Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
4.217 exploits
Nucleihigh
WordPress Hummingbird <= 3.18.0 - Sensitive Information Exposure via Log File
Hummingbird <= 3.18.0 - Unauthenticated Sensitive Information Exposure via Log File
36RISCO
abrir
Nucleihigh
D-Link DIR-803 - Authentication Bypass
D-Link DIR-803 Configuration getcfg.php information disclosure
28RISCO
abrir
Nucleicritical
Gladinet CentreStack & Triofox - Hardcoded Credentials
CVE-2025-14611HIGHsob ataque
Gladinet CentreStack and TrioFox Hard Coded AES Keys
98RISCO
abrir
Nucleimedium
WordPress Widgets for Social Photo Feed <= 1.8 - Information Disclosure
Widgets for Social Photo Feed <= 1.8 - Missing Authentication to Unauthenticated Plugin Settings Access/Update via trustindex_feed_hook_instagram REST API endpoints
28RISCO
abrir
Nucleicritical
Sangfor OSM - Arbitrary File Upload
Sangfor Operation and Maintenance Management System common.jsp unrestricted upload
28RISCO
abrir
Nucleicritical
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit - Broken Access Control
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation
63RISCO
abrir
Nucleimedium
EasyCVR <=2.1.2 - Information Disclosure
Anhui Xufan Information Technology EasyCVR getbaseconfig information disclosure
28RISCO
abrir
Nucleicritical
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RISCO
abrir
Nucleihigh
Pichome 2.1.0 - Arbitrary File Read
zyx0814 Pichome index.php path traversal
28RISCO
abrir
Nucleicritical
Ingress-Nginx Controller - Remote Code Execution
ingress-nginx admission controller RCE escalation
85RISCO
abrir
Nucleicritical
WordPress JobWP Plugin <= 2.3.9 - SQL Injection
JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin <= 2.3.9 - Unauthenticated SQL Injection
36RISCO
abrir
Nucleihigh
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RISCO
abrir
Nucleicritical
Cisco IOS XE WLC - Arbitrary File Upload
A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client de
68RISCO
abrir
Nucleicritical
Cisco ISE - Remote Code Execution
CVE-2025-20281CRITICALsob ataque
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RISCO
abrir
Nucleimedium
Cisco Secure Firewall ASA & FTD - Authentication Bypass
CVE-2025-20362MEDIUMsob ataque
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Softwar
100RISCO
abrir
Nucleihigh
Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
36RISCO
abrir
Nucleimedium
JoomlaUX JUX Real Estate 3.4.0 - Reflected XSS
JoomlaUX JUX Real Estate realties cross site scripting
28RISCO
abrir
Nucleimedium
Mage AI - Insecure Default Authentication Setup
Mage AI insecure default initialization of resource
28RISCO
abrir
Nucleihigh
WordPress WPCOM Member <= 1.7.6 - SQL Injection
WPCOM Member <= 1.7.6 - Unauthenticated Time-Based SQL Injection
36RISCO
abrir
Nucleicritical
Landray EIS SQL注入漏洞
Landray EIS 2001 through 2006 allows Message/fi_message_receiver.aspx?replyid= SQL injection.
28RISCO
abrir
Nucleihigh
Sante PACS Server.exe - Path Traversal Information Disclosure
Santesoft Sante PACS Server Path Traversal Information Disclosure
48RISCO
abrir
Nucleicritical
Course Booking System <= 6.0.6 - SQL Injection
WordPress Course Booking System plugin <= 6.0.6 - SQL Injection vulnerability
63RISCO
abrir
Nucleicritical
Kubio AI Page Builder <= 2.5.1 - Local File Inclusion
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir
Nucleicritical
Elestio Memos <= v0.24.0 - Server-Side Request Forgery
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplie
43RISCO
abrir
Nucleicritical
Langflow AI - Unauthenticated Remote Code Execution
CVE-2025-3248CRITICALsob ataqueransomware
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
Nucleihigh
EventON Lite <= 2.4 - Authenticated Local File Inclusion
WordPress EventON plugin <= 2.4 - Local File Inclusion vulnerability
36RISCO
abrir
Nucleicritical
Web-Check < 2.0.1 Screenshot API - OS Command Injection
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RISCO
abrir
Nucleihigh
Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_request
An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.
48RISCO
abrir
Nucleicritical
NetMRI Unauthenticated SQL Injection via skipjackUsername
An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.
55RISCO
abrir
Nucleimedium
NetMRI < 7.6.1 - Authentication Bypass via Hardcoded Credentials
An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.
40RISCO
abrir
anteriorpágina 112 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.