Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.322exploits catalogados
38.524CVEs com exploração pública
24.695testados em laboratório
82.322 exploits
GitHub PoC
https & http
CVE-2022-41082HIGHsob ataqueransomware22 mar 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir ↗
Metasploit600
Local Privilege Escalation via CVE-2023-0386
CVE-2023-0386HIGHsob ataque22 mar 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir ↗
Exploit-DB
Linksys AX3200 V1.1.00 - Command Injection
CVE-2022-38841HIGHwebappshardware22 mar 2023
Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagn
46RISCO
abrir ↗
GitHub PoC★ 1
Mustafa1986/cve-2022-42475-Fortinet
CVE-2022-42475CRITICALsob ataqueransomware22 mar 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-23397CRITICALsob ataque22 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 14
Python script for sending e-mails with CVE-2023-23397 payload using SMTP
CVE-2023-23397CRITICALsob ataque22 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗
GitHub PoC
Mustafa1986/CVE-2022-22963
CVE-2022-22963CRITICALsob ataque21 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗
GitHub PoC★ 25
Proof of Concept for CVE-2023-23397 in Python
CVE-2023-23397CRITICALsob ataque21 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALsob ataque21 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗
GitHub PoC
maldev866/ChExp_CVE-2021-30632
CVE-2021-30632HIGHsob ataque21 mar 2023
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISCO
abrir ↗
VulnCheck XDB
local
CVE-2023-21768HIGH21 mar 2023
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISCO
abrir ↗
GitHub PoC★ 6
Altenergy Power System Control Software set_timezone RCE Vulnerability (CVE-2023-28343)
CVE-2023-28343—21 mar 2023
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISCO
abrir ↗
GitHub PoC
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
CVE-2022-36193CRITICAL21 mar 2023
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent chang
48RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2021-30632HIGHsob ataque21 mar 2023
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-23397CRITICALsob ataque21 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-23397CRITICALsob ataque20 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗
Metasploit300
MinIO Bootstrap Verify Information Disclosure
CVE-2023-28432HIGHsob ataque20 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALsob ataque20 mar 2023
Unauthenticated Command Injection
100RISCO
abrir ↗
GitHub PoC
Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10
CVE-2022-24716HIGH20 mar 2023
Path traversal in Icinga Web 2
78RISCO
abrir ↗
GitHub PoC
this web is vulnerable against CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware20 mar 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗
GitHub PoC★ 130
Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.
CVE-2023-23397CRITICALsob ataque20 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 1
Patch for MS Outlook Critical Vulnerability - CVSS 9.8
CVE-2023-23397CRITICALsob ataque20 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2022-24716HIGH20 mar 2023
Path traversal in Icinga Web 2
78RISCO
abrir ↗
VulnCheck XDB
info-leak
CVE-2022-24716HIGH20 mar 2023
Path traversal in Icinga Web 2
78RISCO
abrir ↗
GitHub PoC★ 1
Repo for CVE-2022-46169
CVE-2022-46169CRITICALsob ataque20 mar 2023
Unauthenticated Command Injection
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2022-24716HIGH19 mar 2023
Path traversal in Icinga Web 2
78RISCO
abrir ↗
VulnCheck XDB
local
CVE-2023-22809HIGH19 mar 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir ↗
GitHub PoC★ 1
Custom exploit written for enumerating usernames as per CVE-2016-6210
CVE-2016-6210MEDIUM19 mar 2023
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-23397CRITICALsob ataque19 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 2
ahmedkhlief/CVE-2023-23397-POC-Using-Interop-Outlook
CVE-2023-23397CRITICALsob ataque19 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗
← anteriorpágina 588 / 2.745próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.