Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
24.466 exploits
Exploit-DB
Pyro CMS 3.9 - Server-Side Template Injection (SSTI) (Authenticated)
CVE-2023-29689webappspython08 ago 2023
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template in
35RISCO
abrir
Exploit-DB
PHPJabbers Service Booking Script 1.0 - Reflected XSS
CVE-2023-4113MEDIUMwebappsphp04 ago 2023
PHP Jabbers Service Booking Script index.php cross site scripting
48RISCO
abrir
Exploit-DB
Shelly PRO 4PM v0.11.0 - Authentication Bypass
CVE-2023-33383remotehardware04 ago 2023
Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition t
23RISCO
abrir
Exploit-DB
PHPJabbers Cleaning Business 1.0 - Reflected XSS
CVE-2023-4115MEDIUMwebappsphp04 ago 2023
PHP Jabbers Cleaning Business index.php cross site scripting
48RISCO
abrir
Exploit-DB
Academy LMS 6.0 - Reflected XSS
CVE-2023-4119MEDIUMwebappsphp04 ago 2023
Academy LMS courses cross site scripting
33RISCO
abrir
Exploit-DB
PHPJabbers Night Club Booking 1.0 - Reflected XSS
CVE-2023-4114MEDIUMwebappsphp04 ago 2023
PHP Jabbers Night Club Booking Software index.php cross site scripting
48RISCO
abrir
Exploit-DB
PHPJabbers Rental Property Booking 2.0 - Reflected XSS
CVE-2023-4117MEDIUMwebappsphp04 ago 2023
PHP Jabbers Rental Property Booking index.php cross site scripting
33RISCO
abrir
Exploit-DB
PHPJabbers Taxi Booking 2.0 - Reflected XSS
CVE-2023-4116MEDIUMwebappsphp04 ago 2023
PHP Jabbers Taxi Booking index.php cross site scripting
48RISCO
abrir
Exploit-DB
WordPress Plugin Ninja Forms 3.6.25 - Reflected XSS
CVE-2023-37979HIGHwebappsphp04 ago 2023
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RISCO
abrir
Exploit-DB
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Event Access
CVE-2023-2796webappsphp04 ago 2023
EventON < 2.1.2 - Unauthenticated Event Access
50RISCO
abrir
Exploit-DB
PHPJabbers Shuttle Booking Software 1.0 - Reflected XSS
CVE-2023-4112MEDIUMwebappsphp04 ago 2023
PHP Jabbers Shuttle Booking Software index.php cross site scripting
48RISCO
abrir
Exploit-DB
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Post Access via IDOR
CVE-2023-3219webappsphp04 ago 2023
EventON < 2.1.2 - Unauthenticated Post Access via IDOR
38RISCO
abrir
Exploit-DBVexDay Proof
Uvdesk v1.1.3 - File Upload Remote Code Execution (RCE) (Authenticated)
CVE-2023-39147webappsphp31 jul 2023
An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafte
23RISCO
abrir
Exploit-DBVexDay Proof
RosarioSIS 10.8.4 - CSV Injection
CVE-2023-29918MEDIUMwebappsphp28 jul 2023
RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.
33RISCO
abrir
Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
CVE-2023-3844LOWwebappsphp28 jul 2023
mooSocial mooDating URL friends cross site scripting
43RISCO
abrir
Exploit-DBVexDay Proof
copyparty v1.8.6 - Reflected Cross Site Scripting (XSS)
CVE-2023-38501MEDIUMwebappspython28 jul 2023
copyparty vulnerable to reflected cross-site scripting via k304 parameter
48RISCO
abrir
Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
CVE-2023-3848LOWwebappsphp28 jul 2023
mooSocial mooDating URL view cross site scripting
43RISCO
abrir
Exploit-DB
Keeper Security desktop 16.10.2 & Browser Extension 16.5.4 - Password Dumping
CVE-2023-36266localmultiple28 jul 2023
An issue was discovered in Keeper Password Manager for Desktop version 16.10.2 (fixed in 17.2), and the KeeperFill Brows
23RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin AN_Gradebook 5.0.1 - SQLi
CVE-2023-2636webappsphp28 jul 2023
AN_GradeBook <= 5.0.1 - Subscriber+ SQLi
23RISCO
abrir
Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
CVE-2023-3847LOWwebappsphp28 jul 2023
mooSocial mooDating URL users cross site scripting
43RISCO
abrir
Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
CVE-2023-3843LOWwebappsphp28 jul 2023
mooSocial mooDating URL question cross site scripting
43RISCO
abrir
Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
CVE-2023-3849LOWwebappsphp28 jul 2023
mooSocial mooDating URL find-a-match cross site scripting
43RISCO
abrir
Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
CVE-2023-3846LOWwebappsphp28 jul 2023
mooSocial mooDating URL pages cross site scripting
43RISCO
abrir
Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
CVE-2023-3845LOWwebappsphp28 jul 2023
mooSocial mooDating URL ajax_invite cross site scripting
43RISCO
abrir
Exploit-DB
pfSense v2.7.0 - OS Command Injection
CVE-2023-27253webappsphp20 jul 2023
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attac
60RISCO
abrir
Exploit-DB
RWS WorldServer 11.7.3 - Session Token Enumeration
CVE-2023-38357webappsmultiple20 jul 2023
Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized a
23RISCO
abrir
Exploit-DB
Microsoft Office 365 Version 18.2305.1222.0 - Elevation of Privilege + RCE.
CVE-2023-33148HIGHremotemultiple20 jul 2023
Microsoft Office Elevation of Privilege Vulnerability
41RISCO
abrir
Exploit-DBVexDay Proof
Online Piggery Management System v1.0 - unauthenticated file upload vulnerability
CVE-2023-37629webappsphp19 jul 2023
Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by send
43RISCO
abrir
Exploit-DB
ABB FlowX v4.00 - Exposure of Sensitive Information
CVE-2023-1258MEDIUMwebappshardware19 jul 2023
Flow-X disclosure of sensitive information to unauthenticated users
33RISCO
abrir
Exploit-DB
Hikvision Hybrid SAN Ds-a71024 Firmware - Multiple Remote Code Execution
CVE-2022-28171HIGHremotehardware19 jul 2023
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to t
53RISCO
abrir
anteriorpágina 19 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.