Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.252exploits catalogados
38.481CVEs com exploração pública
24.695testados em laboratório
82.252 exploits
VulnCheck XDB
initial-access
CVE-2023-32315HIGHsob ataque02 jul 2023
Openfire administration console authentication bypass
100RISCO
abrir ↗
GitHub PoC★ 6
Perform With Massive Openfire Unauthenticated Users
CVE-2023-32315HIGHsob ataque02 jul 2023
Openfire administration console authentication bypass
100RISCO
abrir ↗
GitHub PoC
spip
CVE-2023-27372CRITICAL01 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir ↗
Metasploit600
OpenTSDB 2.4.1 unauthenticated command injection
CVE-2023-36812CRITICAL01 jul 2023
Remote Code Execution in OpenTSDB
68RISCO
abrir ↗
Metasploit600
OpenNMS Horizon Authenticated RCE
CVE-2023-40315MEDIUM01 jul 2023
ROLE_FILESYSTEM_EDITOR Can Be Used To Escalate To ROLE_ADMIN
28RISCO
abrir ↗
Metasploit600
OpenTSDB 2.4.1 unauthenticated command injection
CVE-2023-25826CRITICAL01 jul 2023
Remote Code Execution in OpenTSDB
75RISCO
abrir ↗
Metasploit600
OpenNMS Horizon Authenticated RCE
CVE-2023-0872HIGH01 jul 2023
ROLE_REST can be used to escalate to ROLE_ADMIN via /rest/users
36RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL01 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM01 jul 2023
Cross site scripting
70RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM01 jul 2023
Cross site scripting
70RISCO
abrir ↗
GitHub PoC★ 5
Exploitation of "Shellshock" Vulnerability. Remote code execution in Apache with mod_cgi
CVE-2014-6271CRITICALsob ataque01 jul 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque01 jul 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗
GitHub PoC★ 9
WordPress社交登录和注册(Discord,Google,Twitter,LinkedIn)<=7.6.4-绕过身份验证
CVE-2023-2982CRITICAL30 jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISCO
abrir ↗
GitHub PoC★ 11
Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with CVE-2019-6693 is the encryption routine).
CVE-2019-6693MEDIUMsob ataqueransomware30 jun 2023
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-2982CRITICAL30 jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISCO
abrir ↗
VulnCheck XDB
local
CVE-2020-1048HIGH30 jun 2023
Windows Print Spooler Elevation of Privilege Vulnerability
61RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-42013CRITICALsob ataqueransomware29 jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware29 jun 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗
GitHub PoC★ 4
Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.
CVE-2021-44228CRITICALsob ataqueransomware29 jun 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗
GitHub PoC
yangshifan-git/CVE-2021-1732
CVE-2021-1732HIGHsob ataqueransomware29 jun 2023
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 82
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
CVE-2023-2982CRITICAL29 jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISCO
abrir ↗
GitHub PoC★ 1
Hamesawian/CVE-2021-42013
CVE-2021-42013CRITICALsob ataqueransomware29 jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-2982CRITICAL29 jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-26258—28 jun 2023
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashSe
50RISCO
abrir ↗
GitHub PoC★ 21
非常简单的CVE-2023-0386's exp and analysis.Use c and sh.
CVE-2023-0386HIGHsob ataque28 jun 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir ↗
VulnCheck XDB
local
CVE-2023-0386HIGHsob ataque28 jun 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir ↗
VulnCheck XDB
local
CVE-2023-3269HIGH28 jun 2023
Distros-[dirtyvma] privilege escalation via non-rcu-protected vma traversal
41RISCO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2023-2877—28 jun 2023
Formidable Forms < 6.3.1 - Subscriber+ Remote Code Execution
28RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-42889—27 jun 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗
GitHub PoC★ 179
fortra/CVE-2023-28252
CVE-2023-28252HIGHsob ataqueransomware27 jun 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISCO
abrir ↗
← anteriorpágina 558 / 2.742próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.