Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
4.202 exploits
Nucleihigh
XStream 1.4.18 - Arbitrary Code Execution
XStream is vulnerable to an Arbitrary Code Execution attack
41RISCO
abrir
Nucleihigh
XStream <1.4.18 - Server-Side Request Forgery
A Server-Side Forgery Request vulnerability in XStream via HashMap unmarshaling
41RISCO
abrir
Nucleimedium
Cachet <=2.3.18 - SQL Injection
Unauthenticated SQL Injection
36RISCO
abrir
Nucleimedium
GLPI 9.2/<9.5.6 - Information Disclosure
Disclosure of GLPI and server information in telemetry endpoint
28RISCO
abrir
Nucleihigh
Grafana Snapshot - Authentication Bypass
CVE-2021-39226CRITICALsob ataque
Snapshot authentication bypass in grafana
95RISCO
abrir
Nucleihigh
WordPress True Ranker <2.2.4 - Local File Inclusion
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISCO
abrir
Nucleihigh
WordPress DZS Zoomsounds <=6.50 - Local File Inclusion
ZoomSounds <= 6.45 Unauthenticated Directory Traversal and Sensitive Information Dislosure
68RISCO
abrir
Nucleimedium
WordPress Under Construction <1.19 - Cross-Site Scripting
underConstruction <= 1.18 - Reflected Cross-Site Scripting
28RISCO
abrir
Nucleimedium
WordPress Easy Social Icons Plugin < 3.0.9 - Cross-Site Scripting
Easy Social Icons <= 3.0.8 - Reflected Cross-Site Scripting
28RISCO
abrir
Nucleimedium
WordPress BulletProof Security 5.1 Information Disclosure
BulletProof Security <= 5.1 Sensitive Information Disclosure
70RISCO
abrir
Nucleihigh
OptinMonster Plugin < 2.6.5 - Unprotected REST-API
OptinMonster <= 2.6.4 Unprotected REST-API Endpoints
41RISCO
abrir
Nucleimedium
FV Flowplayer Video Player WordPress plugin - Authenticated Cross-Site Scripting
FV Flowplayer Video Player <= 7.5.0.727 - 7.5.2.727 Reflected Cross-Site Scripting
28RISCO
abrir
Nucleihigh
Hospital Management System 1.0 - Cross-Site Scripting
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searc
18RISCO
abrir
Nucleihigh
BIQS IT Biqs-drive v1.83 Local File Inclusion
A local file inclusion (LFI) vulnerability exists in version BIQS IT Biqs-drive v1.83 and below when sending a specific
18RISCO
abrir
Nucleimedium
EyouCMS 1.5.4 Open Redirect
EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function
18RISCO
abrir
Nucleimedium
Reolink E1 Zoom Camera <=3.0.0.716 - Private Key Disclosure
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory.
18RISCO
abrir
Nucleihigh
Reolink E1 Zoom Camera <=3.0.0.716 - Information Disclosure
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapp
18RISCO
abrir
Nucleimedium
IRTS OP5 Monitor - Cross-Site Scripting
OP5 Monitor 8.3.1, 8.3.2, and OP5 8.3.3 are vulnerable to Cross Site Scripting (XSS).
28RISCO
abrir
Nucleicritical
Cobbler <3.3.0 - Remote Code Execution
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the lo
40RISCO
abrir
Nucleicritical
Apache <= 2.4.48 Mod_Proxy - Server-Side Request Forgery
CVE-2021-40438CRITICALsob ataque
mod_proxy SSRF
100RISCO
abrir
Nucleicritical
Zoho ManageEngine ADSelfService Plus v6113 - Unauthenticated Remote Command Execution
CVE-2021-40539CRITICALsob ataqueransomware
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISCO
abrir
Nucleicritical
Apache Log4j2 Remote Code Injection
CVE-2021-44228CRITICALsob ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Nucleihigh
WAVLINK AC1200 - Information Disclosure
A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can al
18RISCO
abrir
Nucleicritical
3DPrint Lite < 1.9.1.5 - Arbitrary File Upload
3DPrint Lite < 1.9.1.5 - Unauthenticated Arbitrary File Upload
63RISCO
abrir
Nucleicritical
Rosario Student Information System Unauthenticated SQL Injection
An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allow
55RISCO
abrir
Nucleimedium
Apache Superset <=1.3.2 - Default Login
API sensitive information leak
18RISCO
abrir
Nucleihigh
Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization
Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization
36RISCO
abrir
Nucleicritical
ZoomSounds Plugin - Unauthenticated Arbitrary File Upload
ZoomSounds <= 5.96 - Unauthenticated Arbitrary File Upload
43RISCO
abrir
Nucleicritical
Zoho ManageEngine Desktop Central - Remote Code Execution
CVE-2021-44515CRITICALsob ataque
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server
95RISCO
abrir
Nucleimedium
Open Redirect in Host Authorization Middleware
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host"
18RISCO
abrir
anteriorpágina 104 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.