Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
24.460 exploits
Exploit-DBVexDay Proof
NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
CVE-2022-3142webappsphp25 mar 2023
NEX-Forms < 7.9.7 - Authenticated SQLi
43RISCO
abrir
Exploit-DBVexDay Proof
Abantecart v1.3.2 - Authenticated Remote Code Execution
CVE-2022-26521webappsphp25 mar 2023
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RISCO
abrir
Exploit-DBVexDay Proof
SimpleMachinesForum v2.1.1 - Authenticated Remote Code Execution
CVE-2022-26982webappsphp25 mar 2023
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting
23RISCO
abrir
Exploit-DB
DLink DIR 819 A1 - Denial of Service
CVE-2022-40946HIGHdoshardware25 mar 2023
On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via t
41RISCO
abrir
Exploit-DBVexDay Proof
Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)
CVE-2022-35155MEDIUMwebappsphp25 mar 2023
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the s
33RISCO
abrir
Exploit-DB
Password Manager for IIS v2.0 - XSS
CVE-2022-36664MEDIUMwebappsasp25 mar 2023
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL
33RISCO
abrir
Exploit-DB
ImpressCMS v1.4.3 - Authenticated SQL Injection
CVE-2022-26986webappsphp25 mar 2023
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this al
23RISCO
abrir
Exploit-DB
NVFLARE < 2.1.4 - Unsafe Deserialization due to Pickle
CVE-2022-34668CRITICALremotepython25 mar 2023
NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage ma
53RISCO
abrir
Exploit-DBVexDay Proof
Composr-CMS Version <=10.0.39 - Authenticated Remote Code Execution
CVE-2021-46360webappsphp25 mar 2023
Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrar
23RISCO
abrir
Exploit-DB
Bitbucket v7.0.0 - RCE
CVE-2022-36804HIGHsob ataquewebappspython23 mar 2023
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
Exploit-DB
wkhtmltopdf 0.12.6 - Server Side Request Forgery
CVE-2022-35583webappsasp23 mar 2023
wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by inje
28RISCO
abrir
Exploit-DB
MAN-EAM-0003 V3.2.4 - XXE
CVE-2022-38840HIGHwebappsxml23 mar 2023
cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file uplo
56RISCO
abrir
Exploit-DB
Linksys AX3200 V1.1.00 - Command Injection
CVE-2022-38841HIGHwebappshardware22 mar 2023
Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagn
46RISCO
abrir
Exploit-DB
pfBlockerNG 2.1.4_26 - Remote Code Execution (RCE)
CVE-2022-31814CRITICALwebappsphp20 fev 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir
Exploit-DB
SmartRG Router SR510n 2.6.13 - Remote Code Execution
CVE-2022-37661remotehardware11 nov 2022
SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.
35RISCO
abrir
Exploit-DB
CVAT 2.0 - Server Side Request Forgery
CVE-2022-31188HIGHwebappspython11 nov 2022
Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)
53RISCO
abrir
Exploit-DB
AVEVA InTouch Access Anywhere Secure Gateway 2020 R2 - Path Traversal
CVE-2022-23854HIGHremotehardware11 nov 2022
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an
68RISCO
abrir
Exploit-DB
Open Web Analytics 1.7.3 - Remote Code Execution
CVE-2022-24637webappsphp11 nov 2022
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISCO
abrir
Exploit-DB
MSNSwitch Firmware MNT.2408 - Remote Code Execution
CVE-2022-32429remotehardware11 nov 2022
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technolog
60RISCO
abrir
Exploit-DBVexDay Proof
Wordpress Plugin Zephyr Project Manager 3.2.42 - Multiple SQLi
CVE-2022-2840webappsphp06 out 2022
Zephyr Project Manager < 3.2.5 - Multiple Unauthenticated SQLi
28RISCO
abrir
Exploit-DBVexDay Proof
Wordpress Plugin WP-UserOnline 2.88.0 - Stored Cross Site Scripting (XSS)
CVE-2022-2941MEDIUMwebappsphp23 set 2022
WP-UserOnline <= 2.88.0 - Authenticated (Admin+) Stored Cross-Site Scripting
33RISCO
abrir
Exploit-DB
Feehi CMS 2.1.1 - Remote Code Execution (Authenticated)
CVE-2022-34140webappsphp23 set 2022
A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to
23RISCO
abrir
Exploit-DB
Teleport v10.1.1 - Remote Code Execution (RCE)
CVE-2022-36633remotemultiple23 set 2022
Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ss
35RISCO
abrir
Exploit-DB
TP-Link Tapo c200 1.1.15 - Remote Code Execution (RCE)
CVE-2021-4045CRITICALwebappshardware23 set 2022
TP-LINK Tapo C200 remote code execution vulnerability
70RISCO
abrir
Exploit-DBVexDay Proof
Bookwyrm v0.4.3 - Authentication Bypass
CVE-2022-2651CRITICALwebappsmultiple20 set 2022
Authentication Bypass by Primary Weakness in bookwyrm-social/bookwyrm
53RISCO
abrir
Exploit-DB
Blink1Control2 2.2.7 - Weak Password Encryption
CVE-2022-35513localmultiple20 set 2022
The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage.
23RISCO
abrir
Exploit-DB
Airspan AirSpot 5410 version 0.3.4.1 - Remote Code Execution (RCE)
CVE-2022-36267remotelinux20 set 2022
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerabilit
35RISCO
abrir
Exploit-DBVexDay Proof
Gitea 1.16.6 - Remote Code Execution (RCE) (Metasploit)
CVE-2022-30781webappsmultiple15 set 2022
Gitea before 1.16.7 does not escape git fetch remote.
60RISCO
abrir
Exploit-DB
PAN-OS 10.0 - Remote Code Execution (RCE) (Authenticated)
CVE-2020-2038HIGHremotemultiple09 ago 2022
PAN-OS: OS command injection vulnerability in the management web interface
78RISCO
abrir
Exploit-DB
ThingsBoard 3.3.1 'name' - Stored Cross-Site Scripting (XSS)
CVE-2021-42750webappsmultiple09 ago 2022
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrat
23RISCO
abrir
anteriorpágina 27 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.