Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
4.217 exploits
Nucleimedium
iTop Hub Connector - Information Disclosure
iTop hub connector Information disclosure
28RISCO
abrir
Nucleicritical
Lobe Chat <= v0.150.5 - Server-Side Request Forgery
lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability
55RISCO
abrir
Nucleicritical
Delmia Apriso - Pre-Authentication Unsafe .NET Object Deserialization
Pre-authentication Unsafe .NET object deserialization vulnerability affecting DELMIA Apriso Release 2019 through Release 2024
43RISCO
abrir
Nucleimedium
D-LINK DIR-845L bsc_sms_inbox.php file - Information Disclosure
D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.
28RISCO
abrir
Nucleihigh
Prison Management System - SQL Injection Authentication Bypass
Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the
56RISCO
abrir
Nucleimedium
LumisXP - Cross-site Scripting
A cross-site scripting (XSS) vulnerability in the component XsltResultControllerHtml.jsp of Lumisxp v15.0.x to v16.1.x a
28RISCO
abrir
Nucleimedium
User Meta WP Plugin < 3.1 - Sensitive Information Exposure
WordPress User Meta plugin <= 3.0 - Sensitive Data Exposure vulnerability
28RISCO
abrir
Nucleihigh
Sharp Multifunction Printers - Directory Listing
Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for th
36RISCO
abrir
Nucleimedium
Sharp Multifunction Printers - Cookie Exposure
"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides log
55RISCO
abrir
Nucleimedium
SOPlanning 1.52.00 Cross Site Scripting
SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.
48RISCO
abrir
Nucleimedium
iboss Secure Web Gateway - Stored Cross-Site Scripting
iboss Secure Web Gateway Login Portal login cross site scripting
33RISCO
abrir
Nucleimedium
OneNav v0.9.35-20240318 - Server-Side Request Forgery (SSRF)
OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=ap
28RISCO
abrir
Nucleimedium
Masteriyo LMS <= 1.7.3 - Insecure Direct Object Reference
WordPress LMS by Masteriyo plugin <= 1.7.3 - Broken Authentication vulnerability
28RISCO
abrir
Nucleicritical
GlobalProtect - OS Command Injection
CVE-2024-3400CRITICALsob ataqueransomware
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir
Nucleimedium
Changedetection.io <=v0.45.21 - Cross-Site Scripting
Reflected cross site scripting in changedetection.io
28RISCO
abrir
Nucleicritical
D-Tale 3.10.0 - 3.15.1 - Authentication Bypass & Remote Code Execution
Authentication Bypass and RCE in man-group/dtale
85RISCO
abrir
Nucleicritical
Adobe Commerce & Magento - CosmicSting
CVE-2024-34102CRITICALsob ataque
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
Nucleihigh
TOTOLINK EX1800T TOTOLINK EX1800T - Command Injection
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized e
43RISCO
abrir
Nucleihigh
Next.js - Server Side Request Forgery (SSRF)
Next.js Server-Side Request Forgery in Server Actions
36RISCO
abrir
Nucleihigh
HSC Mailinspector 5.2.17-3 through 5.2.18 - Local File Inclusion
An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability
36RISCO
abrir
Nucleimedium
GP Premium <= 2.4.0 - Cross-Site Scripting
GP Premium <= 2.4.0 - Reflected Cross-Site Scripting
28RISCO
abrir
Nucleicritical
Wordpress Country State City Dropdown <=2.7.2 - SQL Injection
Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
68RISCO
abrir
Nucleihigh
LyLme-Spage - Arbitary File Upload
An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to exec
43RISCO
abrir
Nucleihigh
OpenAPI Generator <= 7.5.0 - Arbitrary File Read/Delete
OpenAPI Generator Online - Arbitrary File Read/Delete
36RISCO
abrir
Nucleicritical
Mitel MiCollab <= 9.8.0.33 - SQL Injection
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to cond
75RISCO
abrir
Nucleicritical
Web Directory Free < 1.7.0 - SQL Injection
Web Directory Free < 1.7.0 - Unauthenticated SQL Injection
75RISCO
abrir
Nucleihigh
openSIS < 9.1 - SQL Injection
SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingL
36RISCO
abrir
Nucleihigh
NextChat - Server-Side Request Forgery
NextChat Server-Side Request Forgery (SSRF)
36RISCO
abrir
Nucleihigh
Ivanti Avalanche SmartDeviceServer - XML External Entity
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on t
58RISCO
abrir
Nucleicritical
FormLift for Infusionsoft Web Forms <= 7.5.17 - SQL Injection
WordPress formlift plugin <= 7.5.17 - Unauthenticated Blind SQL Injection vulnerability
43RISCO
abrir
anteriorpágina 124 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.