Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.081exploits catalogados
38.339CVEs com exploração pública
24.695testados em laboratório
82.081 exploits
VulnCheck XDB
infoleak
CVE-2024-1071CRITICAL18 mar 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISCO
abrir ↗
GitHub PoC★ 12
The PoC demonstrates the potential for remote code execution by exploiting the identified security flaw.
CVE-2024-21762CRITICALsob ataqueransomware17 mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir ↗
GitHub PoC★ 7
jakabakos/CVE-2023-43208-mirth-connect-rce-poc
CVE-2023-43208CRITICALsob ataqueransomware17 mar 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir ↗
GitHub PoC★ 4
sxyrxyy/aiohttp-exploit-CVE-2024-23334-certstream
CVE-2024-23334MEDIUM17 mar 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALsob ataqueransomware17 mar 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-21762CRITICALsob ataqueransomware17 mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir ↗
Metasploit600
RaspberryMatic unauthenticated Remote Code Execution vulnerability through HMServer File Upload.
CVE-2024-24578CRITICAL16 mar 2024
RaspberryMatic Unauthenticated Remote Code Execution vulnerability through HMServer File Upload
43RISCO
abrir ↗
Metasploit600
OpenMetadata authentication bypass and SpEL injection exploit chain
CVE-2024-28254HIGH15 mar 2024
SpEL Injection in `GET /api/v1/events/subscriptions/validation/condition/<expr>` in OpenMetadata
48RISCO
abrir ↗
GitHub PoC★ 29
A PoC exploit for CVE-2023-43208 - Mirth Connect Remote Code Execution (RCE)
CVE-2023-43208CRITICALsob ataqueransomware15 mar 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir ↗
Metasploit600
OpenMetadata authentication bypass and SpEL injection exploit chain
CVE-2024-28255CRITICAL15 mar 2024
Authentication Bypass in OpenMetadata
85RISCO
abrir ↗
GitHub PoC
This is a potentially vulnerable Java web application containing Log4j affected by log4shell(CVE-2021-44228).
CVE-2021-44228CRITICALsob ataqueransomware15 mar 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALsob ataqueransomware15 mar 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2024-21626HIGH15 mar 2024
runc container breakout through process.cwd trickery and leaked fds
61RISCO
abrir ↗
GitHub PoC★ 3
Exploit for Open eClass – CVE-2024-26503: Unrestricted File Upload Leads to Remote Code Execution
CVE-2024-26503CRITICAL15 mar 2024
Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to
48RISCO
abrir ↗
GitHub PoC
exploit for f5-big-ip RCE cve-2023-46747
CVE-2023-46747CRITICALsob ataqueransomware15 mar 2024
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-44228CRITICALsob ataqueransomware15 mar 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗
Exploit-DB
Viessmann Vitogate 300 2.1.3.0 - Remote Code Execution (RCE)
CVE-2023-5222MEDIUMremotehardware14 mar 2024
Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
70RISCO
abrir ↗
Exploit-DB
JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE)
CVE-2023-42793CRITICALsob ataqueransomwareremotejava14 mar 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir ↗
GitHub PoC
A CLI tool for detecting CVE-2023-20048 vulnerability in Cisco Firepower Management Center.
CVE-2023-20048CRITICAL14 mar 2024
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authent
53RISCO
abrir ↗
Exploit-DB
KiTTY 0.76.1.13 - Command Injection
CVE-2024-23749HIGHlocalwindows14 mar 2024
KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insuffic
41RISCO
abrir ↗
Exploit-DB
Viessmann Vitogate 300 2.1.3.0 - Remote Code Execution (RCE)
CVE-2023-5702MEDIUMremotehardware14 mar 2024
Viessmann Vitogate 300 direct request
38RISCO
abrir ↗
Exploit-DB
SolarView Compact 6.00 - Command Injection
CVE-2023-23333CRITICALremotehardware14 mar 2024
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISCO
abrir ↗
Metasploit600
Ghostscript Command Execution via Format String
CVE-2024-29510MEDIUM14 mar 2024
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with
33RISCO
abrir ↗
Exploit-DB
Honeywell PM43 < P10.19.050004 - Remote Code Execution (RCE)
CVE-2023-3710CRITICALremotehardware14 mar 2024
Printer web page invalid command execution
75RISCO
abrir ↗
Exploit-DB
KiTTY 0.76.1.13 - 'Start Duplicated Session Username' Buffer Overflow
CVE-2024-25004HIGHlocalwindows14 mar 2024
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insuf
41RISCO
abrir ↗
Exploit-DB
KiTTY 0.76.1.13 - 'Start Duplicated Session Hostname' Buffer Overflow
CVE-2024-25003HIGHlocalwindows14 mar 2024
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insuf
41RISCO
abrir ↗
GitHub PoC
manrop2702/CVE-2020-7961
CVE-2020-7961CRITICALsob ataque14 mar 2024
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-33246CRITICALsob ataque14 mar 2024
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir ↗
Exploit-DB
GitLab CE/EE < 16.7.2 - Password Reset
CVE-2023-7028CRITICALsob ataqueremotejava14 mar 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISCO
abrir ↗
GitHub PoC★ 16
Chequea si tu firewall es vulnerable a CVE-2024-21762 (RCE sin autenticación)
CVE-2024-21762CRITICALsob ataqueransomware13 mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir ↗
← anteriorpágina 487 / 2.737próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.