Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.447exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
77.448 exploits
VulnCheck XDB
initial-access
CVE-2023-27532HIGHsob ataqueransomware23 mar 2023
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RISCO
abrir
GitHub PoC8
CVE-2022-42475 飞塔RCE漏洞 POC
CVE-2022-42475CRITICALsob ataqueransomware23 mar 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISCO
abrir
Exploit-DB
Bitbucket v7.0.0 - RCE
CVE-2022-36804HIGHsob ataquewebappspython23 mar 2023
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
Exploit-DB
wkhtmltopdf 0.12.6 - Server Side Request Forgery
CVE-2022-35583webappsasp23 mar 2023
wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by inje
28RISCO
abrir
Exploit-DB
MAN-EAM-0003 V3.2.4 - XXE
CVE-2022-38840HIGHwebappsxml23 mar 2023
cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file uplo
56RISCO
abrir
GitHub PoC10
MiniO verify interface sensitive information disclosure vulnerability (CVE-2023-28432)
CVE-2023-28432HIGHsob ataque23 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
GitHub PoC34
CVE-2023-28434 nuclei templates
CVE-2023-28432HIGHsob ataque23 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
GitHub PoC8
CVE-2023-28343 POC exploit
CVE-2023-2834323 mar 2023
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISCO
abrir
GitHub PoC114
Exploit for CVE-2023-27532 against Veeam Backup & Replication
CVE-2023-27532HIGHsob ataqueransomware23 mar 2023
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-28434HIGHsob ataque23 mar 2023
MinIO is vulnerable to privilege escalation on Linux/MacOS
71RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-23397CRITICALsob ataque23 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-2834323 mar 2023
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-23397CRITICALsob ataque22 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2022-41082HIGHsob ataqueransomware22 mar 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
Exploit-DB
Linksys AX3200 V1.1.00 - Command Injection
CVE-2022-38841HIGHwebappshardware22 mar 2023
Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagn
46RISCO
abrir
GitHub PoC14
Python script for sending e-mails with CVE-2023-23397 payload using SMTP
CVE-2023-23397CRITICALsob ataque22 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
Metasploit300
Wordpress Plugin WooCommerce Payments Unauthenticated Admin Creation
CVE-2023-2812122 mar 2023
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RISCO
abrir
Metasploit600
Local Privilege Escalation via CVE-2023-0386
CVE-2023-0386HIGHsob ataque22 mar 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir
GitHub PoC1
Mustafa1986/cve-2022-42475-Fortinet
CVE-2022-42475CRITICALsob ataqueransomware22 mar 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISCO
abrir
GitHub PoC
https & http
CVE-2022-41082HIGHsob ataqueransomware22 mar 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-42475CRITICALsob ataqueransomware22 mar 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISCO
abrir
GitHub PoC1
betillogalvanfbc/POC-CVE-2022-44268
CVE-2022-44268MEDIUM22 mar 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir
GitHub PoC
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
CVE-2022-36193CRITICAL21 mar 2023
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent chang
48RISCO
abrir
GitHub PoC
Mustafa1986/CVE-2022-22963
CVE-2022-22963CRITICALsob ataque21 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC25
Proof of Concept for CVE-2023-23397 in Python
CVE-2023-23397CRITICALsob ataque21 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC6
Altenergy Power System Control Software set_timezone RCE Vulnerability (CVE-2023-28343)
CVE-2023-2834321 mar 2023
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-23397CRITICALsob ataque21 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
local
CVE-2023-21768HIGH21 mar 2023
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALsob ataque21 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-30632HIGHsob ataque21 mar 2023
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISCO
abrir
anteriorpágina 516 / 2.582próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.