Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.252exploits catalogados
38.481CVEs com exploração pública
24.695testados em laboratório
82.252 exploits
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware03 jun 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALsob ataqueransomware03 jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-0441—02 jun 2023
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RISCO
abrir ↗
GitHub PoC★ 1
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
CVE-2022-0441—02 jun 2023
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RISCO
abrir ↗
GitHub PoC★ 3
CVE-2023-33246:Apache RocketMQ 远程命令执行漏洞检测工具
CVE-2023-33246CRITICALsob ataque02 jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir ↗
GitHub PoC★ 114
Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit
CVE-2023-33246CRITICALsob ataque01 jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir ↗
Metasploit600
Splunk "edit_user" Capability Privilege Escalation
CVE-2023-32707HIGH01 jun 2023
‘edit_user’ Capability Privilege Escalation
78RISCO
abrir ↗
GitHub PoC★ 81
Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit
CVE-2023-33246CRITICALsob ataque01 jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir ↗
Metasploit600
Chamilo unauthenticated command injection in PowerPoint upload
CVE-2023-34960—01 jun 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RISCO
abrir ↗
GitHub PoC
[CVE-2021-33690] Server Side Request Forgery vulnerability in SAP NetWeaver Development Infrastructure
CVE-2021-33690CRITICAL01 jun 2023
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Compo
75RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-33690CRITICAL01 jun 2023
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Compo
75RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-33246CRITICALsob ataque01 jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir ↗
Exploit-DB
Pydio Cells 4.1.2 - Unauthorised Role Assignments
CVE-2023-32749HIGHwebappsgo31 mai 2023
Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying t
46RISCO
abrir ↗
Exploit-DB
Pydio Cells 4.1.2 - Server-Side Request Forgery
CVE-2023-32750MEDIUMwebappsgo31 mai 2023
Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which
33RISCO
abrir ↗
Exploit-DB
unilogies/bumsys v1.0.3 beta - Unrestricted File Upload
CVE-2023-0455HIGHwebappsphp31 mai 2023
Unrestricted Upload of File with Dangerous Type in unilogies/bumsys
41RISCO
abrir ↗
GitHub PoC★ 2
4mazing/CVE-2023-33246-Copy
CVE-2023-33246CRITICALsob ataque31 mai 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir ↗
GitHub PoC★ 1
Exploit for CVE:2010-2075. This exploit allows remote command execution in UnrealIRCd 3.2.8.1.
CVE-2010-2075—31 mai 2023
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISCO
abrir ↗
Metasploit600
Wordpress File Manager Advanced Shortcode 2.3.2 - Unauthenticated Remote Code Execution through shortcode
CVE-2023-2068—31 mai 2023
File Manager Advanced Shortcode <= 2.3.2 - Unauthenticated Remote Code Execution through shortcode
50RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Online Security Guards Hiring System 1.0 - Reflected XSS
CVE-2023-0527LOWwebappsphp31 mai 2023
PHPGurukul Online Security Guards Hiring System search-request.php cross site scripting
43RISCO
abrir ↗
Metasploit600
MOVEit SQL Injection vulnerability
CVE-2023-34362CRITICALsob ataqueransomware31 mai 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISCO
abrir ↗
GitHub PoC★ 2
A simple python script for a firewall rule that blocks incoming requests based on the Spring4Shell (CVE-2022-22965) vulnerability
CVE-2022-22965CRITICALsob ataque31 mai 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗
Exploit-DB
Pydio Cells 4.1.2 - Cross-Site Scripting (XSS) via File Download
CVE-2023-32751MEDIUMwebappsgo31 mai 2023
Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are genera
33RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALsob ataque31 mai 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Faculty Evaluation System 1.0 - Unauthenticated File Upload
CVE-2023-33440HIGHwebappsphp31 mai 2023
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_u
61RISCO
abrir ↗
Exploit-DB
Flexense HTTP Server 10.6.24 - Buffer Overflow (DoS) (Metasploit)
CVE-2018-8065—remotemultiple31 mai 2023
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access v
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALsob ataqueransomware30 mai 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗
GitHub PoC
the proof of concept written in Python for an unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups. This is a critical severity issue
CVE-2023-2825CRITICAL30 mai 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISCO
abrir ↗
GitHub PoC★ 62
I5N0rth/CVE-2023-33246
CVE-2023-33246CRITICALsob ataque30 mai 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir ↗
GitHub PoC★ 1
eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's password in plain text.
CVE-2023-33730CRITICAL30 mai 2023
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2
48RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-1675HIGHsob ataqueransomware30 mai 2023
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir ↗
← anteriorpágina 565 / 2.742próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.