Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.081exploits catalogados
38.339CVEs com exploração pública
24.695testados em laboratório
82.081 exploits
Metasploit600
Judge0 sandbox escape
CVE-2024-28185CRITICAL04 mar 2024
Judge0 vulnerable to Sandbox Escape via Symbolic Link
43RISCO
abrir ↗
Metasploit600
pgAdmin Session Deserialization RCE
CVE-2024-2044CRITICAL04 mar 2024
Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4
65RISCO
abrir ↗
Metasploit600
JetBrains TeamCity Unauthenticated Remote Code Execution
CVE-2024-27198CRITICALsob ataqueransomware04 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗
Metasploit600
Judge0 sandbox escape
CVE-2024-28189CRITICAL04 mar 2024
Judge0 vulnerable to Sandbox Escape Patch Bypass via chown running on Symbolic Link
43RISCO
abrir ↗
GitHub PoC★ 3
CVE-2024-1071 with Docker
CVE-2024-1071CRITICAL04 mar 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque04 mar 2024
Grafana path traversal
100RISCO
abrir ↗
Exploit-DB
Petrol Pump Management Software v1.0 - 'Address' Stored Cross Site Scripting
CVE-2024-27743MEDIUMremotephp03 mar 2024
Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code
33RISCO
abrir ↗
Exploit-DB
Petrol Pump Management Software v.1.0 - SQL Injection
CVE-2024-27746CRITICALremotephp03 mar 2024
SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a c
53RISCO
abrir ↗
Exploit-DB
Petrol Pump Management Software v1.0 - Remote Code Execution via File Upload
CVE-2024-27747CRITICALremotephp03 mar 2024
File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a cra
53RISCO
abrir ↗
Exploit-DB
Petrol Pump Management Software v.1.0 - Stored Cross Site Scripting via SVG file
CVE-2024-27744MEDIUMremotephp03 mar 2024
Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code
33RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-2437CRITICAL02 mar 2024
UserPro <= 5.1.1 - Authentication Bypass to Administrator
63RISCO
abrir ↗
GitHub PoC
RxRCoder/CVE-2023-2437
CVE-2023-2437CRITICAL02 mar 2024
UserPro <= 5.1.1 - Authentication Bypass to Administrator
63RISCO
abrir ↗
GitHub PoC★ 2
PoC for CVE-2024-1512 in MasterStudy LMS WordPress Plugin.
CVE-2024-1512CRITICAL01 mar 2024
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL01 mar 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2023-48084—01 mar 2024
Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.
50RISCO
abrir ↗
GitHub PoC★ 2
abian2/CVE-2024-23652
CVE-2024-23652CRITICAL01 mar 2024
BuildKit possible host system access from mount stub cleaner
48RISCO
abrir ↗
GitHub PoC★ 3
(Mirorring)
CVE-2024-1651CRITICAL29 fev 2024
Torrentpier 2.4.1 - RCE
60RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2024-21413CRITICALsob ataque29 fev 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 2
dshabani96/CVE-2024-21413
CVE-2024-21413CRITICALsob ataque29 fev 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir ↗
GitHub PoC
letsr00t/CVE-2023-0386
CVE-2023-0386HIGHsob ataque29 fev 2024
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL29 fev 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗
VulnCheck XDB
local
CVE-2023-2640HIGH29 fev 2024
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RISCO
abrir ↗
GitHub PoC★ 3
(Mirorring)
CVE-2024-25600CRITICAL29 fev 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗
GitHub PoC
J3Ss0u/CVE-2023-41993
CVE-2023-41993HIGHsob ataque28 fev 2024
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-41993HIGHsob ataque28 fev 2024
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-21762CRITICALsob ataqueransomware28 fev 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir ↗
GitHub PoC★ 107
Safely detect whether a FortiGate SSL VPN is vulnerable to CVE-2024-21762
CVE-2024-21762CRITICALsob ataqueransomware28 fev 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir ↗
GitHub PoC★ 2
jakabakos/CVE-2023-39362-cacti-snmp-command-injection-poc
CVE-2023-39362HIGH28 fev 2024
Authenticated command injection in SNMP options of a Device
63RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-40000HIGH28 fev 2024
WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability
68RISCO
abrir ↗
GitHub PoC★ 6
CVE-2024-23334
CVE-2024-23334MEDIUM28 fev 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir ↗
← anteriorpágina 490 / 2.737próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.