Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
24.466 exploits
Exploit-DB
WinterCMS < 1.2.3 - Persistent Cross-Site Scripting
CVE-2023-37269LOWwebappsphp15 jul 2023
Winter CMS vulnerable to stored XSS through privileged upload of SVG file
28RISCO
abrir
Exploit-DB
Cisco UCS-IMC Supervisor 2.2.0.0 - Authentication Bypass
CVE-2019-1937CRITICALwebappshardware15 jul 2023
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Authentication Bypass Vulnerability
85RISCO
abrir
Exploit-DB
Icinga Web 2.10 - Authenticated Remote Code Execution
CVE-2022-24715HIGHwebappsphp15 jul 2023
Arbitrary code execution for authenticated users in Icinga Web 2
46RISCO
abrir
Exploit-DB
BuildaGate5library v5 - Reflected Cross-Site Scripting (XSS)
CVE-2023-36163webappsphp11 jul 2023
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code
23RISCO
abrir
Exploit-DB
Game Jackal Server v5 - Unquoted Service Path _GJServiceV5_
CVE-2023-36166localwindows11 jul 2023
20RISCO
abrir
Exploit-DB
MiniTool Partition Wizard ShadowMaker v.12.7 - Unquoted Service Path _MTAgentService_
CVE-2023-36164localwindows11 jul 2023
20RISCO
abrir
Exploit-DB
MiniTool Partition Wizard ShadowMaker v.12.7 - Unquoted Service Path _MTSchedulerService_
CVE-2023-36165localwindows11 jul 2023
20RISCO
abrir
Exploit-DB
AVG Anti Spyware 7.5 - Unquoted Service Path _AVG Anti-Spyware Guard_
CVE-2023-36167localwindows11 jul 2023
20RISCO
abrir
Exploit-DB
Spring Cloud 3.2.2 - Remote Command Execution (RCE)
CVE-2022-22963CRITICALsob ataquewebappsjava11 jul 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
Exploit-DB
Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution
CVE-2022-21907CRITICALremotewindows07 jul 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir
Exploit-DB
Microsoft Outlook Microsoft 365 MSO (Version 2306 Build 16.0.16529.20100) 32-bit - Remote Code Execution
CVE-2023-33131HIGHremotemultiple07 jul 2023
Microsoft Outlook Remote Code Execution Vulnerability
41RISCO
abrir
Exploit-DB
Lost and Found Information System v1.0 - SQL Injection
CVE-2023-33592webappsphp06 jul 2023
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RISCO
abrir
Exploit-DB
Microsoft Edge 114.0.1823.67 (64-bit) - Information Disclosure
CVE-2023-33145MEDIUMlocalmultiple06 jul 2023
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
33RISCO
abrir
Exploit-DB
Sales of Cashier Goods v1.0 - Cross Site Scripting (XSS)
CVE-2023-36346webappsphp03 jul 2023
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parame
38RISCO
abrir
Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 32-bit - Remote Code Execution (RCE)
CVE-2023-33137HIGHremotemultiple03 jul 2023
Microsoft Excel Remote Code Execution Vulnerability
41RISCO
abrir
Exploit-DB
FuguHub 8.1 - Remote Code Execution
CVE-2023-24078HIGHwebappsmultiple03 jul 2023
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RISCO
abrir
Exploit-DB
POS Codekop v2.0 - Authenticated Remote Code Execution (RCE)
CVE-2023-36348webappsphp03 jul 2023
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename p
23RISCO
abrir
Exploit-DB
TP-Link TL-WR940N V4 - Buffer OverFlow
CVE-2023-36355doshardware03 jul 2023
TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6Cfg
35RISCO
abrir
Exploit-DB
WP AutoComplete 1.0.4 - Unauthenticated SQLi
CVE-2022-4297CRITICALwebappsphp03 jul 2023
WP AutoComplete Search <= 1.0.4 - Unauthenticated SQLi
48RISCO
abrir
Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit - Remote Code Execution (RCE)
CVE-2023-28285HIGHremotemultiple03 jul 2023
Microsoft Office Remote Code Execution Vulnerability
41RISCO
abrir
Exploit-DB
Azure Apache Ambari 2302250400 - Spoofing
CVE-2023-23408MEDIUMremotemultiple26 jun 2023
Azure Apache Ambari Spoofing Vulnerability
33RISCO
abrir
Exploit-DB
Windows 11 22h2 - Kernel Privilege Elevation
CVE-2023-28293HIGHlocalwindows26 jun 2023
Windows Kernel Elevation of Privilege Vulnerability
41RISCO
abrir
Exploit-DB
PrestaShop Winbiz Payment module - Improper Limitation of a Pathname to a Restricted Directory
CVE-2023-30198HIGHwebappsphp26 jun 2023
Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download
41RISCO
abrir
Exploit-DB
Microsoft SharePoint Enterprise Server 2016 - Spoofing
CVE-2023-28288HIGHwebappsmultiple26 jun 2023
Microsoft SharePoint Server Spoofing Vulnerability
41RISCO
abrir
Exploit-DB
NCH Express Invoice - Clear Text Password Storage and Account Takeover
CVE-2020-11560localwindows23 jun 2023
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
23RISCO
abrir
Exploit-DB
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
CVE-2022-47075HIGHwebappsaspx22 jun 2023
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the
68RISCO
abrir
Exploit-DB
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
CVE-2022-47076HIGHwebappsaspx22 jun 2023
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via Display
41RISCO
abrir
Exploit-DBVexDay Proof
SPIP v4.2.0 - Remote Code Execution (Unauthenticated)
CVE-2023-27372CRITICALwebappsphp20 jun 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
Exploit-DB
WP Sticky Social 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting (XSS)
CVE-2023-3320MEDIUMwebappsphp20 jun 2023
The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,
33RISCO
abrir
Exploit-DB
Nokia ASIKA 7.13.52 - Hard-coded private key disclosure
CVE-2023-25187MEDIUMremotehardware20 jun 2023
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures
33RISCO
abrir
anteriorpágina 20 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.