Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.252exploits catalogados
38.481CVEs com exploração pública
24.695testados em laboratório
82.252 exploits
GitHub PoC
Vulnerable environment of CVE-2020-17530 (S2-061) for testing
CVE-2020-17530CRITICALsob ataque04 ago 2023
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir ↗
GitHub PoC★ 4
Remote Unauthenticated API Access Vulnerability in MobileIron Core 11.2 and older
CVE-2023-35082CRITICALsob ataqueransomware04 ago 2023
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RISCO
abrir ↗
Exploit-DB
Shelly PRO 4PM v0.11.0 - Authentication Bypass
CVE-2023-33383—remotehardware04 ago 2023
Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition t
23RISCO
abrir ↗
Exploit-DB
PHPJabbers Night Club Booking 1.0 - Reflected XSS
CVE-2023-4114MEDIUMwebappsphp04 ago 2023
PHP Jabbers Night Club Booking Software index.php cross site scripting
48RISCO
abrir ↗
GitHub PoC
Vulnerable environment of CVE-2013-2251 (S2-016) for testing
CVE-2013-2251CRITICALsob ataque04 ago 2023
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RISCO
abrir ↗
Exploit-DB
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Post Access via IDOR
CVE-2023-3219—webappsphp04 ago 2023
EventON < 2.1.2 - Unauthenticated Post Access via IDOR
38RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-35082CRITICALsob ataqueransomware04 ago 2023
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RISCO
abrir ↗
Metasploit600
LG Simple Editor Command Injection (CVE-2023-40504)
CVE-2023-40504CRITICAL04 ago 2023
LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability
65RISCO
abrir ↗
GitHub PoC
Vulnerable environment of CVE-2013-2251 (S2-016) for testing
CVE-2013-2251CRITICALsob ataque04 ago 2023
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RISCO
abrir ↗
Exploit-DB
Academy LMS 6.0 - Reflected XSS
CVE-2023-4119MEDIUMwebappsphp04 ago 2023
Academy LMS courses cross site scripting
33RISCO
abrir ↗
Exploit-DB
PHPJabbers Shuttle Booking Software 1.0 - Reflected XSS
CVE-2023-4112MEDIUMwebappsphp04 ago 2023
PHP Jabbers Shuttle Booking Software index.php cross site scripting
48RISCO
abrir ↗
GitHub PoC★ 2
CVE-2023-37979 PoC and Checker
CVE-2023-37979HIGH04 ago 2023
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RISCO
abrir ↗
GitHub PoC
# Exploit Title: Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated) # Date: 13.03.2022 # Exploit Author: Ashish Koli (Shikari) # Vendor Homepage: https://github.com/pluck-cms/pluck # Version: 4.7.16 # Tested on Ubuntu 20.04.3 LTS # CVE: CVE-2022-26965
CVE-2022-26965—04 ago 2023
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remot
35RISCO
abrir ↗
Exploit-DB
PHPJabbers Service Booking Script 1.0 - Reflected XSS
CVE-2023-4113MEDIUMwebappsphp04 ago 2023
PHP Jabbers Service Booking Script index.php cross site scripting
48RISCO
abrir ↗
Exploit-DB
PHPJabbers Rental Property Booking 2.0 - Reflected XSS
CVE-2023-4117MEDIUMwebappsphp04 ago 2023
PHP Jabbers Rental Property Booking index.php cross site scripting
33RISCO
abrir ↗
Exploit-DB
PHPJabbers Taxi Booking 2.0 - Reflected XSS
CVE-2023-4116MEDIUMwebappsphp04 ago 2023
PHP Jabbers Taxi Booking index.php cross site scripting
48RISCO
abrir ↗
Exploit-DB
PHPJabbers Cleaning Business 1.0 - Reflected XSS
CVE-2023-4115MEDIUMwebappsphp04 ago 2023
PHP Jabbers Cleaning Business index.php cross site scripting
48RISCO
abrir ↗
Exploit-DB
WordPress Plugin Ninja Forms 3.6.25 - Reflected XSS
CVE-2023-37979HIGHwebappsphp04 ago 2023
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RISCO
abrir ↗
Exploit-DB
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Event Access
CVE-2023-2796—webappsphp04 ago 2023
EventON < 2.1.2 - Unauthenticated Event Access
50RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-38646—03 ago 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISCO
abrir ↗
GitHub PoC
overgrowncarrot1/DejaVu-CVE-2021-22205
CVE-2021-22205CRITICALsob ataqueransomware02 ago 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir ↗
GitHub PoC★ 4
Exploit CVE-2021-41773 and CVE-2021-42013
CVE-2021-41773HIGHsob ataqueransomware02 ago 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
GitHub PoC★ 1
CVE-2020-0688 modified exploit for Exchange 2010
CVE-2020-0688HIGHsob ataqueransomware02 ago 2023
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2020-25213CRITICALsob ataque02 ago 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALsob ataqueransomware02 ago 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHsob ataqueransomware02 ago 2023
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir ↗
GitHub PoC
726232111/CVE-2023-28252
CVE-2023-28252HIGHsob ataqueransomware02 ago 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISCO
abrir ↗
GitHub PoC★ 3
Python Interactive Exploit for WP File Manager Vulnerability. The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension.
CVE-2020-25213CRITICALsob ataque02 ago 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir ↗
GitHub PoC★ 1
asepsaepdin/CVE-2010-1240
CVE-2010-1240—02 ago 2023
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISCO
abrir ↗
GitHub PoC★ 64
mistymntncop/CVE-2023-2033
CVE-2023-2033HIGHsob ataque02 ago 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISCO
abrir ↗
← anteriorpágina 549 / 2.742próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.