Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.647exploits catalogados
34.986CVEs com exploração pública
24.695testados em laboratório
13.977 exploits
GitHub PoC5
Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature
CVE-2021-3176121 abr 2021
Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's ru
35RISCO
abrir
GitHub PoC47
DO NOT RUN THIS.
CVE-2021-22893CRITICALsob ataqueransomware21 abr 2021
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windo
90RISCO
abrir
GitHub PoC8
Exploiting a Cross-site request forgery (CSRF) attack to creat a new privileged user through the Webmin's add users feature
CVE-2021-3176221 abr 2021
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users fea
23RISCO
abrir
GitHub PoC1
Exploiting a Cross-site request forgery (CSRF) attack to creat a new privileged user through the Webmin's add users feature
CVE-2021-3176221 abr 2021
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users fea
23RISCO
abrir
GitHub PoC4
Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature
CVE-2021-3176121 abr 2021
Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's ru
35RISCO
abrir
GitHub PoC
jquery file upload poc
CVE-2018-920620 abr 2021
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISCO
abrir
GitHub PoC442
Ubuntu OverlayFS Local Privesc
CVE-2021-3493HIGHsob ataque19 abr 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
GitHub PoC
針對近期微軟公布修補遭駭客攻擊的Exchange Server漏洞問題,台灣DEVCORE表示早在1月5日便已發現安全漏洞後,並且向微軟通報此項編號命名為「CVE-2021-26855 」,以及「CVE-2021-27065」的零日漏洞,同時也將此項漏洞稱為「ProxyLogon」。 此次揭露的「ProxyLogon」漏洞,是以無需驗證即可使用的遠端程式碼執行 (Pre-Auth Remote Code Execution;Pre-Auth RCE)零日漏洞(Zero-day exploit),可讓攻擊者得以繞過身份驗證步驟,驅使系統管理員協助執行惡意文件或執行指令,進而觸發更廣泛的攻擊。 「ProxyLogon」是微軟近期被揭露最重大的RCE漏洞之一,DEVCORE團隊遵循責任揭露 (Responsible Disclosure)原則,在發現後便第一時間立即於今年1月5日通報微軟進行修補,避免該漏洞遭有心人士利用,造成全球用戶重大損失。而微軟遂於3月2日針對相關漏洞釋出安全更新,避免用戶機敏資訊遭受惡意攻擊。個人想法:遭駭客攻擊的Exchange Server漏洞問題,台灣DEVCORE表示早在1月5日便已發現,並且向微軟通報此項編號命名為「CVE-2021-26855 」,以及「CVE-2021-27065」的零日漏洞,同時也將此項漏洞稱為「ProxyLogon」。 此次揭露的「ProxyLogon」漏洞,是以無需驗證即可使用的遠端程式碼執行 (Pre-Auth Remote Code Execution;Pre-Auth RCE)零日漏洞(Zero-day exploit),可讓攻擊者得以繞過身份驗證步驟,驅使系統管理員協助執行惡意文件或執行指令,進而觸發更廣泛的攻擊。 「ProxyLogon」是微軟近期被揭露最重大的RCE漏洞之一,DEVCORE團隊遵循責任揭露 (Responsible Disclosure)原則,在發現後便第一時間立即於今年1月5日通報微軟進行修補,避免該漏洞遭有心人士利用,造成全球用戶重大損失。而微軟遂於3月2日針對相關漏洞釋出安全更新,避免用戶機敏資訊遭受惡意攻擊。個人想法:微軟是大眾常用的軟體之一,駭客只要察覺漏洞就會進行惡意的攻擊,微軟公布4個Exchange Server的安全漏洞後,就遭受駭客的惡意攻擊,這件事的發生,微軟需更加小心並提高資安的防護。
CVE-2021-26855CRITICALsob ataqueransomware19 abr 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC3
my personal POC of CVE-2016-5195(dirtyCOW)
CVE-2016-5195HIGHsob ataque16 abr 2021
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC
cve-2007-2447 this script was rewrite the part of Metasploit modules to python3
CVE-2007-244716 abr 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC43
WordPress - Authenticated XXE (CVE-2021-29447)
CVE-2021-29447HIGH16 abr 2021
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC63
CVE-2021-27928 MariaDB/MySQL-'wsrep provider' 命令注入漏洞
CVE-2021-2792815 abr 2021
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
35RISCO
abrir
GitHub PoC177
[ProxyLogon] CVE-2021-26855 & CVE-2021-27065 Fixed RawIdentity Bug Exploit. [ProxyOracle] CVE-2021-31195 & CVE-2021-31196 Exploit Chains. [ProxyShell] CVE-2021-34473 & CVE-2021-34523 & CVE-2021-31207 Exploit Chains.
CVE-2021-26855CRITICALsob ataqueransomware14 abr 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Malicious Payloads that abuses Win32k Elevation of Privilege Vulnerability (CVE-2021-28310)
CVE-2021-28310HIGHsob ataque14 abr 2021
Win32k Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC
haotiku/CVE-2021-26855-exploit-Exchange
CVE-2021-26855CRITICALsob ataqueransomware14 abr 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
Auto exploit RCE CVE-2020-5902
CVE-2020-5902CRITICALsob ataqueransomware13 abr 2021
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC1
CVE-2020-17519 Cheetah
CVE-2020-17519CRITICALsob ataque13 abr 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir
GitHub PoC2
Samba exploit CVE2003-0201
CVE-2003-020112 abr 2021
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISCO
abrir
GitHub PoC3
GitLab 11.4.7 RCE exploit with different reverse shells. CVE-2018-19571 + CVE-2018-19585
CVE-2018-1957111 abr 2021
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RISCO
abrir
GitHub PoC
CVE-2021-3129-Laravel Debug mode 远程代码执行漏洞
CVE-2021-3129CRITICALsob ataqueransomware11 abr 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC3
VMWare-CVE-2021-21975 SSRF vulnerability
CVE-2021-21975HIGHsob ataqueransomware10 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
GitHub PoC
An exploit to get root in vsftpd 2.3.4 (CVE-2011-2523) written in python
CVE-2011-252309 abr 2021
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC2
CVE-2021-3317
CVE-2021-331709 abr 2021
KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of
35RISCO
abrir
GitHub PoC2
CVE-2020–7961 Mass exploit for Script Kiddies
CVE-2020-7961CRITICALsob ataque09 abr 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir
GitHub PoC5
CVE-2020-35729
CVE-2020-3572909 abr 2021
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RISCO
abrir
GitHub PoC
Buffer Overflow in Seattle Lab Mail (SLmail) 5.5 - POP3
CVE-2003-026408 abr 2021
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISCO
abrir
GitHub PoC
CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
CVE-2016-209807 abr 2021
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISCO
abrir
GitHub PoC37
vRealize RCE + Privesc (CVE-2021-21975, CVE-2021-21983, CVE-0DAY-?????)
CVE-2021-21975HIGHsob ataqueransomware06 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
GitHub PoC6
[CVE-2021-21972] VMware vSphere Client Unauthorized File Upload to Remote Code Execution (RCE)
CVE-2021-21972CRITICALsob ataqueransomware06 abr 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC
Exploit for CVE-2012-2982
CVE-2012-298206 abr 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir
anteriorpágina 374 / 466próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.