Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
8.195 exploits
VulnCheck XDB
client-side
CVE-2023-2033HIGHsob ataque02 ago 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware02 ago 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALsob ataqueransomware02 ago 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-25213CRITICALsob ataque02 ago 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALsob ataqueransomware01 ago 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-23333CRITICAL01 ago 2023
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-35078CRITICALsob ataqueransomware01 ago 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALsob ataque01 ago 2023
Unauthenticated Command Injection
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864631 jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-35078CRITICALsob ataqueransomware31 jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHsob ataque31 jul 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL31 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864630 jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864630 jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-3864630 jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864629 jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-35078CRITICALsob ataqueransomware29 jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-32243CRITICAL29 jul 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2013-015629 jul 2023
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataque28 jul 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864628 jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-346027 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALsob ataqueransomware27 jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-46747CRITICALsob ataqueransomware27 jul 2023
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALsob ataqueransomware26 jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-27163MEDIUM26 jul 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-27163MEDIUM26 jul 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMsob ataque26 jul 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-3864625 jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMsob ataque25 jul 2023
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir
anteriorpágina 156 / 274próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.