Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.401exploits catalogados
35.511CVEs com exploração pública
24.695testados em laboratório
77.401 exploits
Exploit-DB
Gin Markdown Editor v0.7.4 (Electron) - Arbitrary Code Execution
CVE-2023-31873HIGHlocalmultiple23 mai 2023
Gin 0.7.4 allows execution of arbitrary code when a crafted file is opened, e.g., via require('child_process').
41RISCO
abrir
GitHub PoC
manavvedawala2/CVE-2023-32243-proof-of-concept
CVE-2023-32243CRITICAL23 mai 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir
Exploit-DB
eScan Management Console 14.0.1400.2281 - Cross Site Scripting
CVE-2023-31703CRITICALwebappswindows23 mai 2023
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allo
48RISCO
abrir
VulnCheck XDB
local
CVE-2023-32784HIGH23 mai 2023
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISCO
abrir
Metasploit600
Apache RocketMQ update config RCE
CVE-2023-33246CRITICALsob ataque23 mai 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir
Exploit-DB
Optoma 1080PSTX Firmware C02 - Authentication Bypass
CVE-2023-27823CRITICALremotehardware23 mai 2023
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid cr
60RISCO
abrir
Metasploit300
GitLab Authenticated File Read
CVE-2023-2825CRITICAL23 mai 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISCO
abrir
Metasploit600
Barracuda ESG TAR Filename Command Injection
CVE-2023-2868CRITICALsob ataque23 mai 2023
Remote Code injection in Barracuda Email Security Gateway
100RISCO
abrir
Exploit-DB
ChurchCRM v4.5.4 - Reflected XSS via Image (Authenticated)
CVE-2023-31699MEDIUMwebappsphp23 mai 2023
ChurchCRM v4.5.4 is vulnerable to Reflected Cross-Site Scripting (XSS) via image file.
33RISCO
abrir
Exploit-DB
PnPSCADA v2.x - Unauthenticated PostgreSQL Injection
CVE-2023-1934CRITICALwebappshardware23 mai 2023
The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL
48RISCO
abrir
Exploit-DB
Apache Superset 2.0.0 - Authentication Bypass
CVE-2023-27524HIGHsob ataquewebappsmultiple23 mai 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-1949223 mai 2023
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-1949223 mai 2023
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-1949223 mai 2023
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-32243CRITICAL23 mai 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir
Exploit-DB
FusionInvoice 2023-1.0 - Stored XSS (Cross-Site Scripting)
CVE-2023-25439MEDIUMwebappsmultiple23 mai 2023
Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitr
33RISCO
abrir
Exploit-DBVexDay Proof
GetSimple CMS v3.3.16 - Remote Code Execution (RCE)
CVE-2022-41544HIGHwebappsphp23 mai 2023
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file paramete
41RISCO
abrir
GitHub PoC30
PoC for CVE-2023-28771 based on Rapid7's excellent writeup
CVE-2023-28771CRITICALsob ataque23 mai 2023
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RISCO
abrir
Exploit-DBVexDay Proof
Bludit CMS v3.14.1 - Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2023-31698webappsphp23 mai 2023
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's securit
23RISCO
abrir
Exploit-DB
Yank Note v3.52.1 (Electron) - Arbitrary Code Execution
CVE-2023-31874HIGHlocalmultiple23 mai 2023
Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_pro
41RISCO
abrir
GitHub PoC286
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerability.
CVE-2023-25690CRITICAL22 mai 2023
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISCO
abrir
VulnCheck XDB
local
CVE-2023-32784HIGH22 mai 2023
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISCO
abrir
GitHub PoC
Dockerized POC for CVE-2022-42889 Text4Shell
CVE-2022-4288922 mai 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-25690CRITICAL22 mai 2023
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-4288922 mai 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC1
vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption
CVE-2007-596222 mai 2023
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 throug
28RISCO
abrir
GitHub PoC
This little script encrypts password to gpp cpassword. It useful to create vulnerable lab AD (CVE-2014-1812).
CVE-2014-1812HIGHsob ataqueransomware22 mai 2023
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo
98RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALsob ataque21 mai 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
antisecc/CVE-2022-46169
CVE-2022-46169CRITICALsob ataque21 mai 2023
Unauthenticated Command Injection
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHsob ataque21 mai 2023
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
anteriorpágina 497 / 2.581próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.