Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.104GitHub PoC 15.075VulnCheck XDB 8.883Nuclei 4.365Metasploit 3.493✓ só verificadosrecentespopularesrisco
24.466 exploits
Exploit-DB
Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypass
Registration Authentication Bypass Vulnerability
100RISCO
abrir ↗Exploit-DB
X2CRM 8.5 - Stored Cross-Site Scripting (XSS)
X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject ma
33RISCO
abrir ↗Exploit-DB
KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSp
33RISCO
abrir ↗Exploit-DB
MoziloCMS 3.0 - Remote Code Execution (RCE)
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute a
46RISCO
abrir ↗Exploit-DB
NVIDIA Container Toolkit 1.16.1 - Time-of-check Time-of-Use (TOCTOU)
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with de
60RISCO
abrir ↗Exploit-DB
Microsoft Windows - NTLM Hash Leak Malicious Windows Theme
Windows Themes Spoofing Vulnerability
38RISCO
abrir ↗Exploit-DB
JUX Real Estate 3.4.0 - SQL Injection
JoomlaUX JUX Real Estate GET Parameter realties sql injection
38RISCO
abrir ↗Exploit-DB
Extensive VC Addons for WPBakery page builder 1.9.0 - Remote Code Execution (RCE)
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RISCO
abrir ↗Exploit-DB
Chamilo LMS 1.11.24 - Remote Code Execution (RCE)
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗Exploit-DB
openSIS 9.1 - SQLi (Authenticated)
OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.
41RISCO
abrir ↗Exploit-DB
Devika v1 - Path Traversal via 'snapshot_path'
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RISCO
abrir ↗Exploit-DB
SolarWinds Platform 2024.1 SR1 - Race Condition
SolarWinds Platform Race Condition Vulnerability
38RISCO
abrir ↗Exploit-DB
htmlLawed 1.2.5 - Remote Code Execution (RCE)
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISCO
abrir ↗Exploit-DB
Rocket LMS 1.9 - Persistent Cross Site Scripting (XSS)
A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript pa
33RISCO
abrir ↗Exploit-DB
Apache OFBiz 18.12.12 - Directory Traversal
Apache OFBiz: Path traversal leading to RCE
100RISCO
abrir ↗Exploit-DB
Wordpress Theme XStore 9.3.8 - SQLi
WordPress XStore theme <= 9.3.5 - Unauthenticated SQL Injection vulnerability
48RISCO
abrir ↗Exploit-DB
Apache mod_proxy_cluster 1.2.6 - Stored XSS
Mod_cluster/mod_proxy_cluster: stored cross site scripting
33RISCO
abrir ↗Exploit-DB
Laravel Framework 11 - Credential Leakage
An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/log
23RISCO
abrir ↗Exploit-DB
Palo Alto PAN-OS < v11.1.2-h3 - Command Injection and Arbitrary File Creation
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir ↗Exploit-DB
Jenkins 2.441 - Local File Inclusion
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗Exploit-DB
OpenClinic GA 5.247.01 - Information Disclosure
An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the pr
41RISCO
abrir ↗Exploit-DB
OpenClinic GA 5.247.01 - Path Traversal (Authenticated)
An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page param
41RISCO
abrir ↗Exploit-DB
djangorestframework-simplejwt 5.3.1 - Information Disclosure
djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web ap
33RISCO
abrir ↗Exploit-DB
GUnet OpenEclass E-learning platform 3.15 - 'certbadge.php' Unrestricted File Upload
File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted fil
48RISCO
abrir ↗Exploit-DB
MinIO < 2024-01-31T20-20-33Z - Privilege Escalation
MinIO unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation
53RISCO
abrir ↗Exploit-DB
Ray OS v2.6.3 - Command Injection RCE(Unauthorized)
Ray Command Injection in cpu_profile Parameter
85RISCO
abrir ↗Exploit-DB
Daily Habit Tracker 1.0 - Stored Cross-Site Scripting (XSS)
Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via t
38RISCO
abrir ↗Exploit-DB
GL-iNet MT6000 4.5.5 - Arbitrary File Download
An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially
46RISCO
abrir ↗Exploit-DB
Employee Management System 1.0 - _txtusername_ and _txtpassword_ SQL Injection (Admin Login)
20RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.