Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.334VulnCheck XDB 8.195Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
4.217 exploits
Nucleihigh
WyreStorm Apollo VX20 - Information Disclosure
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext password
75RISCO
abrir ↗Nucleihigh
Linksys RE7000 - Command Injection
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter
41RISCO
abrir ↗Nucleimedium
Fujian Kelixin Communication - Command Injection
Fujian Kelixin Communication Command and Dispatch Platform pwd_update.php sql injection
28RISCO
abrir ↗Nucleihigh
Avid NEXIS Agent - Arbitrary File Read
Authenticated Arbitrary File Read affecting Avid NEXIS
36RISCO
abrir ↗Nucleihigh
ReCrystallize Server - Authentication Bypass
ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind
48RISCO
abrir ↗Nucleicritical
InstaWP Connect <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
63RISCO
abrir ↗Nucleihigh
SOPlanning - Remote Code Execution
Remote Code Execution through File Upload in SOPlanning before 1.52.02
43RISCO
abrir ↗Nucleicritical
TeamCity < 2023.11.4 - Authentication Bypass
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗Nucleihigh
TeamCity < 2023.11.4 - Authentication Bypass
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
100RISCO
abrir ↗Nucleihigh
Docassemble - Local File Inclusion
Docassemble unauthorized access through URL manipulation
68RISCO
abrir ↗Nucleihigh
Apache HugeGraph-Server - Remote Command Execution
Apache HugeGraph-Server: Command execution in gremlin
100RISCO
abrir ↗Nucleimedium
Zimbra Collaboration - Cross-Site Scripting (XSS)
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in
63RISCO
abrir ↗Nucleihigh
Linksys E2000 1.0.06 position.js Improper Authentication
Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.
41RISCO
abrir ↗Nucleihigh
ChatGPT个人专用版 - Server Side Request Forgery
pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references sec
60RISCO
abrir ↗Nucleicritical
Contact Form Plugin by Fluent Forms < 5.1.17 - Unauthenticated Limited Privilege Escalation
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation
63RISCO
abrir ↗Nucleihigh
Smart s200 Management Platform v.S200 - SQL Injection
SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain s
36RISCO
abrir ↗Nucleihigh
WordPress FluentForms <= 5.1.16 - Broken Access Control
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation
56RISCO
abrir ↗Nucleicritical
WordPress Automatic Plugin <3.92.1 - Arbitrary File Download and SSRF
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RISCO
abrir ↗Nucleicritical
WordPress Automatic Plugin <= 3.92.0 - SQL Injection
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir ↗Nucleicritical
WordPress LiteSpeed Cache - Unauthenticated Privilege Escalation to Admin
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir ↗Nucleicritical
N-able N-central < 2024.2 - Authentication Bypass Detection
N-central Authentication Bypass
43RISCO
abrir ↗Nucleicritical
OpenMetaData - SpEL Injection in PUT /api/v1/policies
SpEL Injection in `PUT /api/v1/policies` in OpenMetadata
48RISCO
abrir ↗Nucleicritical
OpenMetadata - Authentication Bypass
Authentication Bypass in OpenMetadata
85RISCO
abrir ↗Nucleimedium
pyload-ng js2py - Remote Code Execution
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir ↗Nucleihigh
LG LED Assistant - Unauthenticated Password Reset
Password reset vulnerability without authorization on LG LED Assistant
55RISCO
abrir ↗Nucleimedium
RiteCMS 3.0.0 - Cross-site Scripting
RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_sec
48RISCO
abrir ↗Nucleihigh
LG LED Assistant - Thumbnail Path Traversal File Upload
Path traversal via file upload on LG LED Assistant
40RISCO
abrir ↗Nucleimedium
Coda v.2024Q1 - Cross-Site Scripting
Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary
28RISCO
abrir ↗Nucleihigh
Apache CXF < 4.0.4 - Aegis DataBinding SSRF / Local File Read
Apache CXF SSRF Vulnerability using the Aegis databinding
63RISCO
abrir ↗Nucleicritical
Wordpress Email Subscribers by Icegram Express - SQL Injection
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.