Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.647exploits catalogados
34.986CVEs com exploração pública
24.695testados em laboratório
14.014 exploits
GitHub PoC2
CVE-2020-12351
CVE-2020-1235101 mar 2021
Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via a
23RISCO
abrir
GitHub PoC1
andyfeili/-CVE-2019-7214
CVE-2019-721401 mar 2021
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RISCO
abrir
GitHub PoC160
CVE 2021-21315 PoC
CVE-2021-21315HIGHsob ataque01 mar 2021
Command Injection Vulnerability
100RISCO
abrir
GitHub PoC11
漏洞利用,Vmware vCenter 6.5-7.0 RCE(CVE-2021-21972),上传冰蝎3,getshell
CVE-2021-21972CRITICALsob ataqueransomware01 mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC1
Modified the test PoC from Secura, CVE-2020-1472, to change the machine password to null
CVE-2020-1472MEDIUMsob ataqueransomware01 mar 2021
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC1
VMware vCenter CVE-2021-21972 Tools
CVE-2021-21972CRITICALsob ataqueransomware27 fev 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC
JMousqueton/Detect-CVE-2021-21972
CVE-2021-21972CRITICALsob ataqueransomware27 fev 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC
CVE-2015-3224
CVE-2015-322427 fev 2021
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RISCO
abrir
GitHub PoC44
ZeusBox/CVE-2021-21017
CVE-2021-21017HIGHsob ataque26 fev 2021
Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
93RISCO
abrir
GitHub PoC28
Nmap script to check vulnerability CVE-2021-21972
CVE-2021-21972CRITICALsob ataqueransomware26 fev 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC27
VMware vCenter 未授权RCE(CVE-2021-21972)
CVE-2021-21972CRITICALsob ataqueransomware25 fev 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC15
Nibbleblog 4.0.3 - Arbitrary File Upload (CVE-2015-6967)
CVE-2015-696725 fev 2021
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RISCO
abrir
GitHub PoC2
CVE-2021-21972
CVE-2021-21972CRITICALsob ataqueransomware25 fev 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC1
A vulnerability scanner that detects CVE-2021-21972 vulnerabilities.
CVE-2021-21972CRITICALsob ataqueransomware25 fev 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC33
CVE-2021-21972
CVE-2021-21972CRITICALsob ataqueransomware25 fev 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC8
CVE-2020-14882
CVE-2020-14882CRITICALsob ataque25 fev 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC
A vulnerability scanner that detects CVE-2020-14883 vulnerabilities.
CVE-2020-14883HIGHsob ataque25 fev 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC54
alt3kx/CVE-2021-21972
CVE-2021-21972CRITICALsob ataqueransomware25 fev 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC11
VMware vCenter Server远程代码执行漏洞 (CVE-2021-21972)批量检测脚本
CVE-2021-21972CRITICALsob ataqueransomware25 fev 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC
A vulnerability scanner that detects CVE-2020-17519 vulnerabilities.
CVE-2020-17519CRITICALsob ataque25 fev 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir
GitHub PoC1
L-pin/CVE-2021-21972
CVE-2021-21972CRITICALsob ataqueransomware25 fev 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC499
CVE-2021-21972 Exploit
CVE-2021-21972CRITICALsob ataqueransomware24 fev 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC270
Proof of Concept Exploit for vCenter CVE-2021-21972
CVE-2021-21972CRITICALsob ataqueransomware24 fev 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC8
yaunsky/CVE-2021-21972
CVE-2021-21972CRITICALsob ataqueransomware24 fev 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC136
QmF0c3UK/CVE-2021-21972-vCenter-6.5-7.0-RCE-POC
CVE-2021-21972CRITICALsob ataqueransomware24 fev 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC3
lsw29475/CVE-2019-17026
CVE-2019-17026HIGHsob ataque24 fev 2021
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are
83RISCO
abrir
GitHub PoC
oneoy/CVE-2021-3156
CVE-2021-3156HIGHsob ataque23 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC3
Python implementation of 'Username' map script' RCE Exploit for Samba 3.0.20 < 3.0.25rc3 (CVE-2007-2447).
CVE-2007-244722 fev 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC1
Nicoslo/Windows-Exploitation-Web-Server-Tomcat-8.5.39-CVE-2019-0232
CVE-2019-023221 fev 2021
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISCO
abrir
GitHub PoC1
Nicoslo/Windows-exploitation-Apache-Tomcat-8.5.19-CVE-2019-0232-
CVE-2019-023220 fev 2021
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISCO
abrir
anteriorpágina 380 / 468próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.