Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.322exploits catalogados
38.524CVEs com exploração pública
24.695testados em laboratório
82.322 exploits
VulnCheck XDB
initial-access
CVE-2022-31814CRITICAL26 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-31814CRITICAL26 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMsob ataque26 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗
GitHub PoC★ 1
pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)
CVE-2022-31814CRITICAL26 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir ↗
GitHub PoC★ 3
Unauthenticated RCE in Open Web Analytics version <1.7.4
CVE-2022-24637—26 mar 2023
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISCO
abrir ↗
GitHub PoC★ 1
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information.
CVE-2019-1653HIGHsob ataque26 mar 2023
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 6
0xNahim/CVE-2023-23752
CVE-2023-23752MEDIUMsob ataque26 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗
GitHub PoC★ 3
pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)
CVE-2022-31814CRITICAL26 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-1653HIGHsob ataque26 mar 2023
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2022-24716HIGH26 mar 2023
Path traversal in Icinga Web 2
78RISCO
abrir ↗
GitHub PoC
Authenticated Remote Code Execution in Icinga Web 2 <2.8.6, <2.9.6, <2.10
CVE-2022-24715HIGH25 mar 2023
Arbitrary code execution for authenticated users in Icinga Web 2
46RISCO
abrir ↗
Exploit-DB
System Mechanic v15.5.0.61 - Arbitrary Read/Write
CVE-2018-5701—localwindows25 mar 2023
In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerabi
28RISCO
abrir ↗
Exploit-DB
_camp_ Raspberry Pi camera server 1.0 - Authentication Bypass
CVE-2022-37109CRITICALwebappspython25 mar 2023
patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access
60RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Abantecart v1.3.2 - Authenticated Remote Code Execution
CVE-2022-26521—webappsphp25 mar 2023
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RISCO
abrir ↗
GitHub PoC
Brandaoo/CVE-2014-6271
CVE-2014-6271CRITICALsob ataque25 mar 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗
GitHub PoC★ 1
a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)
CVE-2019-0708CRITICALsob ataqueransomware25 mar 2023
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Composr-CMS Version <=10.0.39 - Authenticated Remote Code Execution
CVE-2021-46360—webappsphp25 mar 2023
Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrar
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
SimpleMachinesForum v2.1.1 - Authenticated Remote Code Execution
CVE-2022-26982—webappsphp25 mar 2023
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Translatepress Multilinugal WordPress plugin < 2.3.3 - Authenticated SQL Injection
CVE-2022-3141—webappsphp25 mar 2023
Translatepress Multilinugal < 2.3.3 - Admin+ SQLi
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution
CVE-2022-26149—webappsphp25 mar 2023
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an ex
23RISCO
abrir ↗
Exploit-DB
ImpressCMS v1.4.3 - Authenticated SQL Injection
CVE-2022-26986—webappsphp25 mar 2023
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this al
23RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque25 mar 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗
Exploit-DB
Password Manager for IIS v2.0 - XSS
CVE-2022-36664MEDIUMwebappsasp25 mar 2023
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL
33RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
CVE-2022-3142—webappsphp25 mar 2023
NEX-Forms < 7.9.7 - Authenticated SQLi
43RISCO
abrir ↗
GitHub PoC★ 5
Joomla Unauthorized Access Vulnerability (CVE-2023-23752) Dockerized
CVE-2023-23752MEDIUMsob ataque25 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗
Exploit-DB
DLink DIR 819 A1 - Denial of Service
CVE-2022-40946HIGHdoshardware25 mar 2023
On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via t
41RISCO
abrir ↗
Exploit-DB
NVFLARE < 2.1.4 - Unsafe Deserialization due to Pickle
CVE-2022-34668CRITICALremotepython25 mar 2023
NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage ma
53RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)
CVE-2022-35155MEDIUMwebappsphp25 mar 2023
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the s
33RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMsob ataque25 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-28432HIGHsob ataque24 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir ↗
← anteriorpágina 586 / 2.745próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.