Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.401exploits catalogados
35.511CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.332GitHub PoC 14.209VulnCheck XDB 8.646Nuclei 4.289Metasploit 3.474✓ só verificadosrecentespopularesrisco
77.401 exploits
GitHub PoC★ 3
Unauthenticated RCE in Open Web Analytics version <1.7.4
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISCO
abrir ↗VulnCheck XDB
initial-access
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir ↗VulnCheck XDB
initial-access
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir ↗VulnCheck XDB
initial-access
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir ↗GitHub PoC★ 5
0xNahim/CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗VulnCheck XDB
initial-access
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗GitHub PoC★ 1
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information.
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir ↗Exploit-DB
DLink DIR 819 A1 - Denial of Service
On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via t
41RISCO
abrir ↗VulnCheck XDB
initial-access
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗GitHub PoC
Authenticated Remote Code Execution in Icinga Web 2 <2.8.6, <2.9.6, <2.10
Arbitrary code execution for authenticated users in Icinga Web 2
46RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SimpleMachinesForum v2.1.1 - Authenticated Remote Code Execution
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Abantecart v1.3.2 - Authenticated Remote Code Execution
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
NEX-Forms < 7.9.7 - Authenticated SQLi
43RISCO
abrir ↗GitHub PoC★ 4
Joomla Unauthorized Access Vulnerability (CVE-2023-23752) Dockerized
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗Exploit-DB
_camp_ Raspberry Pi camera server 1.0 - Authentication Bypass
patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the s
33RISCO
abrir ↗Exploit-DB
ImpressCMS v1.4.3 - Authenticated SQL Injection
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this al
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Translatepress Multilinugal WordPress plugin < 2.3.3 - Authenticated SQL Injection
Translatepress Multilinugal < 2.3.3 - Admin+ SQLi
23RISCO
abrir ↗GitHub PoC
Brandaoo/CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗Exploit-DB
Password Manager for IIS v2.0 - XSS
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL
33RISCO
abrir ↗Exploit-DB
NVFLARE < 2.1.4 - Unsafe Deserialization due to Pickle
NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage ma
48RISCO
abrir ↗GitHub PoC★ 1
a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an ex
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Composr-CMS Version <=10.0.39 - Authenticated Remote Code Execution
Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrar
23RISCO
abrir ↗Exploit-DB
System Mechanic v15.5.0.61 - Arbitrary Read/Write
In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerabi
28RISCO
abrir ↗GitHub PoC★ 94
Joomla! < 4.2.8 - Unauthenticated information disclosure
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗GitHub PoC★ 6
test of exploit for CVE-2023-21716
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.