Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
4.202 exploits
Nucleihigh
OpenAPI Generator <= 7.5.0 - Arbitrary File Read/Delete
OpenAPI Generator Online - Arbitrary File Read/Delete
36RISCO
abrir
Nucleicritical
Mitel MiCollab <= 9.8.0.33 - SQL Injection
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to cond
75RISCO
abrir
Nucleicritical
Web Directory Free < 1.7.0 - SQL Injection
Web Directory Free < 1.7.0 - Unauthenticated SQL Injection
75RISCO
abrir
Nucleihigh
openSIS < 9.1 - SQL Injection
SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingL
36RISCO
abrir
Nucleimedium
TileServer API - Cross Site Scripting
tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data
28RISCO
abrir
Nucleimedium
WordPress 12 Step Meeting List Plugin <= 3.14.33 - Cross-Site Scripting
WordPress 12 Step Meeting List plugin <= 3.14.33 - Cross Site Scripting (XSS) vulnerability
36RISCO
abrir
Nucleihigh
Wordpress WPMobile.App >= 11.42 - Cross-Site Scripting
WordPress WPMobile.App plugin <= 11.41 - Cross Site Scripting (XSS) vulnerability
36RISCO
abrir
Nucleicritical
WP Hotel Booking <= 2.1.0 - SQL Injection
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
63RISCO
abrir
Nucleicritical
Apache OFBiz - Directory Traversal & Remote Code Execution
Apache OFBiz: Path traversal leading to a RCE
85RISCO
abrir
Nucleihigh
Reposilite >= 3.3.0, < 3.5.12 - Arbitrary File Read
Path traversal while serving Reposilite javadoc expanded files
36RISCO
abrir
Nucleicritical
GeoServer RCE in Evaluating Property Name Expressions
CVE-2024-36401CRITICALsob ataque
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir
Nucleicritical
GeoServer and GeoTools - Remote Code Execution
GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressions
65RISCO
abrir
Nucleicritical
SuiteCRM - SQL Injection
SuiteCRM unauthenticated SQL Injection
43RISCO
abrir
Nucleihigh
Flowise 1.4.3 - Arbitrary File Read
GHSL-2023-232: Flowise Path Injection at /api/v1/openai-assistants-file
56RISCO
abrir
Nucleimedium
Puppeteer Renderer - Directory Traversal
puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter usin
28RISCO
abrir
Nucleihigh
Keycloak < 24.0.5 - Broken Access Control
Keycloak: unguarded admin rest api endpoints allows low privilege users to use administrative functionalities
36RISCO
abrir
Nucleihigh
LyLme spage v1.9.5 - Server-Side Request Forgery
LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.
43RISCO
abrir
Nucleicritical
PrestaShop productsalert - SQL Injection
SQL injection vulnerability in the module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaSho
36RISCO
abrir
Nucleicritical
Web Directory Free < 1.7.3 - Local File Inclusion
Web Directory Free < 1.7.3 - Unauthenticated LFI
63RISCO
abrir
Nucleihigh
CRMEB v.5.2.2 - SQL Injection
SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProduct
28RISCO
abrir
Nucleihigh
Jan v0.4.12 'readFileSync' - Path Traversal
Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.
36RISCO
abrir
Nucleicritical
Jan v0.4.12 - Arbitrary File Upload
An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute
43RISCO
abrir
Nucleihigh
Splunk Enterprise - Local File Inclusion
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISCO
abrir
Nucleicritical
Ollama - Remote Code Execution
Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,
78RISCO
abrir
Nucleimedium
Argo CD Unauthenticated Access to sensitive setting
Unauthenticated Access to sensitive settings in Argo CD
28RISCO
abrir
Nucleimedium
WP Extended < 3.0.0 - Stored Cross-Site Scripting
WordPress WP Extended plugin <= 2.4.7 - Cross Site Scripting (XSS) vulnerability
36RISCO
abrir
Nucleimedium
WP-Lister Lite for Amazon <= 2.6.16 - Cross-Site Scripting
WordPress WP-Lister Lite for Amazon plugin <= 2.6.16 - Reflected Cross Site Scripting (XSS) vulnerability
36RISCO
abrir
Nucleicritical
SecurEnvoy Two Factor Authentication - LDAP Injection
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-suppl
63RISCO
abrir
Nucleihigh
Electrolink FM/DAB/TV Transmitter (controlloLogin.js) - Credentials Disclosure
Electrolink FM/DAB/TV Transmitter Cleartext Storage of Sensitive Information
36RISCO
abrir
Nucleimedium
Hostel < 1.1.5.3 - Cross-Site Scripting
Hostel < 1.1.5.3 - Reflected XSS
28RISCO
abrir
anteriorpágina 105 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.