Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8.182Nuclei 4.217Metasploit 3.462✓ só verificadosrecentespopularesrisco
4.217 exploits
Nucleimedium
WP-Lister Lite for Amazon <= 2.6.16 - Cross-Site Scripting
WordPress WP-Lister Lite for Amazon plugin <= 2.6.16 - Reflected Cross Site Scripting (XSS) vulnerability
36RISCO
abrir ↗Nucleicritical
SecurEnvoy Two Factor Authentication - LDAP Injection
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-suppl
63RISCO
abrir ↗Nucleihigh
Electrolink FM/DAB/TV Transmitter (controlloLogin.js) - Credentials Disclosure
Electrolink FM/DAB/TV Transmitter Cleartext Storage of Sensitive Information
36RISCO
abrir ↗Nucleimedium
GnuBoard5 5.5.16 - Open Redirect
An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the in
28RISCO
abrir ↗Nucleihigh
OfficeWeb365 Indexs Interface - Arbitrary File Read
Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 al
36RISCO
abrir ↗Nucleicritical
Craft CMS <=v3.7.31 - SQL Injection
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
48RISCO
abrir ↗Nucleimedium
SiteGuard WP Plugin <= 1.7.6 - Login Page Disclosure
SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measu
28RISCO
abrir ↗Nucleimedium
Base64 Encoder/Decoder <= 0.9.2 - Cross-Site Scripting
Base64 Encoder/Decoder <= 0.9.2 - Reflected XSS
28RISCO
abrir ↗Nucleihigh
TurboMeeting - Post-Authentication Command Injection
A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allow
36RISCO
abrir ↗Nucleicritical
TurboMeeting - Boolean-based SQL Injection
A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x all
55RISCO
abrir ↗Nucleimedium
CodiMD <2.5.4 - Insecure Filename Randomization
CodiMD - Missing Image Access Controls and Unauthorized Image Access
28RISCO
abrir ↗Nucleihigh
Apache HTTPd Windows UNC - Server-Side Request Forgery
Apache HTTP Server on WIndows UNC SSRF
48RISCO
abrir ↗Nucleicritical
Sonicwall - Pre-Authentication Arbitrary File Read
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISCO
abrir ↗Nucleimedium
Uniview NVR301-04S2-P4 - Cross-Site Scripting
Uniview NVR301-04S2-P4 Cross-site Scripting
28RISCO
abrir ↗Nucleihigh
SiYuan <= 3.6.5 - Unauthenticated Path Traversal
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)
36RISCO
abrir ↗Nucleihigh
SiYuan Note <= 3.6.5 - Authentication Bypass
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
43RISCO
abrir ↗Nucleimedium
LobeHub LobeChat <= 2.1.56 - Server-Side Request Forgery
LobeHub: Unauthenticated SSRF in `/webapi/proxy`
43RISCO
abrir ↗Nucleimedium
vLLM <= 0.23.0 - Anthropic Router Heap Address Information Leak
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
28RISCO
abrir ↗Nucleicritical
YMC Filter - SQL Injection
WordPress Filter & Grids plugin <= 3.11.5 - SQL Injection vulnerability
43RISCO
abrir ↗Nucleimedium
Dashy <= 4.3.6 - Reflected XSS via Workspace
Dashy: XSS in workspace url parameter
23RISCO
abrir ↗Nucleimedium
VvvebJs <= 2.0.5 - Cross-Site Scripting
givanz Vvvebjs File Upload Endpoint upload.php cross site scripting
48RISCO
abrir ↗Nucleicritical
Page Builder CK <= 3.5.10 - Unauthenticated Arbitrary File Upload
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
68RISCO
abrir ↗Nucleicritical
Balbooa Forms < 2.4.1 - Unauthenticated Arbitrary File Upload
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
93RISCO
abrir ↗Nucleicritical
Gorse < 0.5.10 - Unauthenticated Database Dump
Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints
63RISCO
abrir ↗Nucleicritical
Drag and Drop Multiple File Upload - CF7 <= 1.3.9.6 - Remote Code Execution
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
56RISCO
abrir ↗Nucleicritical
Dockwatch <= 0.6.567 - OS Command Injection
Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
43RISCO
abrir ↗Nucleicritical
9Router - Unauthenticated LLM Provider API Exposure
9Router 0.4.41 - Unauthenticated API Exposure via /api/providers
43RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.