Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.231exploits catalogados
35.420CVEs com exploração pública
24.695testados em laboratório
77.231 exploits
Metasploit600
PyTorch Model Server Registration and Deserialization RCE
CVE-2022-1471HIGH03 out 2023
Remote Code execution in SnakeYAML
58RISCO
abrir
Metasploit600
Glibc Tunables Privilege Escalation CVE-2023-4911 (aka Looney Tunables)
CVE-2023-4911HIGHsob ataque03 out 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2022-044103 out 2023
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RISCO
abrir
VulnCheck XDB
local
CVE-2023-21768HIGH02 out 2023
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-38743HIGH02 out 2023
Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.
46RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-36845CRITICALsob ataque02 out 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir
GitHub PoC1
Analysis of WS_FTP CVE
CVE-2023-40044CRITICALsob ataqueransomware02 out 2023
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability
100RISCO
abrir
GitHub PoC4
CVE-2023-36845 PoC script automates the PoC for CVE-2023-36845 targeting Juniper Networks Junos OS's J-Web component on EX and SRX Series devices. It exploits a PHP flaw, allowing remote modification of the PHPRC variable. Successful exploitation can lead to code injection and execution.
CVE-2023-36845CRITICALsob ataque02 out 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir
GitHub PoC39
A tool that checks if a TorchServe instance is vulnerable to CVE-2023-43654
CVE-2023-43654CRITICAL02 out 2023
TorchServe Server-Side Request Forgery
75RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-43654CRITICAL02 out 2023
TorchServe Server-Side Request Forgery
75RISCO
abrir
VulnCheck XDB
local
CVE-2023-44976LOW01 out 2023
Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified
28RISCO
abrir
GitHub PoC1
simrotion13/CVE-2023-36845
CVE-2023-36845CRITICALsob ataque01 out 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-36845CRITICALsob ataque01 out 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-29357CRITICALsob ataqueransomware30 set 2023
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC6
navreet1425/CVE-2021-34621
CVE-2021-34621CRITICAL30 set 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RISCO
abrir
GitHub PoC54
LuemmelSec/CVE-2023-29357
CVE-2023-29357CRITICALsob ataqueransomware30 set 2023
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC6
Find Electron Apps Vulnerable to CVE-2023-4863 / CVE-2023-5129
CVE-2023-4863HIGHsob ataque30 set 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-34621CRITICAL30 set 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RISCO
abrir
GitHub PoC
jytmX/CVE-2021-24499
CVE-2021-2449929 set 2023
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISCO
abrir
GitHub PoC
go CVE-2023-24538 patch issue resolver - Kirkstone
CVE-2023-24538CRITICAL29 set 2023
Backticks not treated as string delimiters in html/template
48RISCO
abrir
GitHub PoC
go CVE-2023-24538 patch issue resolver - Dunfell
CVE-2023-24538CRITICAL29 set 2023
Backticks not treated as string delimiters in html/template
48RISCO
abrir
GitHub PoC3
CVE-2023-36845 - Juniper Firewall Remote code execution (RCE)
CVE-2023-36845CRITICALsob ataque29 set 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir
GitHub PoC5
Scans an executable and determines if it was wrapped in an Electron version vulnerable to the Chromium vulnerability CVE-2023-4863/ CVE-2023-5129
CVE-2023-4863HIGHsob ataque29 set 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-36845CRITICALsob ataque29 set 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir
GitHub PoC46
JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit
CVE-2023-42793CRITICALsob ataqueransomware29 set 2023
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-2449929 set 2023
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALsob ataqueransomware29 set 2023
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-36884HIGHsob ataqueransomware28 set 2023
Windows Search Remote Code Execution Vulnerability
93RISCO
abrir
GitHub PoC3
PoC for Stored XSS (CVE-2023-43770) Vulnerability
CVE-2023-43770MEDIUMsob ataque28 set 2023
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft
75RISCO
abrir
GitHub PoC41
MS Office and Windows HTML RCE (CVE-2023-36884) - PoC and exploit
CVE-2023-36884HIGHsob ataqueransomware28 set 2023
Windows Search Remote Code Execution Vulnerability
93RISCO
abrir
anteriorpágina 462 / 2.575próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.