Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.252exploits catalogados
38.481CVEs com exploração pública
24.695testados em laboratório
82.252 exploits
GitHub PoC★ 1
eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's password in plain text.
CVE-2023-33730CRITICAL30 mai 2023
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2
48RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-21839HIGHsob ataque29 mai 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-32243CRITICAL29 mai 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir ↗
Metasploit600
Dolibarr ERP/CRM Authenticated Code Injection
CVE-2023-30253HIGH29 mai 2023
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instea
58RISCO
abrir ↗
GitHub PoC★ 2
Identifies domains which run WordPress and tests against vulnerabilities (CVE-2023-32243) / #VU76395 / etc...
CVE-2023-32243CRITICAL29 mai 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir ↗
GitHub PoC★ 8
The exploit is edited to work with different text encodings and Python 3 and is compatible with CMSMS version 2.2.9 and below.
CVE-2019-9053—29 mai 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗
GitHub PoC
kw3h4/CVE-2023-21839-metasploit-scanner
CVE-2023-21839HIGHsob ataque29 mai 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISCO
abrir ↗
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALsob ataqueransomware29 mai 2023
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗
GitHub PoC★ 6
WindowsProtocolTestSuites is to trigger BSoD, and full exploit poc.
CVE-2020-0796CRITICALsob ataqueransomware29 mai 2023
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗
GitHub PoC★ 2
Perfom With Massive Authentication Bypass In PaperCut MF/NG
CVE-2023-27350CRITICALsob ataqueransomware27 mai 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir ↗
GitHub PoC★ 1
MinIO Information Disclosure Vulnerability scanner by metasploit
CVE-2023-28432HIGHsob ataque27 mai 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2019-2215HIGHsob ataque27 mai 2023
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir ↗
GitHub PoC★ 3
Exploit for Bad Binder
CVE-2019-2215HIGHsob ataque27 mai 2023
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-28432HIGHsob ataque27 mai 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir ↗
GitHub PoC★ 1
PoC for login with password hash in STARFACE
CVE-2023-33243HIGH26 mai 2023
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the
41RISCO
abrir ↗
GitHub PoC★ 2
Spring Cloud Gateway Actuator API SpEL表达式注入命令执行Exp
CVE-2022-22947CRITICALsob ataque26 mai 2023
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir ↗
Metasploit600
Openfire authentication bypass with RCE plugin
CVE-2023-32315HIGHsob ataque26 mai 2023
Openfire administration console authentication bypass
100RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Camaleon CMS v2.7.0 - Server-Side Template Injection (SSTI)
CVE-2023-30145CRITICALwebappsruby26 mai 2023
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALsob ataque26 mai 2023
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir ↗
GitHub PoC
Exploit for CVE-2022-22963 remote command execution in Spring Cloud Function
CVE-2022-22963CRITICALsob ataque25 mai 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2023-2825CRITICAL25 mai 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-28432HIGHsob ataque25 mai 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2022-46689HIGH25 mai 2023
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macO
68RISCO
abrir ↗
Exploit-DB
SCM Manager 1.60 - Cross-Site Scripting Stored (Authenticated)
CVE-2023-33829MEDIUMwebappsmultiple25 mai 2023
A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute
33RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-36804HIGHsob ataque25 mai 2023
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque25 mai 2023
Grafana path traversal
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware25 mai 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-1671CRITICALsob ataque25 mai 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-32243CRITICAL25 mai 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir ↗
GitHub PoC★ 7
Camaleon CMS v2.7.0 contain a Server-Side Template Injection (SSTI) vulnerability
CVE-2023-30145CRITICAL25 mai 2023
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para
60RISCO
abrir ↗
← anteriorpágina 566 / 2.742próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.