Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.934GitHub PoC 13.235VulnCheck XDB 8.150Nuclei 4.193Metasploit 3.462✓ só verificadosrecentespopularesrisco
4.193 exploits
Nucleihigh
GDidees CMS v3.9.1 - Arbitrary File Download
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename paramet
68RISCO
abrir ↗Nucleimedium
OpenCATS - Open Redirect
An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET pa
28RISCO
abrir ↗Nucleicritical
MStore API <= 3.9.2 - Authentication Bypass
MStore API <= 3.9.2 - Authentication Bypass
75RISCO
abrir ↗Nucleicritical
MStore API <= 3.9.1 - Authentication Bypass
MStore API <= 3.9.1 - Authentication Bypass
43RISCO
abrir ↗Nucleicritical
PaperCut - Unauthenticated Remote Code Execution
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir ↗Nucleihigh
PaperCut NG - Authentication Bypass
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
88RISCO
abrir ↗Nucleicritical
SPIP - Remote Command Execution
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir ↗Nucleimedium
WordPress Core <=6.2 - Directory Traversal
WordPress Core < 6.2.1 - Directory Traversal
70RISCO
abrir ↗Nucleicritical
Home Assistant Supervisor - Authentication Bypass
homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for
65RISCO
abrir ↗Nucleicritical
Apache Superset - Authentication Bypass
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir ↗Nucleicritical
Dragonfly2 < 2.1.0-beta.1 - Hardcoded JWT Secret
Dragonfly2 vulnerable to hard coded cyptographic key
55RISCO
abrir ↗Nucleimedium
ReadToMyShoe - Generation of Error Message Containing Sensitive Information
ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing
36RISCO
abrir ↗Nucleimedium
WordPress Redirect After Login <= 0.1.9 - Admin Stored XSS
WordPress Redirect After Login Plugin <= 0.1.9 is vulnerable to Cross Site Scripting (XSS)
28RISCO
abrir ↗Nucleicritical
PrestaShop `tshirtecommerce` Module - SQL Injection
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req
43RISCO
abrir ↗Nucleihigh
tshirtecommerce PrestaShop Module - SQL Injection
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req
43RISCO
abrir ↗Nucleihigh
PrestaShop TshirteCommerce - Directory Traversal
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req
36RISCO
abrir ↗Nucleihigh
PrestaShop tshirtecommerce - Directory Traversal
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req
36RISCO
abrir ↗Nucleimedium
L-Soft LISTSERV 16.5 - Cross-Site Scripting
The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XS
18RISCO
abrir ↗Nucleimedium
Super Socializer < 7.13.52 - Cross-Site Scripting
Super Socializer < 7.13.52 - Reflected XSS
48RISCO
abrir ↗Nucleicritical
Mlflow <2.3.1 - Local File Inclusion Bypass
Path Traversal: '\..\filename' in mlflow/mlflow
43RISCO
abrir ↗Nucleicritical
PrestaShop xipblog - SQL Injection
SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges vi
18RISCO
abrir ↗Nucleimedium
Newsletter < 7.6.9 - Cross-Site Scripting
Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inj
18RISCO
abrir ↗Nucleimedium
EventON <= 2.1 - Missing Authorization
EventON < 2.1.2 - Unauthenticated Event Access
50RISCO
abrir ↗Nucleicritical
WooCommerce Payments - Unauthorized Admin Access
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RISCO
abrir ↗Nucleimedium
Wordpress Multiple Themes - Reflected Cross-Site Scripting
Multiple Themes - Reflected XSS
18RISCO
abrir ↗Nucleimedium
Ellucian Ethos Identity CAS - Cross-Site Scripting
Ellucian Ethos Identity logout cross site scripting
28RISCO
abrir ↗Nucleihigh
GitLab 16.0.0 - Path Traversal
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISCO
abrir ↗Nucleicritical
Altenergy Power Control Software C1.2.5 - Remote Command Injection
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISCO
abrir ↗Nucleihigh
MinIO Cluster Deployment - Information Disclosure
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.