Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.252exploits catalogados
38.481CVEs com exploração pública
24.695testados em laboratório
82.252 exploits
Exploit-DB
Apache Superset 2.0.0 - Authentication Bypass
CVE-2023-27524HIGHsob ataquewebappsmultiple23 mai 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir ↗
Metasploit600
Apache RocketMQ update config RCE
CVE-2023-33246CRITICALsob ataque23 mai 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir ↗
Exploit-DB
PaperCut NG/MG 22.0.4 - Remote Code Execution (RCE)
CVE-2023-27350CRITICALsob ataqueransomwarewebappsmultiple23 mai 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir ↗
Metasploit600
Barracuda ESG TAR Filename Command Injection
CVE-2023-2868CRITICALsob ataque23 mai 2023
Remote Code injection in Barracuda Email Security Gateway
100RISCO
abrir ↗
Exploit-DB
Webkul Qloapps 1.5.2 - Cross-Site Scripting (XSS)
CVE-2023-30256MEDIUMwebappsphp23 mai 2023
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive informat
48RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
GetSimple CMS v3.3.16 - Remote Code Execution (RCE)
CVE-2022-41544HIGHwebappsphp23 mai 2023
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file paramete
46RISCO
abrir ↗
Exploit-DB
CiviCRM 5.59.alpha1 - Stored XSS (Cross-Site Scripting)
CVE-2023-25440MEDIUMwebappsphp23 mai 2023
Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to exe
33RISCO
abrir ↗
Exploit-DB
FusionInvoice 2023-1.0 - Stored XSS (Cross-Site Scripting)
CVE-2023-25439MEDIUMwebappsmultiple23 mai 2023
Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitr
33RISCO
abrir ↗
Exploit-DB
PnPSCADA v2.x - Unauthenticated PostgreSQL Injection
CVE-2023-1934CRITICALwebappshardware23 mai 2023
The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL
48RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-19492—23 mai 2023
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-19492—23 mai 2023
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-19492—23 mai 2023
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-25690CRITICAL22 mai 2023
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-42889—22 mai 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗
GitHub PoC★ 286
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerability.
CVE-2023-25690CRITICAL22 mai 2023
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISCO
abrir ↗
GitHub PoC
This little script encrypts password to gpp cpassword. It useful to create vulnerable lab AD (CVE-2014-1812).
CVE-2014-1812HIGHsob ataqueransomware22 mai 2023
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo
98RISCO
abrir ↗
GitHub PoC★ 1
vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption
CVE-2007-5962—22 mai 2023
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 throug
28RISCO
abrir ↗
GitHub PoC
Dockerized POC for CVE-2022-42889 Text4Shell
CVE-2022-42889—22 mai 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗
VulnCheck XDB
local
CVE-2023-32784HIGH22 mai 2023
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALsob ataque21 mai 2023
Unauthenticated Command Injection
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-0297CRITICAL21 mai 2023
Code Injection in pyload/pyload
85RISCO
abrir ↗
GitHub PoC
antisecc/CVE-2022-46169
CVE-2022-46169CRITICALsob ataque21 mai 2023
Unauthenticated Command Injection
100RISCO
abrir ↗
GitHub PoC
RCE Unauth in PyLoad <0.5.0b3.dev31
CVE-2023-0297CRITICAL21 mai 2023
Code Injection in pyload/pyload
85RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-3493HIGHsob ataque21 mai 2023
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir ↗
VulnCheck XDB
local
CVE-2019-5736—20 mai 2023
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir ↗
VulnCheck XDB
local
CVE-2023-32784HIGH20 mai 2023
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISCO
abrir ↗
GitHub PoC
antisecc/CVE-2022-24716
CVE-2022-24716HIGH20 mai 2023
Path traversal in Icinga Web 2
78RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2022-24716HIGH20 mai 2023
Path traversal in Icinga Web 2
78RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-29919CRITICAL19 mai 2023
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because t
75RISCO
abrir ↗
GitHub PoC
Proof of Concept about a XSS Stored in SCM Manager 1.2 <= 1.60
CVE-2023-33829MEDIUM19 mai 2023
A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute
33RISCO
abrir ↗
← anteriorpágina 568 / 2.742próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.