Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
4.217 exploits
Nucleicritical
TYPO3 ceselector Extension - Insecure Deserialization
Remote Code Execution in extension "Content Element Selector" (ceselector)
43RISCO
abrir
Nucleicritical
DbGate - Remote Code Execution via Anonymous JWT
DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
63RISCO
abrir
Nucleicritical
DbGate - Remote Code Execution via Dynamic Import Bypass
DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection
63RISCO
abrir
Nucleicritical
Google ADK-Python - Unauthenticated Builder Endpoint
Remote Code Execution in Google Agent Development Kit (ADK)
43RISCO
abrir
Nucleicritical
Adobe ColdFusion - RDS Arbitrary File Write
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
85RISCO
abrir
Nucleihigh
ColdFusion - Path Traversal
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
43RISCO
abrir
Nucleicritical
phpBB < 3.3.17 - Authentication Bypass
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RISCO
abrir
Nucleicritical
Starlette - Improper Validation of Unsafe Equivalence in Input
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
48RISCO
abrir
Nucleicritical
Joomla! JCE extension < 2.9.99.5 unauthenticated RCE
CVE-2026-48907CRITICALsob ataque
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
Nucleicritical
WordPress Product Slider Pro for WooCommerce < 3.5.4 - Supply Chain Backdoor RCE
WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
63RISCO
abrir
Nucleimedium
Apache Tomcat - Cross-Site Scripting
Apache Tomcat: XSS in number guess example
48RISCO
abrir
Nucleimedium
Lyrion Music Server <= 9.2.0 - Cross-Site Scripting
Lyrion Music Server 9.2.0 Reflected XSS via server.log
28RISCO
abrir
Nucleihigh
Langflow <= 1.8.4 - Path Traversal to RCE via File Upload
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RISCO
abrir
Nucleicritical
WordPress ARMember Premium <= 7.3.1 - Unauthenticated SQL Injection
ARMember Premium <= 7.3.1 - Unauthenticated SQL Injection via 'order' Parameter
36RISCO
abrir
Nucleicritical
Check Point IKEv1 Remote-Access VPN - Certificate Authentication Bypass
CVE-2026-50751CRITICALsob ataqueransomware
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISCO
abrir
Nucleilow
Gogs < 0.14.3 - Unauthenticated Organization Teams Disclosure
Gogs: Unauthenticated Organization Teams Information Disclosure via API
28RISCO
abrir
Nucleicritical
Magento 2 Amasty Order Attributes < 4.0.0 - Unauthenticated Arbitrary File Upload
Amasty Order Attributes for Magento 2 < 4.0.0 Unauthenticated Arbitrary File Upload
63RISCO
abrir
Nucleihigh
SiYuan <= 3.6.5 - Unauthenticated Path Traversal
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)
36RISCO
abrir
Nucleihigh
SiYuan Note <= 3.6.5 - Authentication Bypass
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
43RISCO
abrir
Nucleimedium
LobeHub LobeChat <= 2.1.56 - Server-Side Request Forgery
LobeHub: Unauthenticated SSRF in `/webapi/proxy`
43RISCO
abrir
Nucleimedium
vLLM <= 0.23.0 - Anthropic Router Heap Address Information Leak
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
28RISCO
abrir
Nucleicritical
YMC Filter - SQL Injection
WordPress Filter & Grids plugin <= 3.11.5 - SQL Injection vulnerability
43RISCO
abrir
Nucleimedium
Dashy <= 4.3.6 - Reflected XSS via Workspace
Dashy: XSS in workspace url parameter
23RISCO
abrir
Nucleimedium
VvvebJs <= 2.0.5 - Cross-Site Scripting
givanz Vvvebjs File Upload Endpoint upload.php cross site scripting
48RISCO
abrir
Nucleicritical
Page Builder CK <= 3.5.10 - Unauthenticated Arbitrary File Upload
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
85RISCO
abrir
Nucleicritical
Balbooa Forms < 2.4.1 - Unauthenticated Arbitrary File Upload
CVE-2026-56291CRITICALsob ataque
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
100RISCO
abrir
Nucleicritical
Gorse < 0.5.10 - Unauthenticated Database Dump
Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints
63RISCO
abrir
Nucleicritical
Drag and Drop Multiple File Upload - CF7 <= 1.3.9.6 - Remote Code Execution
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
56RISCO
abrir
Nucleicritical
Dockwatch <= 0.6.567 - OS Command Injection
Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
43RISCO
abrir
Nucleicritical
9Router - Unauthenticated LLM Provider API Exposure
9Router 0.4.41 - Unauthenticated API Exposure via /api/providers
43RISCO
abrir
anteriorpágina 138 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.