Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.542exploits catalogados
34.971CVEs com exploração pública
24.695testados em laboratório
13.947 exploits
GitHub PoC1
Exploit CVE 2021 26084 Confluence
CVE-2021-26084CRITICALsob ataqueransomware20 out 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC
bibo318/kali-CVE-2019-0708-lab
CVE-2019-0708CRITICALsob ataqueransomware19 out 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC17
CVE-2021-36260
CVE-2021-36260CRITICALsob ataque18 out 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
GitHub PoC1
Lab setup for CVE-2021-41773 (Apache httpd 2.4.49) and CVE-2021-42013 (Apache httpd 2.4.50).
CVE-2021-41773HIGHsob ataqueransomware18 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC4
xiaojiangxl/CVE-2021-40438
CVE-2021-40438CRITICALsob ataqueransomware18 out 2021
mod_proxy SSRF
100RISCO
abrir
GitHub PoC1
Exploit For CVE-2019-17662
CVE-2019-1766218 out 2021
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISCO
abrir
GitHub PoC3
Dahua IPC/VTH/VTO devices auth bypass exploit
CVE-2021-33044CRITICALsob ataque18 out 2021
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISCO
abrir
GitHub PoC11
Scanner for CVE-2022-22948 an Information Disclosure in VMWare vCenter
CVE-2022-22948MEDIUMsob ataque17 out 2021
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious act
83RISCO
abrir
GitHub PoC478
Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)
CVE-2021-40449HIGHsob ataqueransomware16 out 2021
Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC35
Little thing put together quickly to demonstrate this CVE
CVE-2020-11022MEDIUM16 out 2021
jQuery has a potential XSS vulnerability
55RISCO
abrir
GitHub PoC
TIC4301 Project - CVE-2021-40444
CVE-2021-40444HIGHsob ataqueransomware16 out 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC2
Simple honeypot for CVE-2021-41773 vulnerability
CVE-2021-41773HIGHsob ataqueransomware16 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC4
The first vulnerability with the CVE identifier CVE-2021-41773 is a path traversal flaw that exists in Apache HTTP Server 2.4.49.
CVE-2021-41773HIGHsob ataqueransomware15 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC9
apache httpd path traversal checker(CVE-2021-41773 / CVE-2021-42013)
CVE-2021-41773HIGHsob ataqueransomware15 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
metehangenel/MSHTML-CVE-2021-40444
CVE-2021-40444HIGHsob ataqueransomware15 out 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.
CVE-2021-4207115 out 2021
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharac
50RISCO
abrir
GitHub PoC
CVE-2020-25078账号密码信息泄露批量脚本Batch script of D-Link DCS series camera account password information disclosure
CVE-2020-25078HIGHsob ataque15 out 2021
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RISCO
abrir
GitHub PoC2
Docker container lab to play/learn with CVE-2021-42013
CVE-2021-42013CRITICALsob ataqueransomware14 out 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC1
Testing CVE-2021-30858 Rev3
CVE-2021-30858HIGHsob ataque14 out 2021
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, m
76RISCO
abrir
GitHub PoC
Docker container lab to play/learn with CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware14 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
My take on CVE-2021-30858 for ps4 8.xx
CVE-2021-30858HIGHsob ataque14 out 2021
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, m
76RISCO
abrir
GitHub PoC
zomy22/CVE-2020-16846-Saltstack-Salt-API
CVE-2020-16846CRITICALsob ataque14 out 2021
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH clien
100RISCO
abrir
GitHub PoC61
Tool check: CVE-2021-41773, CVE-2021-42013, CVE-2020-17519
CVE-2020-17519CRITICALsob ataque13 out 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir
GitHub PoC
Hasintha-98/Sudo-Vulnerability-Exploit-CVE-2019-14287
CVE-2019-1428713 out 2021
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC8
Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
CVE-2020-1077013 out 2021
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RISCO
abrir
GitHub PoC2
musergi/CVE-2021-3156
CVE-2021-3156HIGHsob ataque13 out 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC61
Tool check: CVE-2021-41773, CVE-2021-42013, CVE-2020-17519
CVE-2021-41773HIGHsob ataqueransomware13 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
critical: Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) (CVE-2021-42013)
CVE-2021-41773HIGHsob ataqueransomware12 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC13
hoav18/CVE-2021-22941
CVE-2021-22941CRITICALsob ataqueransomware12 out 2021
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacke
90RISCO
abrir
GitHub PoC
nxlog ubuntu CVE-2020-35488
CVE-2020-3548812 out 2021
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of
23RISCO
abrir
anteriorpágina 354 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.