Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.252exploits catalogados
38.481CVEs com exploração pública
24.695testados em laboratório
82.252 exploits
GitHub PoC
Proof of concept for LabVIEW Web Server HTTP Get Newline DoS vulnerability
CVE-2002-0748—13 jul 2023
LabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET reques
28RISCO
abrir ↗
GitHub PoC★ 13
This project is a Python script that exploits the CVE-2023-24489 vulnerability in ShareFile. It allows remote command execution on the target server. The script supports both Windows and Linux (On testing) platforms, and it can be used to exploit individual targets or perform mass checking on a list of URLs.
CVE-2023-24489CRITICALsob ataque12 jul 2023
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
100RISCO
abrir ↗
GitHub PoC★ 26
The remediation script should set the reg entries described in https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884 . The detection script checks if they exist. Provided AS-IS without any warrenty.
CVE-2023-36884HIGHsob ataqueransomware12 jul 2023
Windows Search Remote Code Execution Vulnerability
93RISCO
abrir ↗
Metasploit600
Sonicwall
CVE-2023-34132—12 jul 2023
Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the
18RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-28121—12 jul 2023
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-28121—12 jul 2023
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-24489CRITICALsob ataque12 jul 2023
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
100RISCO
abrir ↗
Metasploit600
Sonicwall
CVE-2023-34124CRITICAL12 jul 2023
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authenticatio
75RISCO
abrir ↗
Metasploit600
Sonicwall
CVE-2023-34127HIGH12 jul 2023
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GM
58RISCO
abrir ↗
Metasploit600
Sonicwall
CVE-2023-34133HIGH12 jul 2023
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and
58RISCO
abrir ↗
GitHub PoC
F5-BIG-IP Remote Code Execution Vulnerability CVE-2022-1388: A Case Study
CVE-2022-1388CRITICALsob ataqueransomware12 jul 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-1732HIGHsob ataqueransomware11 jul 2023
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-27163MEDIUM11 jul 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-27372CRITICAL11 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir ↗
Metasploit600
Microsoft Error Reporting Local Privilege Elevation Vulnerability
CVE-2023-36874HIGHsob ataque11 jul 2023
Windows Error Reporting Service Elevation of Privilege Vulnerability
98RISCO
abrir ↗
GitHub PoC★ 1
asepsaepdin/CVE-2021-1732
CVE-2021-1732HIGHsob ataqueransomware11 jul 2023
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir ↗
Exploit-DB
Game Jackal Server v5 - Unquoted Service Path _GJServiceV5_
CVE-2023-36166—localwindows11 jul 2023
20RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2022-45354MEDIUM11 jul 2023
WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure
60RISCO
abrir ↗
Exploit-DB
AVG Anti Spyware 7.5 - Unquoted Service Path _AVG Anti-Spyware Guard_
CVE-2023-36167—localwindows11 jul 2023
20RISCO
abrir ↗
GitHub PoC
CVE-2023-3460
CVE-2023-3460—11 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir ↗
GitHub PoC★ 7
Exploit and scanner for CVE-2023-3460
CVE-2023-3460—11 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir ↗
Exploit-DB
Spring Cloud 3.2.2 - Remote Command Execution (RCE)
CVE-2022-22963CRITICALsob ataquewebappsjava11 jul 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-3460—11 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir ↗
Exploit-DB
MiniTool Partition Wizard ShadowMaker v.12.7 - Unquoted Service Path _MTSchedulerService_
CVE-2023-36165—localwindows11 jul 2023
20RISCO
abrir ↗
GitHub PoC★ 2
CVE-2023-27372-SPIP-CMS-Bypass
CVE-2023-27372CRITICAL11 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir ↗
Exploit-DB
MiniTool Partition Wizard ShadowMaker v.12.7 - Unquoted Service Path _MTAgentService_
CVE-2023-36164—localwindows11 jul 2023
20RISCO
abrir ↗
GitHub PoC★ 2
Search vulnerable FortiOS devices via Shodan (CVE-2023-27997)
CVE-2023-27997CRITICALsob ataqueransomware11 jul 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISCO
abrir ↗
Exploit-DB
BuildaGate5library v5 - Reflected Cross-Site Scripting (XSS)
CVE-2023-36163—webappsphp11 jul 2023
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code
23RISCO
abrir ↗
GitHub PoC★ 1
Python script that generates pfs payloads to exploit CVE-2022-4510
CVE-2022-4510HIGH11 jul 2023
Path Traversal in binwalk
46RISCO
abrir ↗
GitHub PoC★ 6
asepsaepdin/CVE-2023-22809
CVE-2023-22809HIGH10 jul 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir ↗
← anteriorpágina 555 / 2.742próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.