Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.334VulnCheck XDB 8.195Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
4.217 exploits
Nucleimedium
Vite Dev Server - Path Traversal in Optimized Deps .map Handling
Vite has a Path Traversal in Optimized Deps `.map` Handling
28RISCO
abrir ↗Nucleicritical
Fortinet FortiSandbox - Command Injection
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
100RISCO
abrir ↗Nucleimedium
XWiki - Cross-Site Scripting
XWiki has Reflected Cross-Site Scripting (XSS) in its page history compare functionality
28RISCO
abrir ↗Nucleimedium
PraisonAI AgentOS - Information Disclosure
PraisonAI Affected by Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS
28RISCO
abrir ↗Nucleihigh
Gravity SMTP WordPress Plugin - Sensitive Information Exposure
Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API
68RISCO
abrir ↗Nucleihigh
Arcane <= 1.17.2 - Server-Side Request Forgery
Arcane Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint
36RISCO
abrir ↗Nucleihigh
My Calendar WordPress Plugin - Information Disclosure
My Calendar: Unauthenticated Information Disclosure (IDOR) via Multisite switch_to_blog
36RISCO
abrir ↗Nucleihigh
Apache ActiveMQ - Remote Code Execution via HTTP Discovery Transport Bypass
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI
36RISCO
abrir ↗Nucleilow
Mailcow < 2026-03b - Href Link Injection
mailcow-dockerized Login Page has Reflected Parameter Injection / Wrong-Context XSS Escaping
23RISCO
abrir ↗Nucleicritical
Vendure Core - SQL Injection
@vendure/core has a SQL Injection vulnerability
43RISCO
abrir ↗Nucleihigh
HT Mega < 3.0.7 - Sensitive Information Disclosure
HT Mega < 3.0.7 – Unauthenticated PII Disclosure
48RISCO
abrir ↗Nucleicritical
Rclone RC - Broken Access Control
Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
55RISCO
abrir ↗Nucleicritical
RClone RC - Command Injection
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
63RISCO
abrir ↗Nucleicritical
Dgraph <= 25.3.2 - Admin Token Disclosure
Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars in Dgraph
43RISCO
abrir ↗Nucleihigh
NocoBase - SQL Injection
NocoBase Vulnerable to SQL Injection via String Concatenation in Recursive Eager Loading
36RISCO
abrir ↗Nucleihigh
NocoBase - SQL Injection
NocoBase Vulnerable to SQL Validation Bypass via `sqlCollection:update` Missing `checkSQL` Call
36RISCO
abrir ↗Nucleicritical
cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir ↗Nucleihigh
CKAN DataStore SQL Search - SQL Injection
CKAN: Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
36RISCO
abrir ↗Nucleicritical
LiteLLM - SQL Injection
LiteLLM: SQL injection in Proxy API key verification
100RISCO
abrir ↗Nucleicritical
LiteLLM - Command Injection
LiteLLM: Authenticated command execution via MCP stdio test endpoints
100RISCO
abrir ↗Nucleicritical
MagicMirror <= 2.35.0 - Server-Side Request Forgery
MagicMirror²: Unauthenticated SSRF via /cors endpoint
43RISCO
abrir ↗Nucleicritical
phpVMS < 7.0.6 - Legacy Importer Authorization Bypass
phpvms: /importer authorization bypass causing full database wipe
43RISCO
abrir ↗Nucleicritical
WordPress Contact Form by Supsystic - Server-Side Template Injection
Contact Form by Supsystic <= 1.7.36 - Unauthenticated Server-Side Template Injection via Prefill Functionality
75RISCO
abrir ↗Nucleicritical
Gotenberg - Command Injection
Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection
63RISCO
abrir ↗Nucleicritical
JoomSport <= 5.7.7 - SQL Injection
WordPress JoomSport plugin <= 5.7.7 - SQL Injection vulnerability
63RISCO
abrir ↗Nucleicritical
Arelle < 2.39.10 - Remote Code Execution
Arelle < 2.39.10 Unauthenticated RCE via /rest/configure
43RISCO
abrir ↗Nucleicritical
Scramble Laravel - Remote Code Execution
Scramble: Remote code execution via evaluation of user-controlled input in validation rules
63RISCO
abrir ↗Nucleicritical
Open WebUI 'LDAP Empty Password' - Authentication Bypass
Open WebUI: LDAP Empty Password Authentication Bypass
43RISCO
abrir ↗Nucleihigh
Dozzle - Server Side Request Forgery
Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)
36RISCO
abrir ↗Nucleimedium
Open WebUI < 0.9.5 - Information Disclosure
Open WebUI: Unauthenticated RAG Configuration Disclosure
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.