Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.231exploits catalogados
35.420CVEs com exploração pública
24.695testados em laboratório
77.231 exploits
VulnCheck XDB
initial-access
CVE-2023-36847MEDIUMsob ataque24 set 2023
Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-36844MEDIUMsob ataque24 set 2023
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
100RISCO
abrir
GitHub PoC
DimaMend/cve-2022-42889-text4shell
CVE-2022-4288922 set 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-34753HIGH22 set 2023
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exist
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-4288922 set 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC3
Proof-of-Concept (POC) of CVE-2023-38831 Zero-Day vulnerability in WinRAR
CVE-2023-38831HIGHsob ataqueransomware21 set 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC316
mistymntncop/CVE-2023-4863
CVE-2023-4863HIGHsob ataque21 set 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-39361CRITICAL21 set 2023
Unauthenticated SQL Injection in graph_view.php in Cacti
85RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM21 set 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2023-38831HIGHsob ataqueransomware21 set 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-4863HIGHsob ataque21 set 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISCO
abrir
GitHub PoC1
A PoC for CVE-2022-26134 for Educational Purposes and Security Research
CVE-2022-26134CRITICALsob ataqueransomware20 set 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALsob ataqueransomware20 set 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC
Perform With Massive Juniper Remote Code Execution
CVE-2023-36844MEDIUMsob ataque20 set 2023
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-36844MEDIUMsob ataque20 set 2023
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
100RISCO
abrir
Metasploit600
JetBrains TeamCity Unauthenticated Remote Code Execution
CVE-2023-42793CRITICALsob ataqueransomware19 set 2023
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHsob ataque17 set 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
VulnCheck XDB
local
CVE-2023-2640HIGH17 set 2023
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-38831HIGHsob ataqueransomware17 set 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC1
CVE: CVE-2022-0847
CVE-2022-0847HIGHsob ataque17 set 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware17 set 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
ngothienan/CVE-2023-38831
CVE-2023-38831HIGHsob ataqueransomware17 set 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
VulnCheck XDB
local
CVE-2023-32629HIGH17 set 2023
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks
61RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2011-319216 set 2023
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISCO
abrir
GitHub PoC62
A go-exploit to scan for Juniper firewalls vulnerable to CVE-2023-36845
CVE-2023-36845CRITICALsob ataque16 set 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir
GitHub PoC
futurezayka/CVE-2011-3192
CVE-2011-319216 set 2023
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISCO
abrir
VulnCheck XDB
local
CVE-2023-36845CRITICALsob ataque16 set 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-4060CRITICAL15 set 2023
User Post Gallery <= 2.19 - Unauthenticated RCE
75RISCO
abrir
GitHub PoC5
WAGO Remote Exploit Tool for CVE-2023-1698
CVE-2023-1698CRITICAL15 set 2023
WAGO: WBM Command Injection in multiple products
85RISCO
abrir
GitHub PoC8
Automatic Mass Tool for checking vulnerability in CVE-2022-4060 - WordPress Plugin : User Post Gallery <= 2.19 - Unauthenticated RCE
CVE-2022-4060CRITICAL15 set 2023
User Post Gallery <= 2.19 - Unauthenticated RCE
75RISCO
abrir
anteriorpágina 464 / 2.575próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.