Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.401exploits catalogados
35.511CVEs com exploração pública
24.695testados em laboratório
77.401 exploits
GitHub PoC3
Unauthenticated RCE in Open Web Analytics version <1.7.4
CVE-2022-2463726 mar 2023
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-31814CRITICAL26 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-31814CRITICAL26 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-1653HIGHsob ataque26 mar 2023
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir
GitHub PoC5
0xNahim/CVE-2023-23752
CVE-2023-23752MEDIUMsob ataque26 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC
pumpkinpiteam/CVE-2022-24716
CVE-2022-24716HIGH26 mar 2023
Path traversal in Icinga Web 2
78RISCO
abrir
VulnCheck XDB
infoleak
CVE-2022-24716HIGH26 mar 2023
Path traversal in Icinga Web 2
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMsob ataque26 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC1
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information.
CVE-2019-1653HIGHsob ataque26 mar 2023
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir
Exploit-DB
DLink DIR 819 A1 - Denial of Service
CVE-2022-40946HIGHdoshardware25 mar 2023
On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via t
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMsob ataque25 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque25 mar 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
Authenticated Remote Code Execution in Icinga Web 2 <2.8.6, <2.9.6, <2.10
CVE-2022-24715HIGH25 mar 2023
Arbitrary code execution for authenticated users in Icinga Web 2
46RISCO
abrir
Exploit-DBVexDay Proof
SimpleMachinesForum v2.1.1 - Authenticated Remote Code Execution
CVE-2022-26982webappsphp25 mar 2023
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting
23RISCO
abrir
Exploit-DBVexDay Proof
Abantecart v1.3.2 - Authenticated Remote Code Execution
CVE-2022-26521webappsphp25 mar 2023
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RISCO
abrir
Exploit-DBVexDay Proof
NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
CVE-2022-3142webappsphp25 mar 2023
NEX-Forms < 7.9.7 - Authenticated SQLi
43RISCO
abrir
GitHub PoC4
Joomla Unauthorized Access Vulnerability (CVE-2023-23752) Dockerized
CVE-2023-23752MEDIUMsob ataque25 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
Exploit-DB
_camp_ Raspberry Pi camera server 1.0 - Authentication Bypass
CVE-2022-37109CRITICALwebappspython25 mar 2023
patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access
60RISCO
abrir
Exploit-DBVexDay Proof
Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)
CVE-2022-35155MEDIUMwebappsphp25 mar 2023
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the s
33RISCO
abrir
Exploit-DB
ImpressCMS v1.4.3 - Authenticated SQL Injection
CVE-2022-26986webappsphp25 mar 2023
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this al
23RISCO
abrir
Exploit-DBVexDay Proof
Translatepress Multilinugal WordPress plugin < 2.3.3 - Authenticated SQL Injection
CVE-2022-3141webappsphp25 mar 2023
Translatepress Multilinugal < 2.3.3 - Admin+ SQLi
23RISCO
abrir
GitHub PoC
Brandaoo/CVE-2014-6271
CVE-2014-6271CRITICALsob ataque25 mar 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Exploit-DB
Password Manager for IIS v2.0 - XSS
CVE-2022-36664MEDIUMwebappsasp25 mar 2023
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL
33RISCO
abrir
Exploit-DB
NVFLARE < 2.1.4 - Unsafe Deserialization due to Pickle
CVE-2022-34668CRITICALremotepython25 mar 2023
NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage ma
48RISCO
abrir
GitHub PoC1
a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)
CVE-2019-0708CRITICALsob ataqueransomware25 mar 2023
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
Exploit-DBVexDay Proof
MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution
CVE-2022-26149webappsphp25 mar 2023
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an ex
23RISCO
abrir
Exploit-DBVexDay Proof
Composr-CMS Version <=10.0.39 - Authenticated Remote Code Execution
CVE-2021-46360webappsphp25 mar 2023
Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrar
23RISCO
abrir
Exploit-DB
System Mechanic v15.5.0.61 - Arbitrary Read/Write
CVE-2018-5701localwindows25 mar 2023
In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerabi
28RISCO
abrir
GitHub PoC94
Joomla! < 4.2.8 - Unauthenticated information disclosure
CVE-2023-23752MEDIUMsob ataque24 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC6
test of exploit for CVE-2023-21716
CVE-2023-21716CRITICAL24 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir
anteriorpágina 514 / 2.581próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.