Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
4.193 exploits
Nucleihigh
Flowise <= 1.8.2 Authentication Bypass
Flowise Authentication Bypass
55RISCO
abrir
Nucleihigh
WordPress Clean Login <= 1.14.5 Authenticated (Contributor+) - Local File Inclusion
Clean Login <= 1.14.5 - Authenticated (Contributor+) Local File Inclusion
36RISCO
abrir
Nucleicritical
GiveWP Donation Plugin <= 3.16.1 - Unauthenticated PHP Object Injection
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RISCO
abrir
Nucleicritical
WooCommerce Ultimate Gift Card ≤ 2.6.0 - Arbitrary File Upload
WooCommerce Ultimate Gift Card <= 2.9.2 - Unauthenticated Arbitrary File Upload
63RISCO
abrir
Nucleihigh
REST API TO MiniProgram <= 4.7.1 - SQL Injection
REST API TO MiniProgram <= 4.7.1 - Unauthenticated SQL Injection
36RISCO
abrir
Nucleicritical
VICIdial - SQL Injection
VICIdial Unauthenticated SQL Injection
85RISCO
abrir
Nucleicritical
SPIP BigUp Plugin - Remote Code Execution
SPIP Bigup Multipart File Upload OS Command Injection
85RISCO
abrir
Nucleicritical
LearnPress < 4.2.7.1 - SQL Injection
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
75RISCO
abrir
Nucleicritical
LearnPress < 4.2.7.1 - SQL Injection
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
68RISCO
abrir
Nucleihigh
WordPress TS Poll < 2.4.0 - SQL Injection
TS Poll – Survey, Versus Poll, Image Poll, Video Poll < 2.4.0 - Admin+ SQL Injection
36RISCO
abrir
Nucleilow
Z-Downloads < 1.11.7 - Cross-Site Scripting
Z-Downloads < 1.11.7 - Admin+ Stored XSS via SVG Upload
63RISCO
abrir
Nucleihigh
Keycloak - SAML Core Package Signature Validation Flaw
Keycloak-saml-core: improper verification of saml responses leading to privilege escalation in keycloak
36RISCO
abrir
Nucleihigh
WebIQ 2.15.9 - Directory Traversal
WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability
68RISCO
abrir
Nucleimedium
All-in-One WP Migration < 7.87 - Unauthenticated Information Disclosure
All-in-One WP Migration and Backup <= 7.86 - Unauthenticated Information Disclosure via Error Logs
28RISCO
abrir
Nucleicritical
WP Time Capsule Plugin - Remote Code Execution
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISCO
abrir
Nucleicritical
Mlflow < 2.17.0 - Local File Inclusion
Path Traversal in mlflow/mlflow
36RISCO
abrir
Nucleicritical
Riello Netman 204 - SQL Injection
SQL Injection
50RISCO
abrir
Nucleimedium
Keycloak - Open Redirect
Keycloak: vulnerable redirect uri validation results in open redirec
28RISCO
abrir
Nucleicritical
LatePoint <= 5.0.11 - SQL Injection
LatePoint <= 5.0.11 - Unauthenticated Arbitrary User Password Change via SQL Injection
43RISCO
abrir
Nucleicritical
LatePoint <= 5.0.12 - Authentication Bypass
LatePoint <= 5.0.12 - Authentication Bypass
43RISCO
abrir
Nucleicritical
Ivanti Cloud Services Appliance - Path Traversal
CVE-2024-8963CRITICALsob ataque
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted func
100RISCO
abrir
Nucleimedium
123Solar 1.8.4.5 - Cross-Site Scripting
jeanmarc77 123solar detailed.php cross site scripting
28RISCO
abrir
Nucleicritical
pgAdmin 4 - Authentication Bypass
OAuth2 client id and secret exposed through the web browser in pgAdmin 4
63RISCO
abrir
Nucleicritical
WordPress File Upload <= 4.24.11 - Arbitrary File Read
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISCO
abrir
Nucleihigh
WP Popup Builder Popup Forms and Marketing Lead Generation <= 1.3.5 - Arbitrary Shortcode Execution
WP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add
48RISCO
abrir
Nucleimedium
Rank Math SEO < 1.0.229 - Unauthenticated User and Term Metadata Insert/Update/Deletion
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Missing Authorization to Unauthenticated User and Term Metadata Insert, Update, and Delete
28RISCO
abrir
Nucleicritical
TitanNit Web Control 2.01/Atemio 7600 - Remote Code Execution
OS Command Injection in Atelmo Atemio AM 520 HD Full HD Satellite Receiver
63RISCO
abrir
Nucleihigh
Automation By Autonami < 3.3.0 - SQL Injection
Automation By Autonami < 3.3.0 - Unauthenticated SQLi
36RISCO
abrir
Nucleicritical
WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update
WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update
43RISCO
abrir
Nucleicritical
GutenKit <= 2.1.0 - Arbitrary File Upload
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
68RISCO
abrir
anteriorpágina 84 / 140próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.