Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
4.201 exploits
Nucleimedium
Bludit 3.13.1 - Cross Site Scripting
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
38RISCO
abrir
Nucleicritical
Microsoft Open Management Infrastructure - Remote Code Execution
CVE-2021-38647CRITICALsob ataqueransomware
Open Management Infrastructure Remote Code Execution Vulnerability
100RISCO
abrir
Nucleimedium
Cyberoam NetGenie Cross-Site Scripting
Cyberoam NetGenie C0101B1-20141120-NG11VO devices through 2021-08-14 allow tweb/ft.php?u=[XSS] attacks.
18RISCO
abrir
Nucleimedium
ClinicCases 7.3.3 Cross-Site Scripting
Multiple reflected cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow unauthenticated attackers to in
18RISCO
abrir
Nucleimedium
ExponentCMS <= 2.6 - Host Header Injection
A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can cha
18RISCO
abrir
Nucleihigh
XStream 1.4.18 - Remote Code Execution
XStream is vulnerable to an Arbitrary Code Execution attack
41RISCO
abrir
Nucleihigh
XStream 1.4.18 - Remote Code Execution
CVE-2021-39144HIGHsob ataque
XStream is vulnerable to a Remote Command Execution attack
100RISCO
abrir
Nucleihigh
XStream 1.4.18 - Arbitrary Code Execution
XStream is vulnerable to an Arbitrary Code Execution attack
41RISCO
abrir
Nucleihigh
XStream <1.4.18 - Server-Side Request Forgery
A Server-Side Forgery Request vulnerability in XStream via HashMap unmarshaling
41RISCO
abrir
Nucleimedium
Cachet <=2.3.18 - SQL Injection
Unauthenticated SQL Injection
36RISCO
abrir
Nucleimedium
GLPI 9.2/<9.5.6 - Information Disclosure
Disclosure of GLPI and server information in telemetry endpoint
28RISCO
abrir
Nucleihigh
Grafana Snapshot - Authentication Bypass
CVE-2021-39226CRITICALsob ataque
Snapshot authentication bypass in grafana
95RISCO
abrir
Nucleihigh
WordPress True Ranker <2.2.4 - Local File Inclusion
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISCO
abrir
Nucleihigh
WordPress DZS Zoomsounds <=6.50 - Local File Inclusion
ZoomSounds <= 6.45 Unauthenticated Directory Traversal and Sensitive Information Dislosure
68RISCO
abrir
Nucleimedium
WordPress Under Construction <1.19 - Cross-Site Scripting
underConstruction <= 1.18 - Reflected Cross-Site Scripting
28RISCO
abrir
Nucleimedium
WordPress Easy Social Icons Plugin < 3.0.9 - Cross-Site Scripting
Easy Social Icons <= 3.0.8 - Reflected Cross-Site Scripting
28RISCO
abrir
Nucleimedium
WordPress BulletProof Security 5.1 Information Disclosure
BulletProof Security <= 5.1 Sensitive Information Disclosure
70RISCO
abrir
Nucleihigh
OptinMonster Plugin < 2.6.5 - Unprotected REST-API
OptinMonster <= 2.6.4 Unprotected REST-API Endpoints
41RISCO
abrir
Nucleimedium
FV Flowplayer Video Player WordPress plugin - Authenticated Cross-Site Scripting
FV Flowplayer Video Player <= 7.5.0.727 - 7.5.2.727 Reflected Cross-Site Scripting
28RISCO
abrir
Nucleihigh
Hospital Management System 1.0 - Cross-Site Scripting
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searc
18RISCO
abrir
Nucleihigh
BIQS IT Biqs-drive v1.83 Local File Inclusion
A local file inclusion (LFI) vulnerability exists in version BIQS IT Biqs-drive v1.83 and below when sending a specific
18RISCO
abrir
Nucleimedium
EyouCMS 1.5.4 Open Redirect
EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function
18RISCO
abrir
Nucleimedium
Reolink E1 Zoom Camera <=3.0.0.716 - Private Key Disclosure
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory.
18RISCO
abrir
Nucleihigh
Reolink E1 Zoom Camera <=3.0.0.716 - Information Disclosure
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapp
18RISCO
abrir
Nucleimedium
IRTS OP5 Monitor - Cross-Site Scripting
OP5 Monitor 8.3.1, 8.3.2, and OP5 8.3.3 are vulnerable to Cross Site Scripting (XSS).
28RISCO
abrir
Nucleicritical
Cobbler <3.3.0 - Remote Code Execution
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the lo
40RISCO
abrir
Nucleicritical
Apache <= 2.4.48 Mod_Proxy - Server-Side Request Forgery
CVE-2021-40438CRITICALsob ataque
mod_proxy SSRF
100RISCO
abrir
Nucleicritical
Zoho ManageEngine ADSelfService Plus v6113 - Unauthenticated Remote Command Execution
CVE-2021-40539CRITICALsob ataqueransomware
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISCO
abrir
Nucleimedium
Opensis-Classic 8.0 - Cross-Site Scripting
Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute Ja
18RISCO
abrir
Nucleimedium
OS4Ed OpenSIS Community 8.0 - Local File Inclusion
OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), wh
43RISCO
abrir
anteriorpágina 97 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.