Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.252exploits catalogados
38.481CVEs com exploração pública
24.695testados em laboratório
82.252 exploits
VulnCheck XDB
local
CVE-2023-22809HIGH10 jul 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir ↗
GitHub PoC★ 6
asepsaepdin/CVE-2023-22809
CVE-2023-22809HIGH10 jul 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir ↗
GitHub PoC
asepsaepdin/CVE-2021-4034
CVE-2021-4034HIGHsob ataqueransomware10 jul 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware10 jul 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-3560HIGHsob ataque10 jul 2023
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir ↗
VulnCheck XDB
denial-of-service
CVE-2023-34960—09 jul 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RISCO
abrir ↗
GitHub PoC★ 1
Using CVE-2022-0847, "Dirty Pipe Exploit", to pop a reverse bash shell for arbitrary code execution on a foreign machine.
CVE-2022-0847HIGHsob ataque09 jul 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗
GitHub PoC★ 4
A Directory Traversal attack (also known as path traversal) aims to access files and directories that are stored outside the intended folder.
CVE-2023-32235HIGH09 jul 2023
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2
68RISCO
abrir ↗
GitHub PoC
Mass CVE-2023-3460.
CVE-2023-3460—09 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir ↗
GitHub PoC
bthnrml/guncel-cve-2019-9053.py
CVE-2019-9053—09 jul 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗
VulnCheck XDB
local
CVE-2022-0847HIGHsob ataque09 jul 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗
GitHub PoC★ 10
POC for CVE-2023-34362 affecting MOVEit Transfer
CVE-2023-34362CRITICALsob ataqueransomware09 jul 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-35843HIGH09 jul 2023
NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access
56RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-3460—09 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-34362CRITICALsob ataqueransomware09 jul 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISCO
abrir ↗
GitHub PoC
An issue in MiniTool Partition Wizard ShadowMaker v.12.7 allows an attacker to execute arbitrary code via the MTAgentService component
CVE-2023-36164—08 jul 2023
20RISCO
abrir ↗
GitHub PoC
An issue in MiniTool Partition Wizard ShadowMaker v.12.7 allows an attacker to execute arbitrary code and gain privileges via the SchedulerService.exe component.
CVE-2023-36165—08 jul 2023
20RISCO
abrir ↗
GitHub PoC★ 2
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL
CVE-2023-36163—08 jul 2023
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code
23RISCO
abrir ↗
GitHub PoC
Icinga Web 2 - Authenticated Remote Code Execution <2.8.6, <2.9.6, <2.10
CVE-2022-24715HIGH08 jul 2023
Arbitrary code execution for authenticated users in Icinga Web 2
46RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-32315HIGHsob ataque07 jul 2023
Openfire administration console authentication bypass
100RISCO
abrir ↗
GitHub PoC
pitufo1721/CVE-2025-55182-GodzillaMemoryShell
CVE-2025-55182CRITICALsob ataqueransomware07 jul 2023
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗
GitHub PoC
LoaiEsam37/CVE-2023-2982
CVE-2023-2982CRITICAL07 jul 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISCO
abrir ↗
GitHub PoC★ 5
CVE-2023-32315-Openfire-Bypass
CVE-2023-32315HIGHsob ataque07 jul 2023
Openfire administration console authentication bypass
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-3460—07 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir ↗
Exploit-DB
Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution
CVE-2022-21907CRITICALremotewindows07 jul 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir ↗
GitHub PoC
Achat 0.150 beta7 - Remote Buffer Overflow Rewrite for python3 for the PNPT course.
CVE-2015-1578—07 jul 2023
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RISCO
abrir ↗
Exploit-DB
Microsoft Outlook Microsoft 365 MSO (Version 2306 Build 16.0.16529.20100) 32-bit - Remote Code Execution
CVE-2023-33131HIGHremotemultiple07 jul 2023
Microsoft Outlook Remote Code Execution Vulnerability
41RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-2982CRITICAL07 jul 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISCO
abrir ↗
GitHub PoC
rizqimaulanaa/CVE-2023-3460
CVE-2023-3460—07 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir ↗
Exploit-DB
Microsoft Edge 114.0.1823.67 (64-bit) - Information Disclosure
CVE-2023-33145MEDIUMlocalmultiple06 jul 2023
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
33RISCO
abrir ↗
← anteriorpágina 556 / 2.742próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.