Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
77.302 exploits
GitHub PoC2
CVE-2021-3129 | Laravel Debug Mode Vulnerability
CVE-2021-3129CRITICALsob ataqueransomware27 jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALsob ataqueransomware27 jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-346027 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir
GitHub PoC1
Exploit for the vulnerability of Ultimate Member Plugin.
CVE-2023-346027 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-46747CRITICALsob ataqueransomware27 jul 2023
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISCO
abrir
GitHub PoC
simple program for joomla scanner CVE-2023-23752 with target list
CVE-2023-23752MEDIUMsob ataque26 jul 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALsob ataqueransomware26 jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMsob ataque26 jul 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-27163MEDIUM26 jul 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-27163MEDIUM26 jul 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISCO
abrir
GitHub PoC
Laravel RCE (CVE-2021-3129)
CVE-2021-3129CRITICALsob ataqueransomware26 jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
Metasploit300
GameOver(lay) Privilege Escalation and Container Escape
CVE-2023-32629HIGH26 jul 2023
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks
61RISCO
abrir
Metasploit600
Greenshot .NET Deserialization Fileformat Exploit
CVE-2023-3463426 jul 2023
Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .green
38RISCO
abrir
Metasploit300
GameOver(lay) Privilege Escalation and Container Escape
CVE-2023-2640HIGH26 jul 2023
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-3864625 jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMsob ataque25 jul 2023
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-8644CRITICALsob ataque25 jul 2023
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
100RISCO
abrir
GitHub PoC2
Python script to exploit PlaySMS before 1.4.3
CVE-2020-8644CRITICALsob ataque25 jul 2023
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
100RISCO
abrir
GitHub PoC
Challenge based on CVE-2021-22204 where users send a malicious file to a web application to gain RCE
CVE-2021-22204MEDIUMsob ataque25 jul 2023
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir
GitHub PoC46
A PoC exploit for CVE-2017-7921 - Hikvision Camera Series Improper Authentication Vulnerability.
CVE-2017-7921CRITICALsob ataque24 jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-7921CRITICALsob ataque24 jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-3496024 jul 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RISCO
abrir
GitHub PoC1
Learn what is BlueJam CVE-2017-0781
CVE-2017-078124 jul 2023
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RISCO
abrir
GitHub PoC1
CVE-2022-23305 Log4J JDBCAppender SQl injection POC
CVE-2022-23305CRITICAL24 jul 2023
SQL injection in JDBC Appender in Apache Log4j V1
60RISCO
abrir
GitHub PoC1
ImageMagick Arbitrary Read Files - CVE-2022-44268
CVE-2022-44268MEDIUM23 jul 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-1177CRITICAL23 jul 2023
Path Traversal: '\..\filename' in mlflow/mlflow
75RISCO
abrir
Metasploit600
Metabase Setup Token RCE
CVE-2023-3864622 jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-4191MEDIUM22 jul 2023
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Priv
70RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-2287322 jul 2023
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg
50RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-3496022 jul 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RISCO
abrir
anteriorpágina 479 / 2.577próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.