Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.353exploits catalogados
35.510CVEs com exploração pública
24.695testados em laboratório
77.302 exploits
VulnCheck XDB
initial-access
CVE-2023-25157CRITICAL12 jun 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISCO
abrir
GitHub PoC3
A script, written in golang. POC for CVE-2023-25157
CVE-2023-25157CRITICAL12 jun 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2022-2227411 jun 2023
A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to
35RISCO
abrir
GitHub PoC14
GeoServer & GeoTools SQL Injection (CVE-2023-25157 & CVE-2023-25158)
CVE-2023-25157CRITICAL11 jun 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-25157CRITICAL11 jun 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISCO
abrir
GitHub PoC
andyhsu024/CVE-2022-45025
CVE-2022-45025CRITICAL11 jun 2023
Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerabi
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-25158CRITICAL11 jun 2023
Unfiltered SQL Injection in Geotools
48RISCO
abrir
GitHub PoC1
lukinneberg/CVE-2023-2636
CVE-2023-263611 jun 2023
AN_GradeBook <= 5.0.1 - Subscriber+ SQLi
23RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-25157CRITICAL10 jun 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISCO
abrir
GitHub PoC10
0x2458bughunt/CVE-2023-25157
CVE-2023-25157CRITICAL10 jun 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISCO
abrir
GitHub PoC2
DreamD2v/CVE-2023-31541
CVE-2023-31541CRITICAL10 jun 2023
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3
48RISCO
abrir
GitHub PoC21
m-cetin/CVE-2023-29336
CVE-2023-29336HIGHsob ataque09 jun 2023
Win32k Elevation of Privilege Vulnerability
83RISCO
abrir
GitHub PoC6
Proof of Concept for vulnerability CVE-2023-2986 in 'Abandoned Cart Lite for WooCommerce' Plugin in WordPress
CVE-2023-2986CRITICAL09 jun 2023
Abandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication Bypass
60RISCO
abrir
GitHub PoC
antisecc/CVE-2018-16763
CVE-2018-1676309 jun 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC138
MOVEit CVE-2023-34362
CVE-2023-34362CRITICALsob ataqueransomware09 jun 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISCO
abrir
Exploit-DB
WordPress Theme Workreap 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
CVE-2021-24499webappsphp09 jun 2023
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISCO
abrir
VulnCheck XDB
local
CVE-2023-29336HIGHsob ataque09 jun 2023
Win32k Elevation of Privilege Vulnerability
83RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-2986CRITICAL09 jun 2023
Abandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication Bypass
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-3496009 jun 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RISCO
abrir
GitHub PoC1
Thruk Monitoring Web Interface <= 3.06 vulnerable to CVE-2023-34096 (Path Traversal).
CVE-2023-34096MEDIUM09 jun 2023
Thruk has Path Traversal Vulnerability in panorama.pm
45RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-34362CRITICALsob ataqueransomware09 jun 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISCO
abrir
Metasploit300
MongoDB Ops Manager Diagnostic Archive Sensitive Information Retriever
CVE-2023-0342LOW09 jun 2023
MongoDB Ops Manager may disclose sensitive information in Diagnostic Archive
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALsob ataqueransomware08 jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-35885CRITICAL08 jun 2023
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
85RISCO
abrir
GitHub PoC56
Cloudpanel 0-day Exploit
CVE-2023-35885CRITICAL08 jun 2023
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
85RISCO
abrir
GitHub PoC
hello4r1end/patch_CVE-2023-22809
CVE-2023-22809HIGH08 jun 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir
GitHub PoC
axelbankole/CVE-2012-1495-Webcalendar-
CVE-2012-149508 jun 2023
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user
60RISCO
abrir
GitHub PoC1
CVE: 2021-42013 Tested on: 2.4.49 and 2.4.50 Description: Path Traversal or Remote Code Execution vulnerabilities in Apache 2.4.49 and 2.4.50
CVE-2021-42013CRITICALsob ataqueransomware08 jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC1
This is a reproduction of PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF) vulnerability
CVE-2021-4361708 jun 2023
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Val
28RISCO
abrir
GitHub PoC
Spring rce environment for CVE-2022-22965
CVE-2022-22965CRITICALsob ataque07 jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
anteriorpágina 490 / 2.577próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.