Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
24.466 exploits
Exploit-DB
Webkul Qloapps 1.5.2 - Cross-Site Scripting (XSS)
CVE-2023-30256MEDIUMwebappsphp23 mai 2023
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive informat
48RISCO
abrir
Exploit-DB
Gin Markdown Editor v0.7.4 (Electron) - Arbitrary Code Execution
CVE-2023-31873HIGHlocalmultiple23 mai 2023
Gin 0.7.4 allows execution of arbitrary code when a crafted file is opened, e.g., via require('child_process').
41RISCO
abrir
Exploit-DB
Apache Superset 2.0.0 - Authentication Bypass
CVE-2023-27524HIGHsob ataquewebappsmultiple23 mai 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir
Exploit-DB
Optoma 1080PSTX Firmware C02 - Authentication Bypass
CVE-2023-27823CRITICALremotehardware23 mai 2023
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid cr
60RISCO
abrir
Exploit-DB
PaperCut NG/MG 22.0.4 - Remote Code Execution (RCE)
CVE-2023-27350CRITICALsob ataqueransomwarewebappsmultiple23 mai 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
Exploit-DB
eScan Management Console 14.0.1400.2281 - SQL Injection (Authenticated)
CVE-2023-31702HIGHwebappswindows23 mai 2023
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to d
41RISCO
abrir
Exploit-DB
FLEX 1080 < 1085 Web 1.6.0 - Denial of Service
CVE-2022-2591HIGHdosandroid13 mai 2023
TEM FLEX-1085 reboot denial of service
41RISCO
abrir
Exploit-DB
Jedox 2020.2.5 - Stored Cross-Site Scripting in Log-Module
CVE-2022-47877CRITICALwebappsphp05 mai 2023
A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web
48RISCO
abrir
Exploit-DB
Jedox 2020.2.5 - Remote Code Execution via Configurable Storage Path
CVE-2022-47878CRITICALwebappsphp05 mai 2023
Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authentica
60RISCO
abrir
Exploit-DB
Jedox 2022.4.2 - Code Execution via RPC Interfaces
CVE-2022-47879HIGHwebappsphp05 mai 2023
A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load a
41RISCO
abrir
Exploit-DBVexDay Proof
Online Pizza Ordering System v1.0 - Unauthenticated File Upload
CVE-2023-2246MEDIUMwebappsphp05 mai 2023
SourceCodester Online Pizza Ordering System unrestricted upload
33RISCO
abrir
Exploit-DB
Jedox 2022.4.2 - Remote Code Execution via Directory Traversal
CVE-2022-47875HIGHwebappsphp05 mai 2023
A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to ex
46RISCO
abrir
Exploit-DB
Jedox 2020.2.5 - Disclosure of Database Credentials via Improper Access Controls
CVE-2022-47874MEDIUMwebappsphp05 mai 2023
Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of dat
38RISCO
abrir
Exploit-DB
Jedox 2020.2.5 - Remote Code Execution via Executable Groovy-Scripts
CVE-2022-47876CRITICALwebappsphp05 mai 2023
The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code v
48RISCO
abrir
Exploit-DB
Jedox 2022.4.2 - Disclosure of Database Credentials via Connection Checks
CVE-2022-47880MEDIUMwebappsphp05 mai 2023
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users wi
33RISCO
abrir
Exploit-DB
MilleGPG5 5.9.2 (Gennaio 2023) - Local Privilege Escalation / Incorrect Access Control
CVE-2023-25438HIGHlocalwindows02 mai 2023
An issue was discovered in Genomedics MilleGP5 5.9.2, allows remote attackers to execute arbitrary code and gain escalat
41RISCO
abrir
Exploit-DB
FS-S3900-24T4S - Privilege Escalation
CVE-2023-30350HIGHlocalhardware02 mai 2023
FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin
41RISCO
abrir
Exploit-DB
KodExplorer 4.49 - CSRF to Arbitrary File Upload
CVE-2022-4944MEDIUMwebappsphp25 abr 2023
kalcaddle KodExplorer cross-site request forgery
33RISCO
abrir
Exploit-DB
PaperCut NG/MG 22.0.4 - Authentication Bypass
CVE-2023-27350CRITICALsob ataqueransomwarewebappsmultiple25 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
Exploit-DB
Sophos Web Appliance 4.3.10.4 - Pre-auth command injection
CVE-2023-1671CRITICALsob ataquewebappsphp25 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISCO
abrir
Exploit-DBVexDay Proof
Bang Resto v1.0 - Stored Cross-Site Scripting (XSS)
CVE-2023-29848MEDIUMwebappsphp20 abr 2023
Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in
33RISCO
abrir
Exploit-DB
Linux Kernel 6.2 - Userspace Processes To Enable Mitigation
CVE-2023-1998MEDIUMlocallinux20 abr 2023
Spectre v2 SMT mitigations problem in Linux kernel
33RISCO
abrir
Exploit-DB
GDidees CMS 3.9.1 - Local File Disclosure
CVE-2023-27179HIGHwebappsphp20 abr 2023
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename paramet
68RISCO
abrir
Exploit-DBVexDay Proof
Bang Resto v1.0 - 'Multiple' SQL Injection
CVE-2023-29849HIGHwebappsphp20 abr 2023
Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice
41RISCO
abrir
Exploit-DB
File Replication Pro 7.5.0 - Privilege Escalation/Password reset due Incorrect Access Control
CVE-2023-26918CRITICALlocalwindows20 abr 2023
Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan
48RISCO
abrir
Exploit-DB
Microsoft Word 16.72.23040900 - Remote Code Execution (RCE)
CVE-2023-28311HIGHremotemultiple20 abr 2023
Microsoft Word Remote Code Execution Vulnerability
41RISCO
abrir
Exploit-DB
Online Computer and Laptop Store 1.0 - Remote Code Execution (RCE)
CVE-2023-1826MEDIUMwebappsphp10 abr 2023
SourceCodester Online Computer and Laptop Store index.php unrestricted upload
33RISCO
abrir
Exploit-DB
Paradox Security Systems IPR512 - Denial Of Service
CVE-2023-24709HIGHdoshardware10 abr 2023
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and l
53RISCO
abrir
Exploit-DB
Microsoft Edge (Chromium-based) Webview2 1.0.1661.34 - Spoofing
CVE-2023-24892HIGHlocalmultiple10 abr 2023
Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
41RISCO
abrir
Exploit-DB
FortiRecorder 6.4.3 - Denial of Service
CVE-2022-41333MEDIUMdoshardware08 abr 2023
An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below
33RISCO
abrir
anteriorpágina 22 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.