Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.542exploits catalogados
34.971CVEs com exploração pública
24.695testados em laboratório
13.947 exploits
GitHub PoC27
cve-2021-42013.py is a python script that will help in finding Path Traversal or Remote Code Execution vulnerability in Apache 2.4.50
CVE-2021-42013CRITICALsob ataqueransomware27 out 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
rafaelcaria/drupalgeddon2-CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware27 out 2021
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC21
VMware vCenter Server任意文件上传漏洞 / Code By:Jun_sheng
CVE-2021-22005CRITICALsob ataqueransomware27 out 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
GitHub PoC
RB4C/drupalgeddon2-CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware27 out 2021
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC
b1tg/CVE-2021-34486-exp
CVE-2021-34486HIGHsob ataque27 out 2021
Windows Event Tracing Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC296
command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
CVE-2021-36260CRITICALsob ataque27 out 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
GitHub PoC11
Remote Code Execution exploit for Apache servers. Affected versions: Apache 2.4.49, Apache 2.4.50
CVE-2021-41773HIGHsob ataqueransomware26 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC7
CVE-2021-26084,Atlassian Confluence OGNL注入漏洞
CVE-2021-26084CRITICALsob ataqueransomware26 out 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC1
confluence远程代码执行RCE / Code By:Jun_sheng
CVE-2021-26084CRITICALsob ataqueransomware25 out 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC
Script fo testing CVE-2000-0649 for Apache and MS IIS servers
CVE-2000-064925 out 2021
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RISCO
abrir
GitHub PoC
A automatic scanner to apache 2.4.49
CVE-2021-41773HIGHsob ataqueransomware25 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC18
PoC for the CVE-2021-20837 : RCE in MovableType
CVE-2021-2083725 out 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISCO
abrir
GitHub PoC45
LPE exploit for a UAF in Windows (CVE-2021-40449).
CVE-2021-40449HIGHsob ataqueransomware25 out 2021
Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC1
MazX0p/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware25 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC12
CVE-2021-40438 exploit PoC with Docker setup.
CVE-2021-40438CRITICALsob ataqueransomware24 out 2021
mod_proxy SSRF
100RISCO
abrir
GitHub PoC2
tiagob0b/CVE-2021-22005
CVE-2021-22005CRITICALsob ataqueransomware24 out 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
GitHub PoC1
Serv-U-FTP CVE-2021-35211 exploit
CVE-2021-35211CRITICALsob ataqueransomware24 out 2021
Serv-U Remote Memory Escape Vulnerability
100RISCO
abrir
GitHub PoC7
PoC CVE-2021-42013 reverse shell Apache 2.4.50 with CGI
CVE-2021-42013CRITICALsob ataqueransomware24 out 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
tiagob0b/CVE-2021-40444
CVE-2021-40444HIGHsob ataqueransomware24 out 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC2
Poc CVE-2021-42013 - Apache 2.4.50 without CGI
CVE-2021-42013CRITICALsob ataqueransomware23 out 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
Poc CVE-2021-41773 - Apache 2.4.49 with CGI enabled
CVE-2021-41773HIGHsob ataqueransomware23 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC2
cve-2021-41773.py is a python script that will help in finding Path Traversal or Remote Code Execution vulnerability in Apache 2.4.49
CVE-2021-41773HIGHsob ataqueransomware23 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
scopion/CVE-2017-3241
CVE-2017-324122 out 2021
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versi
35RISCO
abrir
GitHub PoC
BabyTeam1024/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware22 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
THIS IS NOT AN ORIGINAL EXPLOIT. THIS IS AN AUDITED VERSION FOR A THM BOX
CVE-2020-10915CRITICAL20 out 2021
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.
85RISCO
abrir
GitHub PoC98
windows 10 14393 LPE
CVE-2021-40449HIGHsob ataqueransomware20 out 2021
Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
LayarKacaSiber/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware20 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
LayarKacaSiber/CVE-2021-42013
CVE-2021-42013CRITICALsob ataqueransomware20 out 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
CVE-2021-3156 exploit
CVE-2021-3156HIGHsob ataque20 out 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC2
Just a simple CVE-2021-31166 exploit tool
CVE-2021-31166CRITICALsob ataque20 out 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISCO
abrir
anteriorpágina 353 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.