)
CVE-2021-43936CRITICALwebappsphp13 dez 2021
Distributed Data Systems WebHM
60RISCO
abrir
Exploit-DB
HD-Network Real-time Monitoring System 2.0 - Local File Inclusion (LFI)
CVE-2021-45043remotelinux13 dez 2021
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_L
50RISCO
abrir
Exploit-DB
Grafana 8.3.0 - Directory Traversal and Arbitrary File Read
CVE-2021-43798HIGHsob ataquewebappsmultiple09 dez 2021
Grafana path traversal
100RISCO
abrir
Exploit-DB
Student Management System 1.0 - SQLi Authentication Bypass
CVE-2020-23935webappsphp09 dez 2021
Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (
28RISCO
abrir
Exploit-DB
Raspberry Pi 5.10 - Default Credentials
CVE-2021-38759remotelinux09 dez 2021
Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain a
28RISCO
abrir
Exploit-DB
Auerswald COMpact 8.0B - Multiple Backdoors
CVE-2021-40859remotehardware06 dez 2021
Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web
60RISCO
abrir
Exploit-DB
Croogo 3.0.2 - Remote Code Execution (Authenticated)
CVE-2021-44673webappsphp06 dez 2021
A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malic
23RISCO
abrir
Exploit-DB
WordPress Plugin DZS Zoomsounds 6.45 - Arbitrary File Read (Unauthenticated)
CVE-2021-39316HIGHwebappsphp03 dez 2021
ZoomSounds <= 6.45 Unauthenticated Directory Traversal and Sensitive Information Dislosure
68RISCO
abrir
Exploit-DB
Online Enrollment Management System in PHP and PayPal 1.0 - 'U_NAME' Stored Cross-Site Scripting
CVE-2021-40577webappsphp01 dez 2021
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP an
23RISCO
abrir
Exploit-DB
Linux Kernel 5.1.x - 'PTRACE_TRACEME' pkexec Local Privilege Escalation (2)
CVE-2019-13272HIGHsob ataquelocallinux23 nov 2021
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
Exploit-DBVexDay Proof
SuiteCRM 7.11.18 - Remote Code Execution (RCE) (Authenticated) (Metasploit)
CVE-2021-42840webappsphp17 nov 2021
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumsta
50RISCO
abrir
Exploit-DB
GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2021-22205CRITICALsob ataqueransomwarewebappsruby17 nov 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
Exploit-DB
Bludit 3.13.1 - 'username' Cross Site Scripting (XSS)
CVE-2021-35323webappsphp17 nov 2021
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
38RISCO
abrir
Exploit-DB
Online Learning System 2.0 - Remote Code Execution (RCE)
CVE-2021-42580webappsphp16 nov 2021
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/adm
23RISCO
abrir
Exploit-DB
Simple Subscription Website 1.0 - SQLi Authentication Bypass
CVE-2021-43140webappsphp15 nov 2021
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
23RISCO
abrir
Exploit-DB
WordPress Plugin WPSchoolPress 2.1.16 - 'Multiple' Cross Site Scripting (XSS)
CVE-2021-24664webappsphp15 nov 2021
WPSchoolPress < 2.1.17 - Multiple Admin+ Stored Cross-Site Scripting
23RISCO
abrir
Exploit-DB
PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF)
CVE-2021-43617webappsphp15 nov 2021
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Val
28RISCO
abrir
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
CVE-2021-41773HIGHsob ataqueransomwarewebappsmultiple11 nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
CVE-2021-42013CRITICALsob ataqueransomwarewebappsmultiple11 nov 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
Exploit-DB
FormaLMS 2.4.4 - Authentication Bypass
CVE-2021-43136webappsmultiple11 nov 2021
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain
28RISCO
abrir
anteriorpágina 33 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.