Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.542exploits catalogados
34.971CVEs com exploração pública
24.695testados em laboratório
13.947 exploits
GitHub PoC1
daletoniris/CVE-2021-22555-esc-priv
CVE-2021-22555HIGHsob ataque01 out 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISCO
abrir
GitHub PoC1
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deployment of the VNC server. The password for authentication is stored in cleartext in a file that can be read via a ../../ThinVnc.ini directory traversal attack vector.
CVE-2019-1766201 out 2021
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISCO
abrir
GitHub PoC28
Cisco RV110w UPnP stack overflow
CVE-2021-34730CRITICAL30 set 2021
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerability
53RISCO
abrir
GitHub PoC12
Simple Serv-U CVE-2021-35211 PoC
CVE-2021-35211CRITICALsob ataqueransomware30 set 2021
Serv-U Remote Memory Escape Vulnerability
100RISCO
abrir
GitHub PoC5
This docx exploit uses res files inside Microsoft .docx file to execute malicious files. This exploit is related to CVE-2021-40444
CVE-2021-40444HIGHsob ataqueransomware29 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
CVE-2021-25162
CVE-2021-2516229 set 2021
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products
28RISCO
abrir
GitHub PoC
According to researchers with Rapid7, over 110,000 devices appear on internet, which run stable Samba versions, while 92,500 seem to run unstable Samba versions, for which there is no fix. The newest Samba models, including the models 4.6.x before 4.6.4, 4.5.x before 4.5.10 and 3.5.0 before 4.4.13, was impacted by this error. May 24, 2017, Samba released version 4.6.4, which fixes a serious remote code execution vulnerability, vulnerability number CVE-2017-7494, which affected Samba 3.5.0 onwards. Vulnerability number: CVE-2017-7494 Severity Rating: High Affected software: • Samba Version < 4.6.4 • Samba Version < 4.5.10 • Samba Version < 4.4.14 Unaffected software: • Samba Version = 4.6.4 • Samba Version = 4.5.10 • Samba Version = 4.4.14
CVE-2017-7494CRITICALsob ataqueransomware29 set 2021
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
GitHub PoC
漏洞复现与poc收集,CVE-2021-21975,cve-2021-22005,CVE-2021-26295,VMware vCenter任意文件读取
CVE-2021-21975HIGHsob ataqueransomware29 set 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
GitHub PoC14
CrackerCat/CVE-2021-30632
CVE-2021-30632HIGHsob ataque28 set 2021
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISCO
abrir
GitHub PoC37
rwincey/CVE-2021-22005
CVE-2021-22005CRITICALsob ataqueransomware28 set 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
GitHub PoC1
CVE-2021-22005_PoC
CVE-2021-22005CRITICALsob ataqueransomware27 set 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
GitHub PoC3
CVE-2019-19781
CVE-2019-19781CRITICALsob ataqueransomware27 set 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC
Sudo heap-based buffer overflow privilege escalation commands and mitigations.
CVE-2021-3156HIGHsob ataque27 set 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC2
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
CVE-2018-1676327 set 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC19
Windows HTTP协议栈远程代码执行漏洞 CVE-2021-31166
CVE-2021-31166CRITICALsob ataque27 set 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC209
Python implementation for PrintNightmare (CVE-2021-1675 / CVE-2021-34527)
CVE-2021-1675HIGHsob ataqueransomware26 set 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
Quick and dirty CVE-2021-38647 (Omigod) exploit written in Go.
CVE-2021-38647CRITICALsob ataqueransomware26 set 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC10
C# PrintNightmare (CVE-2021-1675)
CVE-2021-1675HIGHsob ataqueransomware26 set 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
AmesianX/CVE-2021-21220
CVE-2021-21220HIGHsob ataque26 set 2021
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
98RISCO
abrir
GitHub PoC1
Python script to obtain RCE on Mantis Bug Tracker prior to version 1.2.x Check CVE-2008-4687 for additional information
CVE-2008-468725 set 2021
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISCO
abrir
GitHub PoC13
CVE-2021-22005批量验证python脚本
CVE-2021-22005CRITICALsob ataqueransomware25 set 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
GitHub PoC17
CVE-2021-3156 - sudo exploit for ubuntu 18.04 & 20.04
CVE-2021-3156HIGHsob ataque25 set 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC1
CVE-2021-38647 is an unauthenticated RCE vulnerability effecting the OMI agent as root.
CVE-2021-38647CRITICALsob ataqueransomware24 set 2021
Open Management Infrastructure Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
Windows Kernel Registry Elevation of Privilege Vulnerability
CVE-2018-841024 set 2021
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory
23RISCO
abrir
GitHub PoC1
BeneficialCode/CVE-2021-1732
CVE-2021-1732HIGHsob ataqueransomware24 set 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC5
CVE-2021-33739 PoC Analysis
CVE-2021-33739HIGHsob ataque24 set 2021
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC
CVE 2021 40444 Windows Exploit services.dll
CVE-2021-40444HIGHsob ataqueransomware24 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
CVE-2021-22005
CVE-2021-22005CRITICALsob ataqueransomware24 set 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
GitHub PoC1
pisut4152/Sigma-Rule-for-CVE-2021-22005-scanning-activity
CVE-2021-22005CRITICALsob ataqueransomware23 set 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
GitHub PoC8
1ZRR4H/CVE-2021-22005
CVE-2021-22005CRITICALsob ataqueransomware23 set 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
anteriorpágina 358 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.