Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.647exploits catalogados
34.986CVEs com exploração pública
24.695testados em laboratório
14.014 exploits
GitHub PoC2
CVE-2020–7961 Mass exploit for Script Kiddies
CVE-2020-7961CRITICALsob ataque09 abr 2021
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir
GitHub PoC2
CVE-2021-3317
CVE-2021-331709 abr 2021
KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of
35RISCO
abrir
GitHub PoC
Buffer Overflow in Seattle Lab Mail (SLmail) 5.5 - POP3
CVE-2003-026408 abr 2021
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISCO
abrir
GitHub PoC
CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
CVE-2016-209807 abr 2021
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISCO
abrir
GitHub PoC
Exploit for CVE-2012-2982
CVE-2012-298206 abr 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir
GitHub PoC
pwn3z/CVE-2019-19781-Citrix
CVE-2019-19781CRITICALsob ataqueransomware06 abr 2021
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC37
vRealize RCE + Privesc (CVE-2021-21975, CVE-2021-21983, CVE-0DAY-?????)
CVE-2021-21975HIGHsob ataqueransomware06 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
GitHub PoC1
Exploit Code for CVE-2020-1472 aka Zerologon
CVE-2020-1472MEDIUMsob ataqueransomware06 abr 2021
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC6
[CVE-2021-21972] VMware vSphere Client Unauthorized File Upload to Remote Code Execution (RCE)
CVE-2021-21972CRITICALsob ataqueransomware06 abr 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC
capturingcats/CVE-2021-3156
CVE-2021-3156HIGHsob ataque05 abr 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC3
Exploiting CVE-2014-7205 by injecting arbitrary JavaScript resulting in Remote Code Execution.
CVE-2014-720505 abr 2021
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t
60RISCO
abrir
GitHub PoC
delina1/CVE-2018-8174_EXP
CVE-2018-8174HIGHsob ataqueransomware05 abr 2021
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
GitHub PoC
delina1/CVE-2018-8174
CVE-2018-8174HIGHsob ataqueransomware05 abr 2021
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir
GitHub PoC1
CVE-2017-9805-Exploit
CVE-2017-9805HIGHsob ataque04 abr 2021
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC
piruprohacking/CVE-2020-25213
CVE-2020-25213CRITICALsob ataque03 abr 2021
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir
GitHub PoC
CVE-2019-0708 Exploit
CVE-2019-0708CRITICALsob ataqueransomware03 abr 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
shreesh1/CVE-2014-0226-poc
CVE-2014-022602 abr 2021
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denia
45RISCO
abrir
GitHub PoC3
linuxdy/CVE-2021-1732_exp
CVE-2021-1732HIGHsob ataqueransomware02 abr 2021
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC4
[CVE-2021-21975] VMware vRealize Operations Manager API Server Side Request Forgery (SSRF)
CVE-2021-21975HIGHsob ataqueransomware02 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
GitHub PoC27
Nmap script to check vulnerability CVE-2021-21975
CVE-2021-21975HIGHsob ataqueransomware01 abr 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
GitHub PoC
Pommaq/CVE-1999-0016-POC
CVE-1999-001601 abr 2021
Land IP denial of service.
45RISCO
abrir
GitHub PoC1
Vulnmachines/apache-ofbiz-CVE-2020-9496
CVE-2020-949601 abr 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISCO
abrir
GitHub PoC3
CVE-2020-14882部署冰蝎内存马
CVE-2020-14882CRITICALsob ataque31 mar 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC12
VMWare vRealize SSRF-CVE-2021-21975
CVE-2021-21975HIGHsob ataqueransomware31 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
GitHub PoC9
hev0x/CVE-2021-26828_ScadaBR_RCE
CVE-2021-26828HIGHsob ataque31 mar 2021
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe
83RISCO
abrir
GitHub PoC13
CVE-2021-21975 vRealize Operations Manager SSRF
CVE-2021-21975HIGHsob ataqueransomware31 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
GitHub PoC2
dorkerdevil/CVE-2021-21975
CVE-2021-21975HIGHsob ataqueransomware31 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
GitHub PoC1
A collection of scripts and instructions to test CVE-2014-0160 (heartbleed). ❤️ 🩸
CVE-2014-0160HIGHsob ataque30 mar 2021
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
CVE-2019-12840
CVE-2019-1284030 mar 2021
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISCO
abrir
GitHub PoC11
Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal
CVE-2020-2383930 mar 2021
A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpa
28RISCO
abrir
anteriorpágina 376 / 468próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.