Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8.182Nuclei 4.217Metasploit 3.462✓ só verificadosrecentespopularesrisco
4.217 exploits
Nucleicritical
SAP Memory Pipes (MPI) Desynchronization
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISCO
abrir ↗Nucleimedium
Apache ShardingSphere ElasticJob-UI privilege escalation
Access-Token in ElasticJob UI causes password disclosure
30RISCO
abrir ↗Nucleicritical
PrestaShop AP Pagebuilder <= 2.4.4 - SQL Injection
A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder
23RISCO
abrir ↗Nucleimedium
Transposh WordPress Translation <= 1.0.8 - Unauthenticated Settings Change
Transposh WordPress Translation <= 1.0.9.6 - Unauthorized Settings Change
28RISCO
abrir ↗Nucleimedium
WordPress Transposh <=1.0.8.1 - Information Disclosure
Transposh WordPress Translation <= 1.0.9.6 - Sensitive Information Disclosure
28RISCO
abrir ↗Nucleicritical
AudioCodes Device Manager Express - SQL Injection
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injec
68RISCO
abrir ↗Nucleicritical
Open Web Analytics 1.7.3 - Remote Code Execution
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISCO
abrir ↗Nucleicritical
Garage Management System 1.0 - SQL Injection
SourceCodester Garage Management System login.php sql injection
36RISCO
abrir ↗Nucleimedium
ManageEngine ADSelfService Plus <6121 - Stored Cross-Site Scripting
Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock
18RISCO
abrir ↗Nucleimedium
Zimbra Collaboration Suite < 8.8.15 - Improper Encoding
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), a
70RISCO
abrir ↗Nucleicritical
GeoServer <1.2.2 - Remote Code Execution
Improper Control of Generation of Code in jai-ext
100RISCO
abrir ↗Nucleimedium
XWiki < 12.10.11, 13.4.4 & 13.9-rc-1 - Information Disclosure
Unauthenticated user can retrieve the list of users through uorgsuggest.vm
28RISCO
abrir ↗Nucleihigh
Flyte Console <0.52.0 - Server-Side Request Forgery
Server-Side Request Forgery in FlyteConsole
48RISCO
abrir ↗Nucleicritical
Wavlink WN535K2/WN535K3 - OS Command Injection
WAVLINK WN535K2/WN535K3 os command injection
41RISCO
abrir ↗Nucleicritical
Wavlink WN535K2/WN535K3 - OS Command Injection
WAVLINK WN535K2/WN535K3 nightled.cgi os command injection
58RISCO
abrir ↗Nucleicritical
Wavlink WN535K2/WN535K3 - OS Command Injection
WAVLINK WN535K2/WN535K3 touchlist_sync.cgi os command injection
48RISCO
abrir ↗Nucleimedium
Contao <4.13.3 - Cross-Site Scripting
Cross site scripting via canonical tag
36RISCO
abrir ↗Nucleihigh
Piano LED Visualizer 1.3 - Local File Inclusion
Absolute Path Traversal due to incorrect use of `send_file` call in Piano LED Visualizer
43RISCO
abrir ↗Nucleihigh
TerraMaster TOS < 4.2.30 Server Information Disclosure
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RISCO
abrir ↗Nucleicritical
TP-Link TL-WR840N - Command Injection
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_set
30RISCO
abrir ↗Nucleicritical
TOTOLink - Unauthenticated Command Injection
TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerab
23RISCO
abrir ↗Nucleicritical
MCMS 5.2.4 - SQL Injection
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
18RISCO
abrir ↗Nucleicritical
WordPress Plugin WP Statistics <= 13.1.5 - SQL Injection
WP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via current_page_id
85RISCO
abrir ↗Nucleihigh
WordPress Plugin WP Statistics <= 13.1.5 - SQL Injection
WP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via IP
65RISCO
abrir ↗Nucleihigh
DVDFab 12 Player/PlayerFab - Local File Inclusion
An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for wh
23RISCO
abrir ↗Nucleicritical
ThinVNC - Authentication Bypass
ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?
23RISCO
abrir ↗Nucleicritical
Bonita Web 2021.2 - Authentication/Authorization Bypass
Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude patt
30RISCO
abrir ↗Nucleicritical
ZEROF Web Server 2.0 - SQL Injection
ZEROF Web Server 2.0 allows /HandleEvent SQL Injection.
18RISCO
abrir ↗Nucleimedium
ZEROF Web Server 2.0 - Cross-Site Scripting
ZEROF Web Server 2.0 allows /admin.back XSS.
18RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.