Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
24.466 exploits
Exploit-DB
Nokia ASIKA 7.13.52 - Hard-coded private key disclosure
CVE-2023-25187MEDIUMremotehardware20 jun 2023
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures
33RISCO
abrir
Exploit-DB
WordPress Theme Medic v1.0.0 - Weak Password Recovery Mechanism for Forgotten Password
CVE-2020-11027MEDIUMwebappsphp19 jun 2023
Password reset links invalidation issue in WordPress
38RISCO
abrir
Exploit-DB
Symantec SiteMinder WebAgent v12.52 - Cross-site scripting (XSS)
CVE-2023-23956MEDIUMwebappshardware19 jun 2023
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
33RISCO
abrir
Exploit-DBVexDay Proof
PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
CVE-2023-0297CRITICALwebappspython14 jun 2023
Code Injection in pyload/pyload
85RISCO
abrir
Exploit-DB
Teachers Record Management System 1.0 - File Upload Type Validation
CVE-2023-3187MEDIUMwebappsphp13 jun 2023
PHPGurukul Teachers Record Management System Profile Picture changeimage.php unrestricted upload
33RISCO
abrir
Exploit-DBVexDay Proof
Sales Tracker Management System v1.0 - Multiple Vulnerabilities
CVE-2023-3184LOWwebappsphp13 jun 2023
SourceCodester Sales Tracker Management System cross site scripting
28RISCO
abrir
Exploit-DB
WordPress Theme Workreap 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
CVE-2021-24499webappsphp09 jun 2023
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISCO
abrir
Exploit-DB
Tree Page View Plugin 1.6.7 - Cross Site Scripting (XSS)
CVE-2023-30868HIGHwebappsphp06 jun 2023
WordPress CMS Tree Page View Plugin <= 1.6.7 is vulnerable to Cross Site Scripting (XSS)
56RISCO
abrir
Exploit-DB
STARFACE 7.3.0.10 - Authentication with Password Hash Possible
CVE-2023-33243HIGHwebappsjsp04 jun 2023
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the
41RISCO
abrir
Exploit-DB
File Manager Advanced Shortcode 2.3.2 - Unauthenticated Remote Code Execution (RCE)
CVE-2023-2068webappsphp04 jun 2023
File Manager Advanced Shortcode <= 2.3.2 - Unauthenticated Remote Code Execution through shortcode
50RISCO
abrir
Exploit-DB
Flexense HTTP Server 10.6.24 - Buffer Overflow (DoS) (Metasploit)
CVE-2018-8065remotemultiple31 mai 2023
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access v
60RISCO
abrir
Exploit-DBVexDay Proof
Online Security Guards Hiring System 1.0 - Reflected XSS
CVE-2023-0527LOWwebappsphp31 mai 2023
PHPGurukul Online Security Guards Hiring System search-request.php cross site scripting
43RISCO
abrir
Exploit-DB
unilogies/bumsys v1.0.3 beta - Unrestricted File Upload
CVE-2023-0455HIGHwebappsphp31 mai 2023
Unrestricted Upload of File with Dangerous Type in unilogies/bumsys
41RISCO
abrir
Exploit-DB
Pydio Cells 4.1.2 - Unauthorised Role Assignments
CVE-2023-32749HIGHwebappsgo31 mai 2023
Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying t
46RISCO
abrir
Exploit-DB
Pydio Cells 4.1.2 - Server-Side Request Forgery
CVE-2023-32750MEDIUMwebappsgo31 mai 2023
Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which
33RISCO
abrir
Exploit-DB
Pydio Cells 4.1.2 - Cross-Site Scripting (XSS) via File Download
CVE-2023-32751MEDIUMwebappsgo31 mai 2023
Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are genera
33RISCO
abrir
Exploit-DBVexDay Proof
Faculty Evaluation System 1.0 - Unauthenticated File Upload
CVE-2023-33440HIGHwebappsphp31 mai 2023
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_u
61RISCO
abrir
Exploit-DBVexDay Proof
Camaleon CMS v2.7.0 - Server-Side Template Injection (SSTI)
CVE-2023-30145CRITICALwebappsruby26 mai 2023
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para
60RISCO
abrir
Exploit-DB
Filmora 12 version ( Build 1.0.0.7) - Unquoted Service Paths Privilege Escalation
CVE-2023-31747HIGHlocalwindows25 mai 2023
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp
41RISCO
abrir
Exploit-DB
Seagate Central Storage 2015.0916 - Unauthenticated Remote Command Execution (Metasploit)
CVE-2020-6627CRITICALremotehardware25 mai 2023
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS comman
53RISCO
abrir
Exploit-DB
SCM Manager 1.60 - Cross-Site Scripting Stored (Authenticated)
CVE-2023-33829MEDIUMwebappsmultiple25 mai 2023
A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute
33RISCO
abrir
Exploit-DB
MobileTrans 4.0.11 - Weak Service Privilege Escalation
CVE-2023-31748HIGHlocalwindows23 mai 2023
Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the exe
41RISCO
abrir
Exploit-DB
Optoma 1080PSTX Firmware C02 - Authentication Bypass
CVE-2023-27823CRITICALremotehardware23 mai 2023
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid cr
60RISCO
abrir
Exploit-DB
Yank Note v3.52.1 (Electron) - Arbitrary Code Execution
CVE-2023-31874HIGHlocalmultiple23 mai 2023
Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_pro
41RISCO
abrir
Exploit-DBVexDay Proof
GetSimple CMS v3.3.16 - Remote Code Execution (RCE)
CVE-2022-41544HIGHwebappsphp23 mai 2023
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file paramete
46RISCO
abrir
Exploit-DB
Webkul Qloapps 1.5.2 - Cross-Site Scripting (XSS)
CVE-2023-30256MEDIUMwebappsphp23 mai 2023
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive informat
48RISCO
abrir
Exploit-DB
FusionInvoice 2023-1.0 - Stored XSS (Cross-Site Scripting)
CVE-2023-25439MEDIUMwebappsmultiple23 mai 2023
Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitr
33RISCO
abrir
Exploit-DB
PnPSCADA v2.x - Unauthenticated PostgreSQL Injection
CVE-2023-1934CRITICALwebappshardware23 mai 2023
The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL
48RISCO
abrir
Exploit-DB
eScan Management Console 14.0.1400.2281 - Cross Site Scripting
CVE-2023-31703CRITICALwebappswindows23 mai 2023
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allo
48RISCO
abrir
Exploit-DB
Apache Superset 2.0.0 - Authentication Bypass
CVE-2023-27524HIGHsob ataquewebappsmultiple23 mai 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir
anteriorpágina 21 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.