Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8.176Nuclei 4.202Metasploit 3.462✓ só verificadosrecentespopularesrisco
4.202 exploits
Nucleihigh
OpenAPI Generator <= 7.5.0 - Arbitrary File Read/Delete
OpenAPI Generator Online - Arbitrary File Read/Delete
36RISCO
abrir ↗Nucleicritical
Mitel MiCollab <= 9.8.0.33 - SQL Injection
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to cond
75RISCO
abrir ↗Nucleicritical
Web Directory Free < 1.7.0 - SQL Injection
Web Directory Free < 1.7.0 - Unauthenticated SQL Injection
75RISCO
abrir ↗Nucleihigh
openSIS < 9.1 - SQL Injection
SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingL
36RISCO
abrir ↗Nucleimedium
TileServer API - Cross Site Scripting
tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data
28RISCO
abrir ↗Nucleimedium
WordPress 12 Step Meeting List Plugin <= 3.14.33 - Cross-Site Scripting
WordPress 12 Step Meeting List plugin <= 3.14.33 - Cross Site Scripting (XSS) vulnerability
36RISCO
abrir ↗Nucleihigh
Wordpress WPMobile.App >= 11.42 - Cross-Site Scripting
WordPress WPMobile.App plugin <= 11.41 - Cross Site Scripting (XSS) vulnerability
36RISCO
abrir ↗Nucleicritical
WP Hotel Booking <= 2.1.0 - SQL Injection
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
63RISCO
abrir ↗Nucleicritical
Apache OFBiz - Directory Traversal & Remote Code Execution
Apache OFBiz: Path traversal leading to a RCE
85RISCO
abrir ↗Nucleihigh
Reposilite >= 3.3.0, < 3.5.12 - Arbitrary File Read
Path traversal while serving Reposilite javadoc expanded files
36RISCO
abrir ↗Nucleicritical
GeoServer RCE in Evaluating Property Name Expressions
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗Nucleicritical
GeoServer and GeoTools - Remote Code Execution
GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressions
65RISCO
abrir ↗Nucleihigh
Flowise 1.4.3 - Arbitrary File Read
GHSL-2023-232: Flowise Path Injection at /api/v1/openai-assistants-file
56RISCO
abrir ↗Nucleimedium
Puppeteer Renderer - Directory Traversal
puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter usin
28RISCO
abrir ↗Nucleihigh
Keycloak < 24.0.5 - Broken Access Control
Keycloak: unguarded admin rest api endpoints allows low privilege users to use administrative functionalities
36RISCO
abrir ↗Nucleihigh
LyLme spage v1.9.5 - Server-Side Request Forgery
LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.
43RISCO
abrir ↗Nucleicritical
PrestaShop productsalert - SQL Injection
SQL injection vulnerability in the module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaSho
36RISCO
abrir ↗Nucleicritical
Web Directory Free < 1.7.3 - Local File Inclusion
Web Directory Free < 1.7.3 - Unauthenticated LFI
63RISCO
abrir ↗Nucleihigh
CRMEB v.5.2.2 - SQL Injection
SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProduct
28RISCO
abrir ↗Nucleihigh
Jan v0.4.12 'readFileSync' - Path Traversal
Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.
36RISCO
abrir ↗Nucleicritical
Jan v0.4.12 - Arbitrary File Upload
An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute
43RISCO
abrir ↗Nucleihigh
Splunk Enterprise - Local File Inclusion
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISCO
abrir ↗Nucleicritical
Ollama - Remote Code Execution
Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,
78RISCO
abrir ↗Nucleimedium
Argo CD Unauthenticated Access to sensitive setting
Unauthenticated Access to sensitive settings in Argo CD
28RISCO
abrir ↗Nucleimedium
WP Extended < 3.0.0 - Stored Cross-Site Scripting
WordPress WP Extended plugin <= 2.4.7 - Cross Site Scripting (XSS) vulnerability
36RISCO
abrir ↗Nucleimedium
WP-Lister Lite for Amazon <= 2.6.16 - Cross-Site Scripting
WordPress WP-Lister Lite for Amazon plugin <= 2.6.16 - Reflected Cross Site Scripting (XSS) vulnerability
36RISCO
abrir ↗Nucleicritical
SecurEnvoy Two Factor Authentication - LDAP Injection
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-suppl
63RISCO
abrir ↗Nucleihigh
Electrolink FM/DAB/TV Transmitter (controlloLogin.js) - Credentials Disclosure
Electrolink FM/DAB/TV Transmitter Cleartext Storage of Sensitive Information
36RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.