Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
4.193 exploits
Nucleicritical
EnGenius EnShare IoT Gigabit Cloud Service 1.4.11 Root Remote Code Execution
EnGenius EnShare IoT Gigabit Cloud Service Command Injection
68RISCO
abrir
Nucleihigh
Fanwei e-cology - SQL Injection
Weaver E-cology SQL Injection
36RISCO
abrir
Nucleicritical
Zhiyuan OA Platform - Arbitrary File Upload
Seeyon Zhiyuan OA System Path Traversal File Upload
68RISCO
abrir
Nucleihigh
WeiPHP 5.0 - Path Traversal
WeiPHP Path Traversal Arbitrary File Read
36RISCO
abrir
Nucleicritical
Maltrail <=0.54 Username Parameter - Remote Command Execution
stamparm/maltrail <=0.54 Remote Command Execution
63RISCO
abrir
Nucleicritical
WordPress Pie Register <= 3.7.1.4 - Authentication Bypass
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
63RISCO
abrir
Nucleicritical
WordPress Simple File List <=4.2.2 - Remote Code Execution
35RISCO
abrir
Nucleimedium
ETQ Reliance - Reflected XSS via SQLConverterServlet
ETQ Reliance CG < SE.2025.1 Reflected XSS in `SQLConverterServlet`
28RISCO
abrir
Nucleicritical
ETQ Reliance - Authentication Bypass via Trailing Space
ETQ Reliance CG Authentication Bypass via Trailing Space RCE
48RISCO
abrir
Nucleimedium
Grafana - Exposes DingDing API Keys
Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not p
28RISCO
abrir
Nucleicritical
Shenzhen Aitemi M300 Wi-Fi Repeater – Unauthenticated Remote Command Execution via `time` Parameter
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RISCO
abrir
Nucleicritical
Langflow AI <= 1.6.9 - CORS Misconfiguration
CVE-2025-34291CRITICALsob ataque
Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
100RISCO
abrir
Nucleicritical
Monsta FTP <= 2.11.2 - Unauthenticated Remote Code Execution
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISCO
abrir
Nucleihigh
YesWiki Reflected XSS via File Upload
YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
36RISCO
abrir
Nucleimedium
Broadstreet WordPress plugin - Reflected XSS
Broadstreet < 1.51.8 - Reflected XSS
28RISCO
abrir
Nucleimedium
YesWiki <= 4.5.1 - Cross-Site Scripting
Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
28RISCO
abrir
Nucleimedium
YesWiki < 4.5.4 - Cross-Site Scripting
Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
28RISCO
abrir
Nucleihigh
XWiki REST API - Attachments Disclosure
XWiki missing authorization when accessing the wiki level attachments list and metadata via REST API
28RISCO
abrir
Nucleimedium
Vite Dev Server - Information Exposure
Vite's server.fs.deny bypassed with /. for files under project root
28RISCO
abrir
Nucleihigh
Java-springboot-codebase 1.1 - Arbitrary File Read
Unauthenticated Arbitrary File Read via Absolute Path
56RISCO
abrir
Nucleicritical
Mitel 6000 - OS Command Injection
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and th
40RISCO
abrir
Nucleimedium
Bootstrap Multiselect <= 1.1.2 - Cross-Site Scripting
An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the sour
28RISCO
abrir
Nucleihigh
Personal Weather Station Dashboard 12 - Directory Traversal
Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ direct
28RISCO
abrir
Nucleihigh
WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Download
WordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerability
36RISCO
abrir
Nucleicritical
Eventin <= 4.0.26 - Privilege Escalation
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
75RISCO
abrir
Nucleihigh
TI WooCommerce Wishlist <= 2.9.2 - Arbitrary File Upload
WordPress TI WooCommerce Wishlist plugin <= 2.9.2 - Arbitrary File Upload Vulnerability
63RISCO
abrir
Nucleicritical
PSW Front-end Login & Registration 1.13 - Weak Password Recovery
WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
68RISCO
abrir
Nucleimedium
Label Studio < 1.18.0 - Reflected XSS
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
36RISCO
abrir
Nucleicritical
Wing FTP Server <= 7.4.3 - Remote Code Execution
CVE-2025-47812CRITICALsob ataque
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
Nucleimedium
Wing FTP Server <= 7.4.3 - Path Disclosure via Overlong UID Cookie
CVE-2025-47813MEDIUMsob ataque
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a
70RISCO
abrir
anteriorpágina 82 / 140próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.