Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.202exploits catalogados
38.443CVEs com exploração pública
24.695testados em laboratório
82.202 exploits
GitHub PoC
CVE-2023-27524
CVE-2023-27524HIGHsob ataque30 out 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir ↗
GitHub PoC
longitudes de código para desencadenar esta vulnerabilidad
CVE-2023-41064HIGHsob ataque30 out 2023
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1
83RISCO
abrir ↗
GitHub PoC★ 3
Joomla Unauthorized Access Vulnerability
CVE-2023-23752MEDIUMsob ataque30 out 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-50917—29 out 2023
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE:
50RISCO
abrir ↗
GitHub PoC
Demonstration of CVE-2022-31692 authorization bypass in Spring Security
CVE-2022-31692CRITICAL29 out 2023
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass v
48RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-4966CRITICALsob ataqueransomware29 out 2023
Unauthenticated sensitive information disclosure
100RISCO
abrir ↗
GitHub PoC★ 10
An Exploitation script developed to exploit the CVE-2023-4966 bleed citrix information disclosure vulnerability
CVE-2023-4966CRITICALsob ataqueransomware29 out 2023
Unauthenticated sensitive information disclosure
100RISCO
abrir ↗
GitHub PoC
CVE-2009-3103 ms09-050
CVE-2009-3103—29 out 2023
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISCO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2009-3103—29 out 2023
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISCO
abrir ↗
GitHub PoC
detect bruteforce using for cve-2021-34527
CVE-2021-34527HIGHsob ataqueransomware28 out 2023
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 5
Parse citrix netscaler logs to check for signs of CVE-2023-4966 exploitation
CVE-2023-4966CRITICALsob ataqueransomware28 out 2023
Unauthenticated sensitive information disclosure
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2023-4911HIGHsob ataque28 out 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
98RISCO
abrir ↗
GitHub PoC★ 2
CVE-2023-33246 - Apache RocketMQ config RCE
CVE-2023-33246CRITICALsob ataque28 out 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir ↗
GitHub PoC★ 8
Proof of concept for CVE-2023-4911 (Looney Tunables) discovered by Qualys Threat Research Unit
CVE-2023-4911HIGHsob ataque28 out 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
98RISCO
abrir ↗
GitHub PoC
nhuynhuy/cve-2017-11882
CVE-2017-11882HIGHsob ataqueransomware28 out 2023
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALsob ataque28 out 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗
GitHub PoC
This is a POC for CVE-2022-22963
CVE-2022-22963CRITICALsob ataque28 out 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗
GitHub PoC★ 8
MosaedH/CVE-2022-32548-RCE-POC
CVE-2022-32548CRITICAL27 out 2023
An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin
60RISCO
abrir ↗
GitHub PoC★ 1
CVE-2023-22515
CVE-2023-22515CRITICALsob ataqueransomware27 out 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-4966CRITICALsob ataqueransomware27 out 2023
Unauthenticated sensitive information disclosure
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALsob ataqueransomware27 out 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir ↗
GitHub PoC
CVE-2023-4966 - NetScaler ADC and NetScaler Gateway Memory Leak Exploit
CVE-2023-4966CRITICALsob ataqueransomware27 out 2023
Unauthenticated sensitive information disclosure
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALsob ataqueransomware27 out 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-3519CRITICALsob ataqueransomware27 out 2023
Unauthenticated remote code execution
100RISCO
abrir ↗
Metasploit600
Apache ActiveMQ Unauthenticated Remote Code Execution
CVE-2023-46604CRITICALsob ataqueransomware27 out 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir ↗
GitHub PoC★ 5
Stack-Overflow on Citrix
CVE-2023-3519CRITICALsob ataqueransomware27 out 2023
Unauthenticated remote code execution
100RISCO
abrir ↗
Metasploit600
Vinchin Backup and Recovery Command Injection
CVE-2023-45498CRITICAL26 out 2023
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability
68RISCO
abrir ↗
Metasploit600
F5 BIG-IP TMUI AJP Smuggling RCE
CVE-2023-46747CRITICALsob ataqueransomware26 out 2023
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISCO
abrir ↗
GitHub PoC
katseyres2/CVE-2021-43798
CVE-2021-43798HIGHsob ataque26 out 2023
Grafana path traversal
100RISCO
abrir ↗
Metasploit600
Vinchin Backup and Recovery Command Injection
CVE-2023-45499—26 out 2023
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.
18RISCO
abrir ↗
← anteriorpágina 526 / 2.741próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.