Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.322exploits catalogados
38.524CVEs com exploração pública
24.695testados em laboratório
82.322 exploits
Exploit-DB
NotrinosERP 0.7 - Authenticated Blind SQL Injection
CVE-2023-24788—webappsphp07 abr 2023
NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/s
23RISCO
abrir ↗
GitHub PoC★ 2
POC,EXP,chatGPT for me
CVE-2022-45047CRITICAL07 abr 2023
Apache MINA SSHD: Java unsafe deserialization vulnerability
48RISCO
abrir ↗
Exploit-DB
Docker based datastores for IBM Instana 241-2 243-0 - No Authentication
CVE-2023-27290CRITICALremotemultiple07 abr 2023
IBM Observability with Instana missing authentication
48RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2020-6287CRITICALsob ataque07 abr 2023
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISCO
abrir ↗
Exploit-DB
MAC 1200R - Directory Traversal
CVE-2021-27825HIGHwebappshardware07 abr 2023
A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-stati
41RISCO
abrir ↗
GitHub PoC
jedai47/CVE-2017-16994
CVE-2017-16994—07 abr 2023
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RISCO
abrir ↗
Exploit-DB
Tenda N300 F3 12.01.01.48 - Malformed HTTP Request Header Processing
CVE-2020-35391CRITICALremotehardware07 abr 2023
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISCO
abrir ↗
GitHub PoC
Checker help to verify created account or find it's mandat
CVE-2020-6287CRITICALsob ataque07 abr 2023
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISCO
abrir ↗
GitHub PoC★ 2
Clone from gist
CVE-2023-29017CRITICAL07 abr 2023
vm2 Sandbox Escape vulnerability
60RISCO
abrir ↗
Exploit-DB
ChurchCRM 4.5.1 - Authenticated SQL Injection
CVE-2023-24787—webappsphp07 abr 2023
20RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALsob ataque07 abr 2023
Unauthenticated Command Injection
100RISCO
abrir ↗
GitHub PoC★ 1
POC,EXP,chatGPT for me,只能给一些思路,全部不可用
CVE-2022-21306CRITICAL07 abr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
48RISCO
abrir ↗
GitHub PoC
jedai47/CVE-2018-7273
CVE-2018-7273—07 abr 2023
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi
23RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-21742HIGH07 abr 2023
Microsoft SharePoint Server Remote Code Execution Vulnerability
53RISCO
abrir ↗
Exploit-DB
Wondershare Dr Fone 12.9.6 - Privilege Escalation
CVE-2023-27010HIGHlocalwindows07 abr 2023
Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability all
41RISCO
abrir ↗
Exploit-DB
IBM Aspera Faspex 4.4.1 - YAML deserialization (RCE)
CVE-2022-47986CRITICALsob ataqueransomwareremotemultiple07 abr 2023
IBM Aspera Faspex code execution
100RISCO
abrir ↗
GitHub PoC★ 2
DarokNET/CVE-2023-27100
CVE-2023-27100CRITICAL07 abr 2023
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22
48RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Auto Dealer Management System 1.0 - Broken Access Control Exploit
CVE-2023-0916MEDIUMwebappsphp06 abr 2023
SourceCodester Auto Dealer Management System Users.php access control
33RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-0669HIGHsob ataqueransomware06 abr 2023
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Simple Food Ordering System v1.0 - Cross-Site Scripting (XSS)
CVE-2023-0902LOWwebappsphp06 abr 2023
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMsob ataque06 abr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗
Exploit-DB
Dompdf 1.2.1 - Remote Code Execution (RCE)
CVE-2022-28368—webappsphp06 abr 2023
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (
60RISCO
abrir ↗
GitHub PoC★ 8
GoAnywhere MFT CVE-2023-0669 LicenseResponseServlet Deserialization Vulnerabilities Python RCE PoC(Proof of Concept)
CVE-2023-0669HIGHsob ataqueransomware06 abr 2023
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Employee Task Management System v1.0 - SQL Injection on edit-task.php
CVE-2023-0902LOWwebappsphp06 abr 2023
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Employee Task Management System v1.0 - Broken Authentication
CVE-2023-0905HIGHwebappsphp06 abr 2023
SourceCodester Employee Task Management System changePasswordForEmployee.php improper authentication
41RISCO
abrir ↗
Exploit-DB
POLR URL 2.3.0 - Shortener Admin Takeover
CVE-2021-21276CRITICALwebappsphp06 abr 2023
Privilege escalation in Polr
48RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - SQL Injection on music_list.php
CVE-2023-0938MEDIUMwebappsphp06 abr 2023
SourceCodester Music Gallery Site GET Request music_list.php sql injection
33RISCO
abrir ↗
GitHub PoC
BaconCriCRi/PoC-CVE-2022-4939-
CVE-2022-4939CRITICAL06 abr 2023
WCFM Membership <= 2.10.0 - Unauthenticated Privilege Escalation
48RISCO
abrir ↗
Exploit-DB
Agilebio Lab Collector Electronic Lab Notebook v4.234 - Remote Code Execution (RCE)
CVE-2023-24217HIGHwebappsphp06 abr 2023
AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability.
41RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Best pos Management System v1.0 - Remote Code Execution (RCE) on File Upload
CVE-2023-0943MEDIUMwebappsphp06 abr 2023
SourceCodester Best POS Management System Image save_settings unrestricted upload
33RISCO
abrir ↗
← anteriorpágina 580 / 2.745próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.