Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
77.302 exploits
GitHub PoC
pitufo1721/CVE-2025-55182-GodzillaMemoryShell
CVE-2025-55182CRITICALsob ataqueransomware07 jul 2023
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
Exploit-DB
Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution
CVE-2022-21907CRITICALremotewindows07 jul 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir
Exploit-DB
Microsoft Edge 114.0.1823.67 (64-bit) - Information Disclosure
CVE-2023-33145MEDIUMlocalmultiple06 jul 2023
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
33RISCO
abrir
GitHub PoC8
An eBPF program to detect attacks on CVE-2022-0847
CVE-2022-0847HIGHsob ataque06 jul 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHsob ataque06 jul 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
Exploit-DB
Lost and Found Information System v1.0 - SQL Injection
CVE-2023-33592webappsphp06 jul 2023
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM06 jul 2023
Cross site scripting
70RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALsob ataque05 jul 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC35
Exploit for CVE-2023-3460. Unauthorized admin access for Ultimate Member plugin < v2.6.7
CVE-2023-346005 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-346005 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL05 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
GitHub PoC6
This is a PoC for CVE-2023-27372 which spawns a fully interactive shell.
CVE-2023-27372CRITICAL05 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
GitHub PoC2
CVE-2017-7921 EXPLOIT
CVE-2017-7921CRITICALsob ataque04 jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir
GitHub PoC
This is the Updated Python3 exploit for CVE-2019-9053
CVE-2019-905304 jul 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALsob ataque04 jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM04 jul 2023
Cross site scripting
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-2834303 jul 2023
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISCO
abrir
GitHub PoC
WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2023-39362). Run it at your own risk!
CVE-2023-39362HIGH03 jul 2023
Authenticated command injection in SNMP options of a Device
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-3496003 jul 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALsob ataqueransomware03 jul 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-3710CRITICAL03 jul 2023
Printer web page invalid command execution
75RISCO
abrir
Exploit-DB
TP-Link TL-WR940N V4 - Buffer OverFlow
CVE-2023-36355doshardware03 jul 2023
TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6Cfg
35RISCO
abrir
GitHub PoC3
Fix WinVerifyTrust Signature Validation Vulnerability, CVE-2013-3900, QID-378332
CVE-2013-3900MEDIUMsob ataque03 jul 2023
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir
GitHub PoC4
Wordpress CVE-2023-32243
CVE-2023-32243CRITICAL03 jul 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir
Exploit-DB
Sales of Cashier Goods v1.0 - Cross Site Scripting (XSS)
CVE-2023-36346webappsphp03 jul 2023
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parame
38RISCO
abrir
Exploit-DB
FuguHub 8.1 - Remote Code Execution
CVE-2023-24078HIGHwebappsmultiple03 jul 2023
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RISCO
abrir
Exploit-DB
WP AutoComplete 1.0.4 - Unauthenticated SQLi
CVE-2022-4297CRITICALwebappsphp03 jul 2023
WP AutoComplete Search <= 1.0.4 - Unauthenticated SQLi
48RISCO
abrir
Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit - Remote Code Execution (RCE)
CVE-2023-28285HIGHremotemultiple03 jul 2023
Microsoft Office Remote Code Execution Vulnerability
41RISCO
abrir
GitHub PoC13
PoC of Imagemagick's Arbitrary File Read
CVE-2022-44268MEDIUM03 jul 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir
Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 32-bit - Remote Code Execution (RCE)
CVE-2023-33137HIGHremotemultiple03 jul 2023
Microsoft Excel Remote Code Execution Vulnerability
41RISCO
abrir
anteriorpágina 484 / 2.577próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.