Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8.176Nuclei 4.202Metasploit 3.462✓ só verificadosrecentespopularesrisco
4.202 exploits
Nucleimedium
TP-Link Archer A20 v3 Router - Cross-site Scripting
The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listi
28RISCO
abrir ↗Nucleihigh
WpStickyBar <= 2.1.0 - SQL Injection
WpStickyBar <= 2.1.0 - Unauthenticated SQLi
68RISCO
abrir ↗Nucleihigh
SimpleHelp <= 5.5.7 - Unauthenticated Path Traversal
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enabl
100RISCO
abrir ↗Nucleicritical
Yii2 PHP Framework < 2.0.52 - Remote Code Execution
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regres
95RISCO
abrir ↗Nucleicritical
Vanna - SQL injection
Arbitrary File Write by Prompt Injection via DuckDB SQL in vanna-ai/vanna
43RISCO
abrir ↗Nucleicritical
Palo Alto Expedition - Admin Account Takeover
Expedition: Missing Authentication Leads to Admin Account Takeover
100RISCO
abrir ↗Nucleicritical
GiveWP - PHP Object Injection
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISCO
abrir ↗Nucleimedium
Deep Sea Electronics DSE855 - Authentication Bypass
Deep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability
28RISCO
abrir ↗Nucleicritical
CZ Loan Management <= 1.1 - SQL Injection
CZ Loan Management <= 1.1 - Unauthenticated SQLi
43RISCO
abrir ↗Nucleicritical
Quiz Maker <= 6.5.8.3 - SQL Injection
Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
68RISCO
abrir ↗Nucleihigh
Lawo AG vsm LTC Time Sync (vTimeSync) - Path Traversal
Unauthenticated Path Traversal
36RISCO
abrir ↗Nucleimedium
LocalAI - Partial Local File Read
SSRF and Partial LFI in /models/apply Endpoint in mudler/localai
28RISCO
abrir ↗Nucleicritical
Push Notification for Post and BuddyPress <= 1.93 - SQL Injection
Push Notification for Post and BuddyPress <=1.93 - Multiple Unauthenticated SQLi
63RISCO
abrir ↗Nucleimedium
TrakSYS 11.x.x - Sensitive Data Exposure
Parsec Automation TrackSYS pagedefinition direct request
28RISCO
abrir ↗Nucleicritical
PayPlus Payment Gateway < 6.6.9 - SQL Injection
PayPlus Payment Gateway < 6.6.9 - Unauthenticated SQLi
56RISCO
abrir ↗Nucleicritical
WordPress Keydatas ≤ 2.5.2 - Arbitrary File Upload
简数采集器 (Keydatas) <= 2.5.2 - Unauthenticated Arbitrary File Upload
55RISCO
abrir ↗Nucleicritical
NetScaler Console - Sensitive Information Disclosure
Sensitive information disclosure
48RISCO
abrir ↗Nucleihigh
LOLLMS WebUI - Absolute Path Traversal
Absolute Path Traversal in parisneo/lollms-webui
36RISCO
abrir ↗Nucleicritical
UsersWP <= 1.2.10 - Unauthenticated SQL Injection
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL Injection via 'uwp_sort_by'
43RISCO
abrir ↗Nucleimedium
WPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure
WPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure
28RISCO
abrir ↗Nucleihigh
User Profile Builder < 3.11.8 - File Upload
User Profile Builder < 3.11.8 - Unauthenticated Media Upload
68RISCO
abrir ↗Nucleicritical
Aimhubio Aim Server 3.19.3 - Arbitrary File Overwrite
Arbitrary File Overwrite and Data Exfiltration in aimhubio/aim
55RISCO
abrir ↗Nucleihigh
Hide My WP Ghost < 5.2.02 - Hidden Login Page Disclosure
Hide My WP Ghost < 5.2.02 - Hidden Login Page Disclosure
36RISCO
abrir ↗Nucleicritical
WordPress Grow by Tradedoubler Plugin < 2.0.22 - Unauthenticated Local File Inclusion
Grow by Tradedoubler <= 2.0.21 - Unauthenticated LFI
63RISCO
abrir ↗Nucleimedium
Contact Form 7 Math Captcha <= 2.0.1 - Cross-site Scripting
Contact Form 7 Math Captcha <= 2.0.1 - Reflected XSS
28RISCO
abrir ↗Nucleimedium
WP Popups - Information Disclosure
WP Popups – WordPress Popup builder <= 2.2.0.1 - Unauthenticated Full Path Disclosure
28RISCO
abrir ↗Nucleimedium
Campaign Monitor for WordPress - Information Disclosure
Campaign Monitor for WordPress <= 2.8.15 - Unauthenticated Full Path Disclosure
28RISCO
abrir ↗Nucleihigh
Lightdash v0.1024.6 - Server-Side Request Forgery
Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and s
36RISCO
abrir ↗Nucleicritical
SPIP Porte Plume Plugin - Remote Code Execution
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.