Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8.176Nuclei 4.202Metasploit 3.462✓ só verificadosrecentespopularesrisco
4.202 exploits
Nucleimedium
WSO2 - Cross-Site Scripting
A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0,
60RISCO
abrir ↗Nucleicritical
Online Fire Reporting System v1.0 - SQL injection
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team.
18RISCO
abrir ↗Nucleicritical
Online Fire Reporting System v1.0 - SQL injection
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_inquiry.
18RISCO
abrir ↗Nucleihigh
Online Fire Reporting System v1.0 - SQL injection
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/requests/take_action.php?id=.
18RISCO
abrir ↗Nucleihigh
Complete Online Job Search System 1.0 - SQL Injection
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/company/index.php?view=edit&id=.
18RISCO
abrir ↗Nucleihigh
Complete Online Job Search System 1.0 - SQL Injection
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=category&search=.
18RISCO
abrir ↗Nucleihigh
Complete Online Job Search System 1.0 - SQL Injection
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=hiring&search=.
18RISCO
abrir ↗Nucleihigh
Car Rental Management System 1.0 - SQL Injection
Car Rental Management System v1.0 is vulnerable to SQL Injection via /ip/car-rental-management-system/admin/ajax.php?act
18RISCO
abrir ↗Nucleihigh
Car Rental Management System 1.0 - SQL Injection
Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.
18RISCO
abrir ↗Nucleihigh
Car Rental Management System 1.0 - SQL Injection
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id
18RISCO
abrir ↗Nucleihigh
Car Rental Management System 1.0 - SQL Injection
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking.
18RISCO
abrir ↗Nucleihigh
Car Rental Management System 1.0 - SQL Injection
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php
18RISCO
abrir ↗Nucleicritical
Hospital Management System 1.0 - SQL Injection
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doc
18RISCO
abrir ↗Nucleimedium
Open edX <2022-06-06 - Cross-Site Scripting
Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
18RISCO
abrir ↗Nucleicritical
Sophos Firewall <= 19.0 MR1 - Remote Code Execution
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewa
95RISCO
abrir ↗Nucleicritical
Portal do Software Publico Brasileiro i3geo 7.0.5 - Local File Inclusion
A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3ge
23RISCO
abrir ↗Nucleimedium
Microweber <1.3.2 - Cross-Site Scripting
HTML code Injection in template search keyword in microweber/microweber
28RISCO
abrir ↗Nucleicritical
MSNSwitch Firmware MNT.2408 - Authentication Bypass
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technolog
60RISCO
abrir ↗Nucleihigh
Lin CMS Spring Boot - Default JWT Token
An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions w
18RISCO
abrir ↗Nucleimedium
u5cms v8.3.5 - Open Redirect
An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser t
18RISCO
abrir ↗Nucleicritical
AWP Classifieds <= 4.2.1 - Unauthenticated SQL Injection
AWP Classifieds Plugin < 4.3 - Unauthenticated SQLi
43RISCO
abrir ↗Nucleimedium
WWBN AVideo 11.6 - Cross-Site Scripting
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master
43RISCO
abrir ↗Nucleimedium
WWBN AVideo 11.6 - Cross-Site Scripting
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master
43RISCO
abrir ↗Nucleimedium
WWBN AVideo 11.6 - Cross-Site Scripting
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master
43RISCO
abrir ↗Nucleimedium
NUUO NVRsolo Video Recorder 03.06.02 - Cross-Site Scripting
NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerabi
18RISCO
abrir ↗Nucleihigh
Powertek Firmware <3.30.30 - Authorization Bypass
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypas
68RISCO
abrir ↗Nucleicritical
WordPress Accordions - Unauthenticated Settings Update
WordPress Accordions plugin <= 2.0.2 - Unauthenticated WordPress Options Change vulnerability
43RISCO
abrir ↗Nucleihigh
Apache Spark UI - Remote Command Injection
Apache Spark shell command injection vulnerability via Spark UI
100RISCO
abrir ↗Nucleihigh
WordPress MultiSafepay for WooCommerce <=4.13.1 - Arbitrary File Read
WordPress MultiSafepay plugin for WooCommerce plugin <= 4.13.1 - Unauthenticated Arbitrary File Read vulnerability
28RISCO
abrir ↗Nucleicritical
WordPress Visitor Statistics <=5.7 - SQL Injection
WordPress WP Visitor Statistics plugin <= 5.7 - Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities
43RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.