Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.542exploits catalogados
34.971CVEs com exploração pública
24.695testados em laboratório
13.947 exploits
GitHub PoC1
2021 kernel vulnerability in Ubuntu.
CVE-2021-3493HIGHsob ataque12 set 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
GitHub PoC
sbladiamond/CVE-2021-3156
CVE-2021-3156HIGHsob ataque11 set 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
KnoooW/CVE-2021-40444-docx-Generate
CVE-2021-40444HIGHsob ataqueransomware11 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC4
fengjixuchui/CVE-2021-40444-docx-Generate
CVE-2021-40444HIGHsob ataqueransomware11 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Strapi Remote Code Execution
CVE-2019-1960911 set 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISCO
abrir
GitHub PoC11
A malicious .cab creation tool for CVE-2021-40444
CVE-2021-40444HIGHsob ataqueransomware11 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Hunting CVE-2018-13379
CVE-2018-13379CRITICALsob ataqueransomware11 set 2021
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
GitHub PoC1
CVE-2021-40444 Sample
CVE-2021-40444HIGHsob ataqueransomware10 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1.743
CVE-2021-40444 PoC
CVE-2021-40444HIGHsob ataqueransomware10 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
koharin/CVE-2020-0041
CVE-2020-0041HIGHsob ataque10 set 2021
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISCO
abrir
GitHub PoC3
CVE-2020-9054 PoC for Zyxel
CVE-2020-9054CRITICALsob ataque09 set 2021
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
100RISCO
abrir
GitHub PoC
Confluence OGNL injection
CVE-2021-26084CRITICALsob ataqueransomware09 set 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC3
maguireja/CVE-2020-25223
CVE-2020-25223CRITICALsob ataque09 set 2021
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RISCO
abrir
GitHub PoC7
CVE-2021-40444 POC
CVE-2021-40444HIGHsob ataqueransomware09 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC3
vysecurity/CVE-2021-40444
CVE-2021-40444HIGHsob ataqueransomware09 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Immersive-Labs-Sec/cve-2021-40444-analysis
CVE-2021-40444HIGHsob ataqueransomware09 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Something I wrote for CVE-2019-15107, a Webmin backdoor
CVE-2019-15107CRITICALsob ataqueransomware09 set 2021
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC2
根据已知样本反编译代码
CVE-2021-40444HIGHsob ataqueransomware09 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC16
rfcxv/CVE-2021-40444-POC
CVE-2021-40444HIGHsob ataqueransomware09 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC16
Microsoft MSHTML Remote Code Execution Vulnerability CVE-2021-40444
CVE-2021-40444HIGHsob ataqueransomware08 set 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC2
Exploit chain for CVE-2019-9791 & CVE-2019-11708 against firefox 65.0 on windows 64bit
CVE-2019-979108 set 2021
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects w
28RISCO
abrir
GitHub PoC1
CVE-2021-26084 patch as provided in "Confluence Security Advisory - 2021-08-25"
CVE-2021-26084CRITICALsob ataqueransomware08 set 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC2
Patched Confluence 7.12.2 (CVE-2021-26084)
CVE-2021-26084CRITICALsob ataqueransomware08 set 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC30
Atlassian Confluence CVE-2021-26084 one-liner mass checker
CVE-2021-26084CRITICALsob ataqueransomware07 set 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC4
alikarimi999/CVE-2021-21315
CVE-2021-21315HIGHsob ataque07 set 2021
Command Injection Vulnerability
100RISCO
abrir
GitHub PoC1
A quick and dirty PoC of cve-2021-26084 as none of the existing ones worked for me.
CVE-2021-26084CRITICALsob ataqueransomware07 set 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC1
Modified Verion of CVE-2016-0792
CVE-2016-079207 set 2021
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex
60RISCO
abrir
GitHub PoC5
A vulnerability can allow an attacker to guess the automatically generated development mode secret token.
CVE-2019-542006 set 2021
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir
GitHub PoC
Confluence OGNL Injection [CVE-2021-26084].
CVE-2021-26086MEDIUMsob ataque05 set 2021
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RISCO
abrir
GitHub PoC42
A Python replicated exploit for Webmin 1.580 /file/show.cgi Remote Code Execution
CVE-2012-298204 set 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir
anteriorpágina 360 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.