Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
4.202 exploits
Nucleicritical
Academy LMS 6.2 - SQL Injection
Academy LMS GET Parameter filter sql injection
28RISCO
abrir
Nucleicritical
ChatGPT-Next-Web - SSRF/XSS
NextChat vulnerable to Server-Side Request Forgery and Cross-site Scripting
85RISCO
abrir
Nucleihigh
Active Directory Integration WP Plugin < 4.1.10 - Log Disclosure
Active Directory Integration < 4.1.10 - Unauthenticated Log Disclosure
41RISCO
abrir
Nucleihigh
reNgine 2.2.0 - Command Injection
reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacha
41RISCO
abrir
Nucleimedium
Apache Solr - Host Environment Variables Leak via Metrics API
Apache Solr: Host environment variables are published via the Metrics API
40RISCO
abrir
Nucleicritical
Mingsoft MCMS 5.2.9 - SQL Injection
Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/
43RISCO
abrir
Nucleihigh
XWiki < 4.10.15 - Sensitive Information Disclosure
XWiki Platform Solr search discloses password hashes of all users
58RISCO
abrir
Nucleimedium
XWiki < 4.10.15 - Email Disclosure
XWiki Platform Solr search discloses email addresses of users
40RISCO
abrir
Nucleicritical
D-Link D-View 8 v2.0.1.28 - Authentication Bypass
Authentication Bypass in D-Link D-View 8
55RISCO
abrir
Nucleicritical
JS Help Desk <= 2.8.1 - SQL Injection
WordPress JS Help Desk – Best Help Desk & Support Plugin <= 2.8.1 is vulnerable to SQL Injection
63RISCO
abrir
Nucleimedium
Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)
Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)
28RISCO
abrir
Nucleicritical
MajorDoMo thumb.php - OS Command Injection
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE:
50RISCO
abrir
Nucleihigh
Apache OFBiz < 18.12.11 - Server Side Request Forgery
Apache OFBiz: Arbitrary file properties reading and SSRF attack
30RISCO
abrir
Nucleicritical
Jordy Meow AI Engine - Unrestricted File Upload
WordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability
75RISCO
abrir
Nucleihigh
Gradio Hugging Face - Local File Inclusion
Make the `/file` secure against file traversal attacks
28RISCO
abrir
Nucleihigh
SolarWinds Security Event Manager - Unauthenticated RCE
SolarWinds Security Event Manager Deserialization of Untrusted Data Remote Code Execution Vulnerability
78RISCO
abrir
Nucleicritical
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
43RISCO
abrir
Nucleihigh
Monitorr Services Configuration - Arbitrary File Upload
15RISCO
abrir
Nucleicritical
Arcserve Unified Data Protection - Authentication Bypass
Authentication Bypass via wizardLogin in Arcserve Unified Data Protection
43RISCO
abrir
Nucleihigh
Arcserve Unified Data Protection - Unauthenticated DoS in ASNative.dll
Unauthenticated DoS in Arcserve Unified Data Protection
48RISCO
abrir
Nucleimedium
Combo Blocks < 2.2.76 - Improper Access Control
Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access
33RISCO
abrir
Nucleicritical
Smart S210 Management Platform - Arbitary File Upload
Byzoro Smart S210 Management Platform uploadfile.php unrestricted upload
40RISCO
abrir
Nucleimedium
Issabel Authenticated - Remote Code Execution
Issabel PBX Asterisk-Cli os command injection
40RISCO
abrir
Nucleicritical
CodeChecker <= 6.24.1 - Authentication Bypass
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
55RISCO
abrir
Nucleimedium
Simple File List < 6.1.13 - Reflected Cross-Site Scripting
Simple File List < 6.1.13 - Reflected Cross-Site Scripting
28RISCO
abrir
Nucleihigh
Simple Certain Time to Show Content - Cross-Site Scripting
Simple Certain Time to Show Content < 1.3.1 - Reflected XSS
36RISCO
abrir
Nucleicritical
Rebuild <= 3.5.5 - Server-Side Request Forgery
Rebuild HTTP Request readRawText server-side request forgery
40RISCO
abrir
Nucleihigh
Tutor LMS <= 2.7.6 - SQL Injection
Tutor LMS <= 2.7.6 - Unauthenticated SQL Injection via rating_filter
78RISCO
abrir
Nucleimedium
Google for WooCommerce <= 2.8.6 - Information Disclosure via Publicly Accessible PHP Info File
Google for WooCommerce <= 2.8.6 - Information Disclosure via Publicly Accessible PHP Info File
28RISCO
abrir
Nucleihigh
Swift Performance Lite < 2.3.7.2 - Local PHP File Inclusion
Swift Performance Lite <= 2.3.7.1 - Unauthenticated Local PHP File Inclusion via 'ajaxify'
36RISCO
abrir
anteriorpágina 106 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.