Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.322exploits catalogados
38.524CVEs com exploração pública
24.695testados em laboratório
82.322 exploits
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMsob ataque11 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALsob ataque11 mar 2023
Unauthenticated Command Injection
100RISCO
abrir ↗
GitHub PoC★ 26
CVE-2023-21839工具
CVE-2023-21839HIGHsob ataque11 mar 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2022-0995HIGHsob ataque10 mar 2023
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This
86RISCO
abrir ↗
VulnCheck XDB
local
CVE-2023-21768HIGH10 mar 2023
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISCO
abrir ↗
GitHub PoC
Microsoft Word 远程代码执行漏洞
CVE-2023-21716CRITICAL10 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir ↗
GitHub PoC★ 11
Tomcat PUT方法任意文件写入(CVE-2017-12615)exp
CVE-2017-12615HIGHsob ataqueransomware10 mar 2023
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-12615HIGHsob ataqueransomware10 mar 2023
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir ↗
GitHub PoC
FortiRecorder Denial of Service Exploit (CVE-2022-41333)
CVE-2022-41333MEDIUM10 mar 2023
An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below
33RISCO
abrir ↗
GitHub PoC★ 2
Tenda f3 Malformed HTTP Request Header Processing Vulnerability.
CVE-2020-35391CRITICAL09 mar 2023
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2020-35391CRITICAL09 mar 2023
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISCO
abrir ↗
VulnCheck XDB
local
CVE-2022-37969HIGHsob ataqueransomware09 mar 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMsob ataque09 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗
GitHub PoC★ 4
CVE-­2021­-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发
CVE-2021-1732HIGHsob ataqueransomware09 mar 2023
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 8
Bulk scanner + get config from CVE-2023-23752
CVE-2023-23752MEDIUMsob ataque09 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗
GitHub PoC★ 3
开源,go多并发批量探测poc,准确率高
CVE-2023-23752MEDIUMsob ataque09 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMsob ataque09 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗
GitHub PoC★ 4
Open Web Analytics 1.7.3 - Remote Code Execution
CVE-2022-24637—09 mar 2023
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISCO
abrir ↗
GitHub PoC★ 2
CVE-2019-15107 图形化测试程序
CVE-2019-15107CRITICALsob ataqueransomware09 mar 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗
GitHub PoC★ 7
Mass Auto Exploit CVE-2022-4395 Unauthenticated Arbitrary File Upload
CVE-2022-4395CRITICAL09 mar 2023
Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload
53RISCO
abrir ↗
GitHub PoC★ 135
Windows LPE exploit for CVE-2022-37969
CVE-2022-37969HIGHsob ataqueransomware09 mar 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗
GitHub PoC
sei-fish/CVE-2021-22205
CVE-2021-22205CRITICALsob ataqueransomware09 mar 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir ↗
GitHub PoC★ 1
CVE-2022-47986: Python, Ruby, NMAP and Metasploit modules to exploit the vulnerability.
CVE-2022-47986CRITICALsob ataqueransomware09 mar 2023
IBM Aspera Faspex code execution
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-1732HIGHsob ataqueransomware09 mar 2023
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-47986CRITICALsob ataqueransomware09 mar 2023
IBM Aspera Faspex code execution
100RISCO
abrir ↗
GitHub PoC★ 4
SSH User Enumerator in Python3, CVE-2018-15473, I updated the code of this exploit (https://www.exploit-db.com/exploits/45939) to work with python3 instead of python2.
CVE-2018-15473MEDIUM09 mar 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir ↗
GitHub PoC★ 59
A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a malicious RTF document. The attacker could deliver this file as an email attachment (or other means).
CVE-2023-21716CRITICAL08 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir ↗
GitHub PoC
Results of retrohunt for files matching YARA rules from https://github.com/AmgdGocha/Detection-Rules/blob/main/CVE-2023-21716.yar
CVE-2023-21716CRITICAL08 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2021-21224HIGHsob ataque08 mar 2023
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a
93RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-21716CRITICAL08 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir ↗
← anteriorpágina 591 / 2.745próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.