Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
77.058 exploits
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALsob ataqueransomware17 mar 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-21762CRITICALsob ataqueransomware17 mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir
GitHub PoC12
The PoC demonstrates the potential for remote code execution by exploiting the identified security flaw.
CVE-2024-21762CRITICALsob ataqueransomware17 mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir
GitHub PoC7
jakabakos/CVE-2023-43208-mirth-connect-rce-poc
CVE-2023-43208CRITICALsob ataqueransomware17 mar 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir
GitHub PoC4
sxyrxyy/aiohttp-exploit-CVE-2024-23334-certstream
CVE-2024-23334MEDIUM17 mar 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
Metasploit600
RaspberryMatic unauthenticated Remote Code Execution vulnerability through HMServer File Upload.
CVE-2024-24578CRITICAL16 mar 2024
RaspberryMatic Unauthenticated Remote Code Execution vulnerability through HMServer File Upload
43RISCO
abrir
Metasploit600
OpenMetadata authentication bypass and SpEL injection exploit chain
CVE-2024-28254HIGH15 mar 2024
SpEL Injection in `GET /api/v1/events/subscriptions/validation/condition/<expr>` in OpenMetadata
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALsob ataqueransomware15 mar 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir
Metasploit600
OpenMetadata authentication bypass and SpEL injection exploit chain
CVE-2024-28255CRITICAL15 mar 2024
Authentication Bypass in OpenMetadata
85RISCO
abrir
GitHub PoC3
Exploit for Open eClass – CVE-2024-26503: Unrestricted File Upload Leads to Remote Code Execution
CVE-2024-26503CRITICAL15 mar 2024
Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to
48RISCO
abrir
GitHub PoC
exploit for f5-big-ip RCE cve-2023-46747
CVE-2023-46747CRITICALsob ataqueransomware15 mar 2024
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-44228CRITICALsob ataqueransomware15 mar 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC29
A PoC exploit for CVE-2023-43208 - Mirth Connect Remote Code Execution (RCE)
CVE-2023-43208CRITICALsob ataqueransomware15 mar 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir
VulnCheck XDB
local
CVE-2024-21626HIGH15 mar 2024
runc container breakout through process.cwd trickery and leaked fds
61RISCO
abrir
GitHub PoC
This is a potentially vulnerable Java web application containing Log4j affected by log4shell(CVE-2021-44228).
CVE-2021-44228CRITICALsob ataqueransomware15 mar 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Exploit-DB
SolarView Compact 6.00 - Command Injection
CVE-2023-23333CRITICALremotehardware14 mar 2024
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISCO
abrir
Exploit-DB
GitLab CE/EE < 16.7.2 - Password Reset
CVE-2023-7028CRITICALsob ataqueremotejava14 mar 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISCO
abrir
Metasploit600
Ghostscript Command Execution via Format String
CVE-2024-29510MEDIUM14 mar 2024
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with
33RISCO
abrir
Exploit-DB
KiTTY 0.76.1.13 - Command Injection
CVE-2024-23749HIGHlocalwindows14 mar 2024
KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insuffic
41RISCO
abrir
Exploit-DB
Honeywell PM43 < P10.19.050004 - Remote Code Execution (RCE)
CVE-2023-3710CRITICALremotehardware14 mar 2024
Printer web page invalid command execution
75RISCO
abrir
GitHub PoC
manrop2702/CVE-2020-7961
CVE-2020-7961CRITICALsob ataque14 mar 2024
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir
GitHub PoC
A CLI tool for detecting CVE-2023-20048 vulnerability in Cisco Firepower Management Center.
CVE-2023-20048CRITICAL14 mar 2024
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authent
53RISCO
abrir
Exploit-DB
JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE)
CVE-2023-42793CRITICALsob ataqueransomwareremotejava14 mar 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
Exploit-DB
Viessmann Vitogate 300 2.1.3.0 - Remote Code Execution (RCE)
CVE-2023-5222MEDIUMremotehardware14 mar 2024
Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
70RISCO
abrir
Exploit-DB
KiTTY 0.76.1.13 - 'Start Duplicated Session Username' Buffer Overflow
CVE-2024-25004HIGHlocalwindows14 mar 2024
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insuf
41RISCO
abrir
Exploit-DB
Viessmann Vitogate 300 2.1.3.0 - Remote Code Execution (RCE)
CVE-2023-5702MEDIUMremotehardware14 mar 2024
Viessmann Vitogate 300 direct request
38RISCO
abrir
Exploit-DB
KiTTY 0.76.1.13 - 'Start Duplicated Session Hostname' Buffer Overflow
CVE-2024-25003HIGHlocalwindows14 mar 2024
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insuf
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-33246CRITICALsob ataque14 mar 2024
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir
GitHub PoC150
out-of-bounds write in Fortinet FortiOS CVE-2024-21762 vulnerability
CVE-2024-21762CRITICALsob ataqueransomware13 mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir
GitHub PoC16
Chequea si tu firewall es vulnerable a CVE-2024-21762 (RCE sin autenticación)
CVE-2024-21762CRITICALsob ataqueransomware13 mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir
anteriorpágina 416 / 2.569próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.