Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8.182Nuclei 4.217Metasploit 3.462✓ só verificadosrecentespopularesrisco
4.217 exploits
Nucleihigh
WordPress Hummingbird <= 3.18.0 - Sensitive Information Exposure via Log File
Hummingbird <= 3.18.0 - Unauthenticated Sensitive Information Exposure via Log File
36RISCO
abrir ↗Nucleihigh
D-Link DIR-803 - Authentication Bypass
D-Link DIR-803 Configuration getcfg.php information disclosure
28RISCO
abrir ↗Nucleicritical
Gladinet CentreStack & Triofox - Hardcoded Credentials
Gladinet CentreStack and TrioFox Hard Coded AES Keys
98RISCO
abrir ↗Nucleimedium
WordPress Widgets for Social Photo Feed <= 1.8 - Information Disclosure
Widgets for Social Photo Feed <= 1.8 - Missing Authentication to Unauthenticated Plugin Settings Access/Update via trustindex_feed_hook_instagram REST API endpoints
28RISCO
abrir ↗Nucleicritical
Sangfor OSM - Arbitrary File Upload
Sangfor Operation and Maintenance Management System common.jsp unrestricted upload
28RISCO
abrir ↗Nucleicritical
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit - Broken Access Control
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation
63RISCO
abrir ↗Nucleimedium
EasyCVR <=2.1.2 - Information Disclosure
Anhui Xufan Information Technology EasyCVR getbaseconfig information disclosure
28RISCO
abrir ↗Nucleicritical
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RISCO
abrir ↗Nucleicritical
Ingress-Nginx Controller - Remote Code Execution
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗Nucleicritical
WordPress JobWP Plugin <= 2.3.9 - SQL Injection
JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin <= 2.3.9 - Unauthenticated SQL Injection
36RISCO
abrir ↗Nucleihigh
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RISCO
abrir ↗Nucleicritical
Cisco IOS XE WLC - Arbitrary File Upload
A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client de
68RISCO
abrir ↗Nucleicritical
Cisco ISE - Remote Code Execution
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RISCO
abrir ↗Nucleimedium
Cisco Secure Firewall ASA & FTD - Authentication Bypass
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Softwar
100RISCO
abrir ↗Nucleihigh
Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
36RISCO
abrir ↗Nucleimedium
JoomlaUX JUX Real Estate 3.4.0 - Reflected XSS
JoomlaUX JUX Real Estate realties cross site scripting
28RISCO
abrir ↗Nucleimedium
Mage AI - Insecure Default Authentication Setup
Mage AI insecure default initialization of resource
28RISCO
abrir ↗Nucleihigh
WordPress WPCOM Member <= 1.7.6 - SQL Injection
WPCOM Member <= 1.7.6 - Unauthenticated Time-Based SQL Injection
36RISCO
abrir ↗Nucleicritical
Landray EIS SQL注入漏洞
Landray EIS 2001 through 2006 allows Message/fi_message_receiver.aspx?replyid= SQL injection.
28RISCO
abrir ↗Nucleihigh
Sante PACS Server.exe - Path Traversal Information Disclosure
Santesoft Sante PACS Server Path Traversal Information Disclosure
48RISCO
abrir ↗Nucleicritical
Course Booking System <= 6.0.6 - SQL Injection
WordPress Course Booking System plugin <= 6.0.6 - SQL Injection vulnerability
63RISCO
abrir ↗Nucleicritical
Kubio AI Page Builder <= 2.5.1 - Local File Inclusion
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir ↗Nucleicritical
Elestio Memos <= v0.24.0 - Server-Side Request Forgery
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplie
43RISCO
abrir ↗Nucleicritical
Langflow AI - Unauthenticated Remote Code Execution
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗Nucleihigh
EventON Lite <= 2.4 - Authenticated Local File Inclusion
WordPress EventON plugin <= 2.4 - Local File Inclusion vulnerability
36RISCO
abrir ↗Nucleicritical
Web-Check < 2.0.1 Screenshot API - OS Command Injection
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RISCO
abrir ↗Nucleihigh
Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_request
An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.
48RISCO
abrir ↗Nucleicritical
NetMRI Unauthenticated SQL Injection via skipjackUsername
An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.
55RISCO
abrir ↗Nucleimedium
NetMRI < 7.6.1 - Authentication Bypass via Hardcoded Credentials
An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.
40RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.