Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.419exploits catalogados
38.564CVEs com exploração pública
24.695testados em laboratório
82.419 exploits
VulnCheck XDB
local
CVE-2023-21768HIGH07 mar 2023
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMsob ataque07 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗
GitHub PoC
rahmadsandy/EXIM-4.87-CVE-2019-10149
CVE-2019-10149CRITICALsob ataque07 mar 2023
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2020-16040—07 mar 2023
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-21716CRITICAL07 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALsob ataque07 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-21716CRITICAL07 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir ↗
GitHub PoC★ 1
adriyansyah-mf/CVE-2023-23752
CVE-2023-23752MEDIUMsob ataque07 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗
Metasploit600
Pretalx Limited File Write to Remote Code Execution
CVE-2023-28458MEDIUM07 mar 2023
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the over
28RISCO
abrir ↗
Metasploit300
Pretalx Arbitrary File Read/Limited File Write
CVE-2023-28458MEDIUM07 mar 2023
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the over
28RISCO
abrir ↗
Metasploit300
Pretalx Arbitrary File Read/Limited File Write
CVE-2023-28459MEDIUM07 mar 2023
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload craft
28RISCO
abrir ↗
GitHub PoC★ 8
spring cloud function 一键利用工具! by charis 博客https://charis3306.top/
CVE-2022-22963CRITICALsob ataque07 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗
GitHub PoC★ 4
FeatherStark/CVE-2023-21716
CVE-2023-21716CRITICAL07 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir ↗
GitHub PoC★ 46
RTF Crash POC Python 3.11 Windows 10
CVE-2023-21716CRITICAL07 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir ↗
GitHub PoC
Script in Ruby for the CVE-2022-35914 - RCE in GLPI
CVE-2022-35914CRITICALsob ataque07 mar 2023
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISCO
abrir ↗
GitHub PoC★ 1
Pada bulan maret 2023, terdapat sample baru yang terindentifikasi sebagai malware. Malware tersebut berasal dari file berekstensi.xls dan .doc dan dikenal dengan nama “Bank Slip.xls”. Aktivitas malware tersebut memiliki hubungan dengan kerentanan yang dikenal dengan id CVE-2017-11882 dan CVE-2018-0802.
CVE-2018-0802HIGHsob ataqueransomware06 mar 2023
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISCO
abrir ↗
GitHub PoC★ 1
Pada bulan maret 2023, terdapat sample baru yang terindentifikasi sebagai malware. Malware tersebut berasal dari file berekstensi.xls dan .doc dan dikenal dengan nama “Bank Slip.xls”. Aktivitas malware tersebut memiliki hubungan dengan kerentanan yang dikenal dengan id CVE-2017-11882 dan CVE-2018-0802.
CVE-2017-11882HIGHsob ataqueransomware06 mar 2023
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir ↗
GitHub PoC★ 2
CVE-2022-31814
CVE-2022-31814CRITICAL05 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-31814CRITICAL05 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-1386—05 mar 2023
Fusion Builder < 3.6.2 - Unauthenticated SSRF
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALsob ataqueransomware04 mar 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗
GitHub PoC★ 13
Laravel Debug mode RCE漏洞(CVE-2021-3129)poc / exp
CVE-2021-3129CRITICALsob ataqueransomware04 mar 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗
GitHub PoC★ 6
This script is used for automating exploit for Oracle Ebussiness (EBS) for CVE 2022-21587 ( Unauthenticated File Upload For Remote Code Execution)
CVE-2022-21587CRITICALsob ataqueransomware03 mar 2023
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-21587CRITICALsob ataqueransomware03 mar 2023
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALsob ataque02 mar 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2019-0708CRITICALsob ataqueransomware02 mar 2023
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALsob ataqueransomware02 mar 2023
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir ↗
GitHub PoC
🚀 Exploit for Spring core RCE in C [ wip ]
CVE-2022-22965CRITICALsob ataque02 mar 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗
GitHub PoC
mritunjay-k/CVE-2014-6271
CVE-2014-6271CRITICALsob ataque02 mar 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗
GitHub PoC
Checker and exploit for Bluekeep CVE-2019-0708 vulnerability
CVE-2019-0708CRITICALsob ataqueransomware02 mar 2023
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗
← anteriorpágina 594 / 2.748próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.