Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
77.302 exploits
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALsob ataqueransomware03 jul 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit - Remote Code Execution (RCE)
CVE-2023-28285HIGHremotemultiple03 jul 2023
Microsoft Office Remote Code Execution Vulnerability
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-32315HIGHsob ataque02 jul 2023
Openfire administration console authentication bypass
100RISCO
abrir
GitHub PoC1
Expoit for CVE-2022-44268
CVE-2022-44268MEDIUM02 jul 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir
GitHub PoC6
Perform With Massive Openfire Unauthenticated Users
CVE-2023-32315HIGHsob ataque02 jul 2023
Openfire administration console authentication bypass
100RISCO
abrir
Metasploit600
OpenNMS Horizon Authenticated RCE
CVE-2023-40315MEDIUM01 jul 2023
ROLE_FILESYSTEM_EDITOR Can Be Used To Escalate To ROLE_ADMIN
28RISCO
abrir
Metasploit600
OpenTSDB 2.4.1 unauthenticated command injection
CVE-2023-36812CRITICAL01 jul 2023
Remote Code Execution in OpenTSDB
68RISCO
abrir
Metasploit600
OpenNMS Horizon Authenticated RCE
CVE-2023-0872HIGH01 jul 2023
ROLE_REST can be used to escalate to ROLE_ADMIN via /rest/users
36RISCO
abrir
Metasploit600
OpenTSDB 2.4.1 unauthenticated command injection
CVE-2023-25826CRITICAL01 jul 2023
Remote Code Execution in OpenTSDB
75RISCO
abrir
GitHub PoC5
Exploitation of "Shellshock" Vulnerability. Remote code execution in Apache with mod_cgi
CVE-2014-6271CRITICALsob ataque01 jul 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque01 jul 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL01 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM01 jul 2023
Cross site scripting
70RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM01 jul 2023
Cross site scripting
70RISCO
abrir
GitHub PoC
spip
CVE-2023-27372CRITICAL01 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
GitHub PoC9
WordPress社交登录和注册(Discord,Google,Twitter,LinkedIn)<=7.6.4-绕过身份验证
CVE-2023-2982CRITICAL30 jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISCO
abrir
GitHub PoC11
Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with CVE-2019-6693 is the encryption routine).
CVE-2019-6693MEDIUMsob ataqueransomware30 jun 2023
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RISCO
abrir
VulnCheck XDB
local
CVE-2020-104830 jun 2023
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writin
43RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-2982CRITICAL30 jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-2982CRITICAL29 jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-42013CRITICALsob ataqueransomware29 jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware29 jun 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC82
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
CVE-2023-2982CRITICAL29 jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISCO
abrir
GitHub PoC
yangshifan-git/CVE-2021-1732
CVE-2021-1732HIGHsob ataqueransomware29 jun 2023
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC4
Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.
CVE-2021-44228CRITICALsob ataqueransomware29 jun 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Hamesawian/CVE-2021-42013
CVE-2021-42013CRITICALsob ataqueransomware29 jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
VulnCheck XDB
local
CVE-2023-0386HIGHsob ataque28 jun 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-2625828 jun 2023
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashSe
50RISCO
abrir
VulnCheck XDB
local
CVE-2023-3269HIGH28 jun 2023
Distros-[dirtyvma] privilege escalation via non-rcu-protected vma traversal
41RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-287728 jun 2023
Formidable Forms < 6.3.1 - Subscriber+ Remote Code Execution
28RISCO
abrir
anteriorpágina 485 / 2.577próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.