Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
4.217 exploits
Nucleihigh
News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Local File Inclusion
News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Remote Code Execution via Local File Inclusion
36RISCO
abrir
Nucleicritical
ColumbiaSoft DocumentLocator - Improper Authentication
ColumbiaSoft Document Locator WebTools login improper authentication
48RISCO
abrir
Nucleimedium
phpMyFAQ < 3.2.0 - Cross-site Scripting
Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
36RISCO
abrir
Nucleimedium
Citrix StoreFront - Cross-Site Scripting
  Cross-site scripting (XSS)
50RISCO
abrir
Nucleicritical
WordPress WPB Show Core <= 2.2 - Server-Side Request Forgery
WPB Show Core <= 2.2 - Unauthenticated Server Side Request Forgery
18RISCO
abrir
Nucleicritical
Hotel Booking Lite < 4.8.5 - Arbitrary File Download & Deletion
Hotel Booking Lite < 4.8.5 - Unauthenticated Arbitrary File Download & Deletion
18RISCO
abrir
Nucleimedium
WordPress Popup Builder <= 4.2.3 - Unauthenticated Stored XSS
Popup Builder < 4.2.3 - Unauthenticated Stored XSS
48RISCO
abrir
Nucleicritical
Mlflow - Arbitrary File Write
MLflow Arbitrary File Write
55RISCO
abrir
Nucleihigh
Ray Static File - Local File Inclusion
Ray Static File Local File Include
41RISCO
abrir
Nucleihigh
Ray API - Local File Inclusion
Ray Log File Local File Include
48RISCO
abrir
Nucleihigh
VertaAI ModelDB - Path Traversal
ModelDB Local File Include
36RISCO
abrir
Nucleicritical
LogDash Activity Log <= 1.1.3 - SQL Injection
LogDash Activity Log < 1.1.4 - Unauthenticated SQLi
28RISCO
abrir
Nucleihigh
H2O ImportFiles - Local File Inclusion
Local File Inclusion in h2oai/h2o-3
43RISCO
abrir
Nucleihigh
WP Fastest Cache 1.2.2 - SQL Injection
WP Fastest Cache < 1.2.2 - Unauthenticated SQL Injection
40RISCO
abrir
Nucleimedium
Quttera Web Malware Scanner <= 3.4.1.48 - Sensitive Data Exposure
Quttera Web Malware Scanner < 3.4.2.1 - Directory Listing to Sensitive Data Exposure
23RISCO
abrir
Nucleihigh
Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposure
Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposure
30RISCO
abrir
Nucleihigh
WordPress Backup Migration <= 1.3.6 - Path Traversal
Backup Migration <= 1.3.6 - Unauthenticated Arbitrary Backup Download to Sensitive Information Exposure
36RISCO
abrir
Nucleimedium
TOTVS Fluig Platform - Cross-Site Scripting
TOTVS Fluig Platform mobileredir openApp.jsp cross site scripting
23RISCO
abrir
Nucleicritical
Control iD iDSecure - Authentication Bypass
Control iD iDSecure passwordCustom Authentication Bypass
75RISCO
abrir
Nucleicritical
WordPress My Calendar <3.4.22 - SQL Injection
The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in th
48RISCO
abrir
Nucleimedium
OpenCMS 14 & 15 - Cross Site Scripting
Cross-site Scripting in Alkacon Software OpenCms
28RISCO
abrir
Nucleimedium
OpenCms 14 & 15 - Open Redirect
Open Redirect in Alkacon Software OpenCms
28RISCO
abrir
Nucleimedium
WordPress Toolbar <= 2.2.6 - Open Redirect
WordPress Toolbar <= 2.2.6 - Open Redirect
33RISCO
abrir
Nucleimedium
WordPress Download Manager - File Password Exposure
Download Manager < 3.2.83 - Unauthenticated Protected File Download Password Leak
36RISCO
abrir
Nucleimedium
Seriously Simple Podcasting < 3.0.0 - Information Disclosure
Seriously Simple Podcasting < 3.0.0 - Unauthenticated Administrator Email Disclosure
28RISCO
abrir
Nucleihigh
Prime Mover < 1.9.3 - Sensitive Data Exposure
Prime Mover < 1.9.3 - Directory Listing to Sensitive Data Exposure
48RISCO
abrir
Nucleicritical
Citrix Netscaler ADC & Gateway - Out-Of-Bounds Memory Read
CVE-2023-6549HIGHsob ataque
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Un
78RISCO
abrir
Nucleicritical
Worpress Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISCO
abrir
Nucleihigh
LearnPress <= 4.2.5.7 - SQL Injection
LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by
75RISCO
abrir
Nucleimedium
Mlflow - Cross-Site Scripting
Reflected XSS via Content-Type Header in mlflow/mlflow
28RISCO
abrir
anteriorpágina 137 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.