Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.759exploits catalogados
38.127CVEs com exploração pública
24.695testados em laboratório
81.759 exploits
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALsob ataqueransomware22 out 2024
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware22 out 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-28771CRITICALsob ataque22 out 2024
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-3560HIGHsob ataque22 out 2024
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALsob ataque22 out 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALsob ataqueransomware22 out 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALsob ataqueransomware22 out 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2024-4956HIGH22 out 2024
Nexus Repository 3 - Path Traversal
61RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-4956HIGH22 out 2024
Nexus Repository 3 - Path Traversal
61RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-4956HIGH22 out 2024
Nexus Repository 3 - Path Traversal
61RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-27925HIGHsob ataqueransomware22 out 2024
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque22 out 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque22 out 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗
VulnCheck XDB
denial-of-service
CVE-2022-21907CRITICAL22 out 2024
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM22 out 2024
Cross site scripting
70RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALsob ataque22 out 2024
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware22 out 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque22 out 2024
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware22 out 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware22 out 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-49070—22 out 2024
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALsob ataqueransomware22 out 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-36845CRITICALsob ataque22 out 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-2523HIGH22 out 2024
Weaver E-Office unrestricted upload
53RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-5360—22 out 2024
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISCO
abrir ↗
GitHub PoC★ 1
grecosamuel/CVE-2024-32002
CVE-2024-32002CRITICAL22 out 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALsob ataqueransomware22 out 2024
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-22954CRITICALsob ataqueransomware22 out 2024
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-28987CRITICALsob ataque22 out 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-38831HIGHsob ataqueransomware22 out 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir ↗
← anteriorpágina 412 / 2.726próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.