Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
4.217 exploits
Nucleicritical
Cisco SSM On-Prem <= 8-202206 - Password Reset Account Takeover
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauth
85RISCO
abrir
Nucleicritical
Hardcoded Admin Credentials For Cisco Smart Licensing Utility API
CVE-2024-20439CRITICALsob ataque
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an a
95RISCO
abrir
Nucleihigh
Cisco Smart Licensing Utility UnAuthenticated Logs Exposure Leaking Plaintext Credentials
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive inf
48RISCO
abrir
Nucleihigh
Artica Proxy - Unauthenticated LFI
Artica Proxy Unauthenticated LFI Protection Bypass Vulnerability
68RISCO
abrir
Nucleihigh
Adobe ColdFusion - Arbitrary File Read
CVE-2024-20767HIGHsob ataque
ColdFusion | Improper Access Control (CWE-284)
100RISCO
abrir
Nucleihigh
Oracle Retail Xstore Suite - Pre-authenticated Path Traversal
Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported
36RISCO
abrir
Nucleimedium
Dash Framework - Cross-site Scripting
Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; v
28RISCO
abrir
Nucleihigh
MobSF - Path Traversal
Arbitrary file write on Decoding
36RISCO
abrir
Nucleimedium
Flarum < 1.8.5 - Open Redirect
Flarum's Logout Route allows open redirects
28RISCO
abrir
Nucleihigh
pyLoad Flask Config - Access Control
pyLoad unauthenticated flask configuration leakage
48RISCO
abrir
Nucleimedium
pyload - Log Injection
pyLoad Log Injection
33RISCO
abrir
Nucleicritical
XWiki < 4.10.20 - Remote code execution
XWiki Remote Code Execution vulnerability via user registration
65RISCO
abrir
Nucleicritical
TeamCity < 2023.11.4 - Authentication Bypass
CVE-2024-27198CRITICALsob ataqueransomware
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
Nucleihigh
TeamCity < 2023.11.4 - Authentication Bypass
CVE-2024-27199HIGHsob ataqueransomware
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
100RISCO
abrir
Nucleihigh
Docassemble - Local File Inclusion
Docassemble unauthorized access through URL manipulation
68RISCO
abrir
Nucleihigh
Apache HugeGraph-Server - Remote Command Execution
CVE-2024-27348CRITICALsob ataque
Apache HugeGraph-Server: Command execution in gremlin
100RISCO
abrir
Nucleimedium
Zimbra Collaboration - Cross-Site Scripting (XSS)
CVE-2024-27443MEDIUMsob ataque
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in
63RISCO
abrir
Nucleihigh
Linksys E2000 1.0.06 position.js Improper Authentication
Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.
41RISCO
abrir
Nucleihigh
ChatGPT个人专用版 - Server Side Request Forgery
pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references sec
60RISCO
abrir
Nucleicritical
Contact Form Plugin by Fluent Forms < 5.1.17 - Unauthenticated Limited Privilege Escalation
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation
63RISCO
abrir
Nucleihigh
Smart s200 Management Platform v.S200 - SQL Injection
SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain s
36RISCO
abrir
Nucleihigh
WordPress FluentForms <= 5.1.16 - Broken Access Control
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation
56RISCO
abrir
Nucleicritical
WordPress Automatic Plugin <3.92.1 - Arbitrary File Download and SSRF
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RISCO
abrir
Nucleicritical
WordPress Automatic Plugin <= 3.92.0 - SQL Injection
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir
Nucleicritical
WordPress LiteSpeed Cache - Unauthenticated Privilege Escalation to Admin
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir
Nucleicritical
N-able N-central < 2024.2 - Authentication Bypass Detection
N-central Authentication Bypass
43RISCO
abrir
Nucleicritical
OpenMetaData - SpEL Injection in PUT /api/v1/policies
SpEL Injection in `PUT /api/v1/policies` in OpenMetadata
48RISCO
abrir
Nucleicritical
OpenMetadata - Authentication Bypass
Authentication Bypass in OpenMetadata
85RISCO
abrir
Nucleimedium
pyload-ng js2py - Remote Code Execution
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
Nucleihigh
LG LED Assistant - Unauthenticated Password Reset
Password reset vulnerability without authorization on LG LED Assistant
55RISCO
abrir
anteriorpágina 127 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.