Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.444exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
77.444 exploits
Exploit-DB
DLink DIR 819 A1 - Denial of Service
CVE-2022-40946HIGHdoshardware25 mar 2023
On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via t
41RISCO
abrir
GitHub PoC4
Joomla Unauthorized Access Vulnerability (CVE-2023-23752) Dockerized
CVE-2023-23752MEDIUMsob ataque25 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
Exploit-DBVexDay Proof
Composr-CMS Version <=10.0.39 - Authenticated Remote Code Execution
CVE-2021-46360webappsphp25 mar 2023
Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrar
23RISCO
abrir
Exploit-DBVexDay Proof
NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
CVE-2022-3142webappsphp25 mar 2023
NEX-Forms < 7.9.7 - Authenticated SQLi
43RISCO
abrir
Exploit-DBVexDay Proof
Abantecart v1.3.2 - Authenticated Remote Code Execution
CVE-2022-26521webappsphp25 mar 2023
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RISCO
abrir
Exploit-DBVexDay Proof
MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution
CVE-2022-26149webappsphp25 mar 2023
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an ex
23RISCO
abrir
Exploit-DB
_camp_ Raspberry Pi camera server 1.0 - Authentication Bypass
CVE-2022-37109CRITICALwebappspython25 mar 2023
patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access
60RISCO
abrir
GitHub PoC
Authenticated Remote Code Execution in Icinga Web 2 <2.8.6, <2.9.6, <2.10
CVE-2022-24715HIGH25 mar 2023
Arbitrary code execution for authenticated users in Icinga Web 2
46RISCO
abrir
Exploit-DB
Password Manager for IIS v2.0 - XSS
CVE-2022-36664MEDIUMwebappsasp25 mar 2023
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMsob ataque25 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
Exploit-DBVexDay Proof
Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)
CVE-2022-35155MEDIUMwebappsphp25 mar 2023
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the s
33RISCO
abrir
GitHub PoC
Brandaoo/CVE-2014-6271
CVE-2014-6271CRITICALsob ataque25 mar 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC1
RSA NetWitness Platform EDR Agent / Incorrect Access Control - Code Execution
CVE-2022-4752924 mar 2023
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Wi
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMsob ataque24 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC1
An exploitation demo of Outlook Elevation of Privilege Vulnerability
CVE-2023-23397CRITICALsob ataque24 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
CVE-2023-23397 powershell patch script for Windows 10 and 11
CVE-2023-23397CRITICALsob ataque24 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC37
MinIO敏感信息泄露漏洞批量扫描poc&exp
CVE-2023-28432HIGHsob ataque24 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
GitHub PoC94
Joomla! < 4.2.8 - Unauthenticated information disclosure
CVE-2023-23752MEDIUMsob ataque24 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC15
CVE-2023-28432 POC
CVE-2023-28432HIGHsob ataque24 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
GitHub PoC6
test of exploit for CVE-2023-21716
CVE-2023-21716CRITICAL24 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC7
CVE-2023-28432,minio未授权访问检测工具
CVE-2023-28432HIGHsob ataque24 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-21716CRITICAL24 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-28432HIGHsob ataque24 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-28432HIGHsob ataque24 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-28432HIGHsob ataque24 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-28432HIGHsob ataque23 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
Exploit-DB
Bitbucket v7.0.0 - RCE
CVE-2022-36804HIGHsob ataquewebappspython23 mar 2023
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC114
Exploit for CVE-2023-27532 against Veeam Backup & Replication
CVE-2023-27532HIGHsob ataqueransomware23 mar 2023
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RISCO
abrir
Exploit-DB
MAN-EAM-0003 V3.2.4 - XXE
CVE-2022-38840HIGHwebappsxml23 mar 2023
cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file uplo
56RISCO
abrir
GitHub PoC8
CVE-2023-28343 POC exploit
CVE-2023-2834323 mar 2023
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISCO
abrir
anteriorpágina 515 / 2.582próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.