Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.596exploits catalogados
36.656CVEs com exploração pública
24.695testados em laboratório
24.466 exploits
Exploit-DB
Dolibarr ERP 11.0.4 - File Upload Restrictions Bypass (Authenticated RCE)
CVE-2020-14209webappsphp25 mar 2021
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code executio
28RISCO
abrir
Exploit-DB
Linksys EA7500 2.0.8.194281 - Cross-Site Scripting
CVE-2012-6708webappshardware25 mar 2021
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differen
23RISCO
abrir
Exploit-DB
MyBB 1.8.25 - Poll Vote Count SQL Injection
CVE-2021-27946webappsphp23 mar 2021
SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).
23RISCO
abrir
Exploit-DBVexDay Proof
Codiad 2.8.4 - Remote Code Execution (Authenticated)
CVE-2018-14009webappsmultiple23 mar 2021
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.
35RISCO
abrir
Exploit-DB
MyBB 1.8.25 - Chained Remote Command Execution
CVE-2021-27889webappsphp22 mar 2021
Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.
23RISCO
abrir
Exploit-DB
WordPress Plugin Delightful Downloads Jquery File Tree 1.6.6 - Path Traversal
CVE-2017-1000170webappsphp22 mar 2021
jqueryFileTree 2.1.5 and older Directory Traversal
50RISCO
abrir
Exploit-DB
MyBB 1.8.25 - Chained Remote Command Execution
CVE-2021-27890webappsphp22 mar 2021
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
28RISCO
abrir
Exploit-DB
LiveZilla Server 8.0.1.0 - 'Accept-Language' Reflected XSS
CVE-2019-12962webappsphp19 mar 2021
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.
38RISCO
abrir
Exploit-DB
VestaCP 0.9.8 - File Upload CSRF
CVE-2021-28379webappsmultiple17 mar 2021
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allow
23RISCO
abrir
Exploit-DB
Zenario CMS 8.8.53370 - 'id' Blind SQL Injection
CVE-2021-26830webappsphp15 mar 2021
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin
23RISCO
abrir
Exploit-DBVexDay Proof
SonLogger 4.2.3.3 - Unauthenticated Arbitrary File Upload (Metasploit)
CVE-2021-27964webappsmultiple15 mar 2021
SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Con
50RISCO
abrir
Exploit-DB
Microsoft Exchange 2019 - Server-Side Request Forgery
CVE-2021-26855CRITICALsob ataqueransomwareremotewindows14 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
Exploit-DB
Microsoft Exchange 2019 - Server-Side Request Forgery (Proxylogon) (PoC)
CVE-2021-27065HIGHsob ataqueransomwarewebappswindows11 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
Exploit-DB
Microsoft Exchange 2019 - Server-Side Request Forgery (Proxylogon) (PoC)
CVE-2021-26855CRITICALsob ataqueransomwarewebappswindows11 mar 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
Exploit-DB
Atlassian JIRA 8.11.1 - User Enumeration
CVE-2020-14181webappsmultiple10 mar 2021
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
60RISCO
abrir
Exploit-DBVexDay Proof
Golden FTP Server 4.70 - 'PASS' Buffer Overflow (2)
CVE-2006-6576remotewindows09 mar 2021
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (
50RISCO
abrir
Exploit-DB
Joomla JCK Editor 6.4.4 - 'parent' SQL Injection (2)
CVE-2018-17254webappsphp08 mar 2021
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
60RISCO
abrir
Exploit-DB
e107 CMS 2.3.0 - CSRF
CVE-2021-27885webappsphp04 mar 2021
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
23RISCO
abrir
Exploit-DBVexDay Proof
AnyDesk 5.5.2 - Remote Code Execution
CVE-2020-13160remotelinux03 mar 2021
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execut
60RISCO
abrir
Exploit-DB
Tiny Tiny RSS - Remote Code Execution
CVE-2020-25787webappsphp02 mar 2021
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting
28RISCO
abrir
Exploit-DBVexDay Proof
Zen Cart 1.5.7b - Remote Code Execution (Authenticated)
CVE-2021-3291webappsphp02 mar 2021
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod
28RISCO
abrir
Exploit-DBVexDay Proof
FortiLogger 4.4.2.2 - Unauthenticated Arbitrary File Upload (Metasploit)
CVE-2021-3378webappsmultiple01 mar 2021
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
60RISCO
abrir
Exploit-DB
VMware vCenter Server 7.0 - Unauthenticated File Upload
CVE-2021-21972CRITICALsob ataqueransomwarewebappsmultiple01 mar 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
Exploit-DB
Monica 2.19.1 - 'last_name' Stored XSS
CVE-2021-27370webappsmultiple23 fev 2021
The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.
23RISCO
abrir
Exploit-DB
TestLink 1.9.20 - Unrestricted File Upload (Authenticated)
CVE-2020-8639webappsphp15 fev 2021
An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute ar
28RISCO
abrir
Exploit-DB
Node.JS - 'node-serialize' Remote Code Execution (2)
CVE-2017-5941webappsnodejs10 fev 2021
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISCO
abrir
Exploit-DB
Adobe Connect 10 - Username Disclosure
CVE-2023-22232MEDIUMwebappsmultiple09 fev 2021
Adobe Connect Improper Access Control Security feature bypass
70RISCO
abrir
Exploit-DB
Alt-N MDaemon webmail 20.0.0 - 'file name' Stored Cross Site Scripting (XSS)
CVE-2020-18723webappswindows08 fev 2021
Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code
23RISCO
abrir
Exploit-DB
Alt-N MDaemon webmail 20.0.0 - 'Contact name' Stored Cross Site Scripting (XSS)
CVE-2020-18724webappswindows08 fev 2021
Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19
23RISCO
abrir
Exploit-DB
Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (1)
CVE-2021-3156HIGHsob ataquelocalmultiple03 fev 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
anteriorpágina 41 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.