Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.122exploits catalogados
38.377CVEs com exploração pública
24.695testados em laboratório
82.122 exploits
GitHub PoC★ 6
itsgiddd/CVE-2023-41991
CVE-2023-41991MEDIUMsob ataque28 nov 2023
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A mal
68RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2022-30190HIGHsob ataqueransomware28 nov 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir ↗
Metasploit600
Chamilo v1.11.24 Unrestricted File Upload PHP Webshell
CVE-2023-4220HIGH28 nov 2023
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗
Metasploit300
Control iD iDSecure Authentication Bypass (CVE-2023-6329)
CVE-2023-6329CRITICAL27 nov 2023
Control iD iDSecure passwordCustom Authentication Bypass
75RISCO
abrir ↗
GitHub PoC
- using python to detect cve-2017-8464 vulnerbilities
CVE-2017-8464HIGHsob ataque27 nov 2023
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-4966CRITICALsob ataqueransomware27 nov 2023
Unauthenticated sensitive information disclosure
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware27 nov 2023
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗
GitHub PoC
Programm to exploit a range of ip adresses
CVE-2023-4966CRITICALsob ataqueransomware27 nov 2023
Unauthenticated sensitive information disclosure
100RISCO
abrir ↗
GitHub PoC
edsonjt81/CVE-2023-22515-Scan.
CVE-2023-22515CRITICALsob ataqueransomware26 nov 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISCO
abrir ↗
GitHub PoC
elsvital/cve-2022-33891-fix
CVE-2022-33891HIGHsob ataque26 nov 2023
Apache Spark shell command injection vulnerability via Spark UI
100RISCO
abrir ↗
GitHub PoC★ 1
https://github.com/AbelChe/evil_minio/tree/main 打包留存
CVE-2023-28432HIGHsob ataque26 nov 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir ↗
GitHub PoC
working exploit for CVE-2019-9053
CVE-2019-9053—26 nov 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-38646—25 nov 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISCO
abrir ↗
GitHub PoC★ 1
Exploit forCVE-2020-29607
CVE-2020-29607—24 nov 2023
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-2033HIGHsob ataque24 nov 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISCO
abrir ↗
GitHub PoC★ 1
Exploit for CVE-2022-46169
CVE-2022-46169CRITICALsob ataque23 nov 2023
Unauthenticated Command Injection
100RISCO
abrir ↗
Metasploit600
WordPress Royal Elementor Addons RCE
CVE-2023-5360—23 nov 2023
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALsob ataque23 nov 2023
Unauthenticated Command Injection
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-49103CRITICALsob ataque22 nov 2023
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RISCO
abrir ↗
GitHub PoC★ 30
PoC for the CVE-2023-49103
CVE-2023-49103CRITICALsob ataque22 nov 2023
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RISCO
abrir ↗
GitHub PoC★ 2
A1Lin/cve-2022-1364
CVE-2022-1364HIGHsob ataque22 nov 2023
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit
76RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2022-1364HIGHsob ataque22 nov 2023
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit
76RISCO
abrir ↗
GitHub PoC
exploit for cve-2023-47246 SysAid RCE (shell upload)
CVE-2023-47246CRITICALsob ataqueransomware22 nov 2023
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a f
100RISCO
abrir ↗
GitHub PoC
By passing an overly large string when invoking nethack, it is possible to corrupt memory. jnethack and falconseye are also prone to this vulnerability.
CVE-2003-0358—22 nov 2023
Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allow
23RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-47246CRITICALsob ataqueransomware22 nov 2023
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a f
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque21 nov 2023
Grafana path traversal
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware21 nov 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗
Metasploit300
ownCloud Phpinfo Reader
CVE-2023-49103CRITICALsob ataque21 nov 2023
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RISCO
abrir ↗
GitHub PoC
Firewall rules to mitigate a zero-day vulnerability malware attack (CVE-2022-22965), known as Spring4Shell
CVE-2022-22965CRITICALsob ataque21 nov 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗
GitHub PoC
Iris288/CVE-2021-43798
CVE-2021-43798HIGHsob ataque21 nov 2023
Grafana path traversal
100RISCO
abrir ↗
← anteriorpágina 519 / 2.738próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.