Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.401exploits catalogados
35.511CVEs com exploração pública
24.695testados em laboratório
77.401 exploits
VulnCheck XDB
initial-access
CVE-2019-908125 abr 2023
20RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-22621CRITICAL25 abr 2023
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitra
85RISCO
abrir
GitHub PoC
2022 Spring Prof. 謝續平
CVE-2022-21907CRITICAL25 abr 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALsob ataqueransomware25 abr 2023
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC
ShyTangerine/cve-2021-26855
CVE-2021-26855CRITICALsob ataqueransomware25 abr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-27524HIGHsob ataque25 abr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-41277CRITICALsob ataque24 abr 2023
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISCO
abrir
Metasploit600
Ivanti Avalanche FileStoreConfig File Upload
CVE-2023-28128HIGH24 abr 2023
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could
58RISCO
abrir
GitHub PoC1
RubXkuB/PoC-Metabase-CVE-2021-41277
CVE-2021-41277CRITICALsob ataque24 abr 2023
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISCO
abrir
Metasploit600
invscout RPM Privilege Escalation
CVE-2023-28528HIGH24 abr 2023
IBM AIX command execution
36RISCO
abrir
GitHub PoC13
CVE-2023-22894
CVE-2023-22894CRITICAL24 abr 2023
Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting
48RISCO
abrir
GitHub PoC16
CVE-2023-1671-POC, based on dnslog platform
CVE-2023-1671CRITICALsob ataque24 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISCO
abrir
GitHub PoC
andyhsu024/CVE-2021-29447
CVE-2021-29447HIGH24 abr 2023
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-1671CRITICALsob ataque24 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISCO
abrir
GitHub PoC
msd0pe-1/CVE-2023-31747
CVE-2023-31747HIGH24 abr 2023
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-1671CRITICALsob ataque23 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALsob ataqueransomware23 abr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-40799HIGHsob ataque23 abr 2023
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS l
83RISCO
abrir
GitHub PoC1
glen-pearson/ProxyLogon-CVE-2021-26855
CVE-2021-26855CRITICALsob ataqueransomware23 abr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC3
Pre-Auth RCE in Sophos Web Appliance
CVE-2023-1671CRITICALsob ataque23 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISCO
abrir
GitHub PoC1
Exploit for CVE-2022-1609 WordPress Weblizar Backdoor.
CVE-2022-1609CRITICAL22 abr 2023
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALsob ataqueransomware22 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-1609CRITICAL22 abr 2023
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RISCO
abrir
GitHub PoC55
Proof of Concept Exploit for PaperCut CVE-2023-27350
CVE-2023-27350CRITICALsob ataqueransomware22 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
GitHub PoC2
「💥」CVE-2022-4944: KodExplorer <= 4.49 - CSRF to Arbitrary File Upload
CVE-2022-4944MEDIUM21 abr 2023
kalcaddle KodExplorer cross-site request forgery
33RISCO
abrir
Metasploit300
Piwigo CVE-2023-26876 Gather Credentials via SQL Injection
CVE-2023-26876HIGH21 abr 2023
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via t
36RISCO
abrir
GitHub PoC12
imancybersecurity/CVE-2023-27350-POC
CVE-2023-27350CRITICALsob ataqueransomware21 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
GitHub PoC
Anonimo501/ssh_enum_users_CVE-2018-15473
CVE-2018-15473MEDIUM21 abr 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-1454MEDIUM21 abr 2023
jeecg-boot qurestSql sql injection
60RISCO
abrir
GitHub PoC5
A simple python script to check if a service is vulnerable
CVE-2023-27350CRITICALsob ataqueransomware21 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
anteriorpágina 504 / 2.581próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.