Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.934GitHub PoC 13.235VulnCheck XDB 8.150Nuclei 4.193Metasploit 3.462✓ só verificadosrecentespopularesrisco
4.193 exploits
Nucleicritical
Apache Solr - Authentication Bypass
Apache Solr: Authentication bypass possible using a fake URL Path ending
85RISCO
abrir ↗Nucleihigh
CentralSquare CryWolf - Path Traversal
A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allow
41RISCO
abrir ↗Nucleihigh
TablePress < 2.4.3 - XXE Injection
XML External Entity Reference (XXE) in PHPSpreadsheet's XLSX reader
36RISCO
abrir ↗Nucleihigh
OneDev.io < 11.0.9 - Arbitrary File Read
OneDev vulnerable to arbitrary file reading for unauthenticated user
41RISCO
abrir ↗Nucleihigh
Hoverfly < 1.10.3 - Arbitrary File Read
Arbitrary file read in the `/api/v2/simulation` endpoint in hoverfly (`GHSL-2023-274`)
48RISCO
abrir ↗Nucleimedium
Drupal 11.x-dev - Full Path Disclosure
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash
48RISCO
abrir ↗Nucleicritical
SafeGuard for Privileged Passwords < 7.5.2 - Authentication Bypass
One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to c
55RISCO
abrir ↗Nucleicritical
Apache OFBiz - Remote Code Execution
Apache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE
58RISCO
abrir ↗Nucleimedium
XWiki Platform - Unauthorized Document History Access
XWiki Platform document history including authors of any page exposed to unauthorized actors
28RISCO
abrir ↗Nucleicritical
ASIS - SQL Injection Authentication Bypass
ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for A
55RISCO
abrir ↗Nucleicritical
ArForms < 6.6 - Remote Code Execution
ArForms < 6.6 - Unauthenticated RCE
63RISCO
abrir ↗Nucleimedium
FXServer < v9601 - Information Exposure
Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary
43RISCO
abrir ↗Nucleicritical
NetAlertX 23.01.14–24.x < 24.10.12 - Remote Code Execution
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because fun
75RISCO
abrir ↗Nucleicritical
CyberPanel - Command Injection
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISCO
abrir ↗Nucleicritical
ZoneMinder v1.37.* <= 1.37.64 - SQL Injection
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISCO
abrir ↗Nucleimedium
Changedetection.io <= 0.47.4 - Path Traversal
changedetection.io Path Traversal vulnerability
28RISCO
abrir ↗Nucleicritical
CyberPanel v2.3.6 Pre-Auth Remote Code Execution
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RISCO
abrir ↗Nucleicritical
CyberPanel - Command Injection
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut
75RISCO
abrir ↗Nucleimedium
iTop - User Enumeration via REST Endpoint
Users enumeration allowed through Rest API in Combodo iTop
36RISCO
abrir ↗Nucleimedium
Brother MFC-L9570CDW - Information Disclosure
Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.
70RISCO
abrir ↗Nucleicritical
Brother Printers – Authentication Bypass via Default Admin Password
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
68RISCO
abrir ↗Nucleicritical
ServiceNow - Incomplete Input Validation
Incomplete Input Validation in GlideExpression Script
100RISCO
abrir ↗Nucleimedium
FleetCart 4.1.1 - Information Disclosure
EnvaySoft FleetCart information disclosure
33RISCO
abrir ↗Nucleicritical
My Geo Posts Free <= 1.2 - PHP Object Injection
WordPress My Geo Posts Free plugin <= 1.2 - PHP Object Injection vulnerability
63RISCO
abrir ↗Nucleicritical
Fortra FileCatalyst Workflow <= v5.1.6 - SQL Injection
SQL Injection Vulnerability in FileCatalyst Workflow 5.1.6 Build 135 (and earlier)
65RISCO
abrir ↗Nucleimedium
Ganglia Web Interface (v3.7.3 - v3.7.6) - Cross-Site Scripting
A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows atta
28RISCO
abrir ↗Nucleimedium
Ganglia Web Interface (v3.7.3 - v3.7.5) - Cross-Site Scripting
A cross-site scripting (XSS) vulnerability in the component /graph_all_periods.php of Ganglia-web v3.73 to v3.75 allows
28RISCO
abrir ↗Nucleihigh
Kerio Control v9.2.5 - CRLF Injection
An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertE
41RISCO
abrir ↗Nucleicritical
Dolibarr ERP CMS `list.php` - SQL Injection
Multiple vulnerabilities in DOLIBARR's ERP CMS
55RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.