Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.104GitHub PoC 15.075VulnCheck XDB 8.883Nuclei 4.365Metasploit 3.493✓ só verificadosrecentespopularesrisco
24.466 exploits
Exploit-DB
Nokia ASIKA 7.13.52 - Hard-coded private key disclosure
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures
33RISCO
abrir ↗Exploit-DB
WordPress Theme Medic v1.0.0 - Weak Password Recovery Mechanism for Forgotten Password
Password reset links invalidation issue in WordPress
38RISCO
abrir ↗Exploit-DB
Symantec SiteMinder WebAgent v12.52 - Cross-site scripting (XSS)
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
Code Injection in pyload/pyload
85RISCO
abrir ↗Exploit-DB
Teachers Record Management System 1.0 - File Upload Type Validation
PHPGurukul Teachers Record Management System Profile Picture changeimage.php unrestricted upload
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sales Tracker Management System v1.0 - Multiple Vulnerabilities
SourceCodester Sales Tracker Management System cross site scripting
28RISCO
abrir ↗Exploit-DB
WordPress Theme Workreap 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISCO
abrir ↗Exploit-DB
Tree Page View Plugin 1.6.7 - Cross Site Scripting (XSS)
WordPress CMS Tree Page View Plugin <= 1.6.7 is vulnerable to Cross Site Scripting (XSS)
56RISCO
abrir ↗Exploit-DB
STARFACE 7.3.0.10 - Authentication with Password Hash Possible
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the
41RISCO
abrir ↗Exploit-DB
File Manager Advanced Shortcode 2.3.2 - Unauthenticated Remote Code Execution (RCE)
File Manager Advanced Shortcode <= 2.3.2 - Unauthenticated Remote Code Execution through shortcode
50RISCO
abrir ↗Exploit-DB
Flexense HTTP Server 10.6.24 - Buffer Overflow (DoS) (Metasploit)
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access v
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Online Security Guards Hiring System 1.0 - Reflected XSS
PHPGurukul Online Security Guards Hiring System search-request.php cross site scripting
43RISCO
abrir ↗Exploit-DB
unilogies/bumsys v1.0.3 beta - Unrestricted File Upload
Unrestricted Upload of File with Dangerous Type in unilogies/bumsys
41RISCO
abrir ↗Exploit-DB
Pydio Cells 4.1.2 - Unauthorised Role Assignments
Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying t
46RISCO
abrir ↗Exploit-DB
Pydio Cells 4.1.2 - Server-Side Request Forgery
Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which
33RISCO
abrir ↗Exploit-DB
Pydio Cells 4.1.2 - Cross-Site Scripting (XSS) via File Download
Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are genera
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Faculty Evaluation System 1.0 - Unauthenticated File Upload
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_u
61RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Camaleon CMS v2.7.0 - Server-Side Template Injection (SSTI)
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para
60RISCO
abrir ↗Exploit-DB
Filmora 12 version ( Build 1.0.0.7) - Unquoted Service Paths Privilege Escalation
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp
41RISCO
abrir ↗Exploit-DB
Seagate Central Storage 2015.0916 - Unauthenticated Remote Command Execution (Metasploit)
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS comman
53RISCO
abrir ↗Exploit-DB
SCM Manager 1.60 - Cross-Site Scripting Stored (Authenticated)
A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute
33RISCO
abrir ↗Exploit-DB
MobileTrans 4.0.11 - Weak Service Privilege Escalation
Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the exe
41RISCO
abrir ↗Exploit-DB
Optoma 1080PSTX Firmware C02 - Authentication Bypass
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid cr
60RISCO
abrir ↗Exploit-DB
Yank Note v3.52.1 (Electron) - Arbitrary Code Execution
Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_pro
41RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GetSimple CMS v3.3.16 - Remote Code Execution (RCE)
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file paramete
46RISCO
abrir ↗Exploit-DB
Webkul Qloapps 1.5.2 - Cross-Site Scripting (XSS)
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive informat
48RISCO
abrir ↗Exploit-DB
FusionInvoice 2023-1.0 - Stored XSS (Cross-Site Scripting)
Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitr
33RISCO
abrir ↗Exploit-DB
PnPSCADA v2.x - Unauthenticated PostgreSQL Injection
The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL
48RISCO
abrir ↗Exploit-DB
eScan Management Console 14.0.1400.2281 - Cross Site Scripting
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allo
48RISCO
abrir ↗Exploit-DB
Apache Superset 2.0.0 - Authentication Bypass
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.