Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.449exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
77.449 exploits
GitHub PoC9
Exploit to CVE-2022-46169 vulnerability
CVE-2022-46169CRITICALsob ataque13 jan 2023
Unauthenticated Command Injection
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-21661HIGH13 jan 2023
SQL injection in WordPress
78RISCO
abrir
GitHub PoC1
CVE 2022-45299
CVE-2022-45299CRITICAL13 jan 2023
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplyi
48RISCO
abrir
Metasploit300
Wordpress Paid Membership Pro code Unauthenticated SQLi
CVE-2023-23488CRITICAL12 jan 2023
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RISCO
abrir
GitHub PoC2
cve-2010-1622 Learning Environment
CVE-2010-162211 jan 2023
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-48323CRITICAL10 jan 2023
Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A
75RISCO
abrir
GitHub PoC326
Wh04m1001/CVE-2023-21752
CVE-2023-21752HIGH10 jan 2023
Windows Backup Service Elevation of Privilege Vulnerability
41RISCO
abrir
Metasploit600
ManageEngine Endpoint Central Unauthenticated SAML RCE
CVE-2022-47966CRITICALsob ataqueransomware10 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir
Metasploit600
Ancillary Function Driver (AFD) for WinSock Elevation of Privilege
CVE-2023-21768HIGH10 jan 2023
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISCO
abrir
Metasploit600
ManageEngine ADSelfService Plus Unauthenticated SAML RCE
CVE-2022-47966CRITICALsob ataqueransomware10 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir
Metasploit600
ManageEngine ServiceDesk Plus Unauthenticated SAML RCE
CVE-2022-47966CRITICALsob ataqueransomware10 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir
GitHub PoC
CVE-2021-29447 - Authenticated XXE Injection - WordPress < 5.7.1 & PHP > 8
CVE-2021-29447HIGH10 jan 2023
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC
CVE-2017-16995 Linux POC
CVE-2017-1699509 jan 2023
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
GitHub PoC
G01d3nW01f/CVE-2021-43798
CVE-2021-43798HIGHsob ataque09 jan 2023
Grafana path traversal
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2022-23131CRITICALsob ataque09 jan 2023
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir
GitHub PoC28
CVE-2023-0297: The Story of Finding Pre-auth RCE in pyLoad
CVE-2023-0297CRITICAL09 jan 2023
Code Injection in pyload/pyload
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-0297CRITICAL09 jan 2023
Code Injection in pyload/pyload
85RISCO
abrir
GitHub PoC
zabbix saml bypass
CVE-2022-23131CRITICALsob ataque09 jan 2023
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2018-999509 jan 2023
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
GitHub PoC1
.NET console application that exploits CVE-2018-9995 vulnerability
CVE-2018-999509 jan 2023
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
GitHub PoC
CVE-2017-7308 POC
CVE-2017-730809 jan 2023
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer
43RISCO
abrir
GitHub PoC
Sophos EXploit
CVE-2022-1040CRITICALsob ataque08 jan 2023
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-1040CRITICALsob ataque08 jan 2023
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISCO
abrir
GitHub PoC26
Dell Driver EoP (CVE-2021-21551)
CVE-2021-21551HIGHsob ataque07 jan 2023
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISCO
abrir
GitHub PoC2
CVE-2018-19321
CVE-2018-19321HIGHsob ataqueransomware07 jan 2023
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, X
71RISCO
abrir
GitHub PoC1
wr0x00/cve-2022-23131
CVE-2022-23131CRITICALsob ataque07 jan 2023
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-23131CRITICALsob ataque07 jan 2023
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-21551HIGHsob ataque07 jan 2023
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISCO
abrir
GitHub PoC11
Proof of concept for the command injection vulnerability affecting the ZTE MF286R router, including an RCE exploit.
CVE-2022-39073CRITICAL07 jan 2023
There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an att
48RISCO
abrir
GitHub PoC37
CVE-2021-38003 exploits extracted from https://twitter.com/WhichbufferArda/status/1609604183535284224
CVE-2021-38003HIGHsob ataque07 jan 2023
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially explo
83RISCO
abrir
anteriorpágina 530 / 2.582próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.