Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
4.201 exploits
Nucleihigh
Microsoft Exchange - Authentication Bypass
CVE-2021-33766HIGHsob ataque
Microsoft Exchange Server Information Disclosure Vulnerability
100RISCO
abrir
Nucleimedium
npm ansi_up v4 - Cross-Site Scripting
The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTM
18RISCO
abrir
Nucleicritical
FortiLogger 4.4.2.2 - Arbitrary File Upload
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
60RISCO
abrir
Nucleihigh
Cartadis Gespage 8.2.1 - Directory Traversal
Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.
23RISCO
abrir
Nucleimedium
Drupal 7 CKEditor XSS
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1
18RISCO
abrir
Nucleimedium
WordPress Customize Login Image <3.5.3 - Cross-Site Scripting
A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an appl
18RISCO
abrir
Nucleimedium
Accela Civic Platform <=21.1 - Cross-Site Scripting
In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The
43RISCO
abrir
Nucleicritical
Chamilo model.ajax.php - SQL Injection
main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 p
23RISCO
abrir
Nucleimedium
Accela Civic Platform <=21.1 - Cross-Site Scripting
Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are
38RISCO
abrir
Nucleicritical
Eclipse BIRT Viewer - Remote Code Execution
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessibl
50RISCO
abrir
Nucleimedium
Eclipse Jetty - Information Disclosure
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
70RISCO
abrir
Nucleicritical
Exchange Server - Remote Code Execution
CVE-2021-34473CRITICALsob ataqueransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
Nucleicritical
WordPress ProfilePress 3.0.0-3.1.3 - Admin User Creation Weakness
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RISCO
abrir
Nucleicritical
WordPress ProfilePress <= 3.1.3 - Privilege Escalation
ProfilePress 3.0 - 3.1.3 - Authenticated Privilege Escalation
43RISCO
abrir
Nucleicritical
WordPress ProfilePress 3.0-3.1.3 - Arbitrary File Upload
ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader Component
43RISCO
abrir
Nucleimedium
GTranslate < 2.8.65 - Cross-Site Scripting
Reflected XSS in GTranslate Pro and GTranslate Enterprise < 2.8.65
28RISCO
abrir
Nucleimedium
WordPress Securimage-WP-Fixed <=3.5.4 - Cross-Site Scripting
Securimage-WP-Fixed <= 3.5.4 Reflected Cross-Site Scripting
28RISCO
abrir
Nucleimedium
WordPress Skaut Bazar <1.3.3 - Cross-Site Scripting
Skaut bazar <= 1.3.2 Reflected Cross-Site Scripting
28RISCO
abrir
Nucleihigh
FAUST iServer 9.0.018.018.4 - Local File Inclusion
An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau
23RISCO
abrir
Nucleicritical
Kramer VIAware - Privilege Escalation and Remote Code Execution
KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits runn
60RISCO
abrir
Nucleihigh
SolarWinds Serv-U 15.3 - Directory Traversal
Directory Transversal Vulnerability in Serv-U 15.3
61RISCO
abrir
Nucleimedium
MaxSite CMS > V106 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attacke
18RISCO
abrir
Nucleimedium
Bludit 3.13.1 - Cross Site Scripting
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
38RISCO
abrir
Nucleicritical
Microsoft Open Management Infrastructure - Remote Code Execution
CVE-2021-38647CRITICALsob ataqueransomware
Open Management Infrastructure Remote Code Execution Vulnerability
100RISCO
abrir
Nucleimedium
Cyberoam NetGenie Cross-Site Scripting
Cyberoam NetGenie C0101B1-20141120-NG11VO devices through 2021-08-14 allow tweb/ft.php?u=[XSS] attacks.
18RISCO
abrir
Nucleimedium
ClinicCases 7.3.3 Cross-Site Scripting
Multiple reflected cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow unauthenticated attackers to in
18RISCO
abrir
Nucleimedium
ExponentCMS <= 2.6 - Host Header Injection
A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can cha
18RISCO
abrir
Nucleihigh
XStream 1.4.18 - Remote Code Execution
XStream is vulnerable to an Arbitrary Code Execution attack
41RISCO
abrir
Nucleihigh
XStream 1.4.18 - Remote Code Execution
CVE-2021-39144HIGHsob ataque
XStream is vulnerable to a Remote Command Execution attack
100RISCO
abrir
Nucleihigh
XStream 1.4.18 - Arbitrary Code Execution
XStream is vulnerable to an Arbitrary Code Execution attack
41RISCO
abrir
anteriorpágina 95 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.