Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
77.302 exploits
GitHub PoC1
NetScaler (Citrix ADC) CVE-2023-3519 Scanner
CVE-2023-3519CRITICALsob ataqueransomware21 jul 2023
Unauthenticated remote code execution
100RISCO
abrir
GitHub PoC11
CVE-2023-3519 vuln for nuclei scanner
CVE-2023-3519CRITICALsob ataqueransomware21 jul 2023
Unauthenticated remote code execution
100RISCO
abrir
GitHub PoC228
RCE exploit for CVE-2023-3519
CVE-2023-3519CRITICALsob ataqueransomware21 jul 2023
Unauthenticated remote code execution
100RISCO
abrir
GitHub PoC
CVE-2023-3519
CVE-2023-3519CRITICALsob ataqueransomware21 jul 2023
Unauthenticated remote code execution
100RISCO
abrir
GitHub PoC13
mr-r3b00t/CVE-2023-3519
CVE-2023-3519CRITICALsob ataqueransomware21 jul 2023
Unauthenticated remote code execution
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALsob ataqueransomware21 jul 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-3519CRITICALsob ataqueransomware21 jul 2023
Unauthenticated remote code execution
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-3519CRITICALsob ataqueransomware21 jul 2023
Unauthenticated remote code execution
100RISCO
abrir
Exploit-DB
pfSense v2.7.0 - OS Command Injection
CVE-2023-27253webappsphp20 jul 2023
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attac
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM20 jul 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISCO
abrir
GitHub PoC52
Citrix Scanner for CVE-2023-3519
CVE-2023-3519CRITICALsob ataqueransomware20 jul 2023
Unauthenticated remote code execution
100RISCO
abrir
GitHub PoC
PowerShell Script for initial mitigation of vulnerability
CVE-2023-36884HIGHsob ataqueransomware20 jul 2023
Windows Search Remote Code Execution Vulnerability
93RISCO
abrir
GitHub PoC86
Accurately fingerprint and detect vulnerable (and patched!) versions of Netscaler / Citrix ADC to CVE-2023-3519
CVE-2023-3519CRITICALsob ataqueransomware20 jul 2023
Unauthenticated remote code execution
100RISCO
abrir
GitHub PoC
passwa11/CVE-2023-29017-reverse-shell
CVE-2023-29017CRITICAL20 jul 2023
vm2 Sandbox Escape vulnerability
60RISCO
abrir
GitHub PoC1
lakshit1212/CVE-2021-23017-PoC
CVE-2021-2301720 jul 2023
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RISCO
abrir
GitHub PoC2
A PoC exploit for CVE-2015-2166 - Directory Traversal Vulnerability in Ericsson Drutt Mobile Service Delivery Platform (MSDP)
CVE-2015-216620 jul 2023
Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5
43RISCO
abrir
Exploit-DB
RWS WorldServer 11.7.3 - Session Token Enumeration
CVE-2023-38357webappsmultiple20 jul 2023
Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized a
23RISCO
abrir
GitHub PoC4
A PoC exploit for CVE-2010-4231 - Directory Traversal Vulnerability in Camtron and TecVoz IP Cameras.
CVE-2010-423120 jul 2023
Directory traversal vulnerability in the web-based administration interface on the Camtron CMNC-200 Full HD IP Camera an
43RISCO
abrir
Exploit-DB
Microsoft Office 365 Version 18.2305.1222.0 - Elevation of Privilege + RCE.
CVE-2023-33148HIGHremotemultiple20 jul 2023
Microsoft Office Elevation of Privilege Vulnerability
41RISCO
abrir
Exploit-DBVexDay Proof
Online Piggery Management System v1.0 - unauthenticated file upload vulnerability
CVE-2023-37629webappsphp19 jul 2023
Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by send
43RISCO
abrir
GitHub PoC
Muhammad-Ali007/Log4j_CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware19 jul 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM19 jul 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISCO
abrir
Exploit-DB
Hikvision Hybrid SAN Ds-a71024 Firmware - Multiple Remote Code Execution
CVE-2022-28171HIGHremotehardware19 jul 2023
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to t
53RISCO
abrir
Exploit-DB
ABB FlowX v4.00 - Exposure of Sensitive Information
CVE-2023-1258MEDIUMwebappshardware19 jul 2023
Flow-X disclosure of sensitive information to unauthenticated users
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-4288918 jul 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2017-0148HIGHsob ataqueransomware18 jul 2023
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALsob ataque18 jul 2023
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
GitHub PoC
CVE-2023-36884 临时补丁
CVE-2023-36884HIGHsob ataqueransomware18 jul 2023
Windows Search Remote Code Execution Vulnerability
93RISCO
abrir
Metasploit300
Citrix ADC (NetScaler) Forms SSO Target RCE
CVE-2023-3519CRITICALsob ataqueransomware18 jul 2023
Unauthenticated remote code execution
100RISCO
abrir
GitHub PoC1
This shellscript given the OrgKey 0 will parse the header of the base64 artifacts found in MOVEit Logs and decrypt the Serialized object used a payload
CVE-2023-34362CRITICALsob ataqueransomware18 jul 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISCO
abrir
anteriorpágina 480 / 2.577próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.