Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
4.202 exploits
Nucleimedium
FV Flowplayer Video Player WordPress plugin - Authenticated Cross-Site Scripting
FV Flowplayer Video Player <= 7.5.0.727 - 7.5.2.727 Reflected Cross-Site Scripting
28RISCO
abrir
Nucleihigh
Hospital Management System 1.0 - Cross-Site Scripting
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searc
18RISCO
abrir
Nucleihigh
BIQS IT Biqs-drive v1.83 Local File Inclusion
A local file inclusion (LFI) vulnerability exists in version BIQS IT Biqs-drive v1.83 and below when sending a specific
18RISCO
abrir
Nucleimedium
EyouCMS 1.5.4 Open Redirect
EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function
18RISCO
abrir
Nucleimedium
Reolink E1 Zoom Camera <=3.0.0.716 - Private Key Disclosure
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory.
18RISCO
abrir
Nucleihigh
Reolink E1 Zoom Camera <=3.0.0.716 - Information Disclosure
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapp
18RISCO
abrir
Nucleimedium
IRTS OP5 Monitor - Cross-Site Scripting
OP5 Monitor 8.3.1, 8.3.2, and OP5 8.3.3 are vulnerable to Cross Site Scripting (XSS).
28RISCO
abrir
Nucleicritical
Cobbler <3.3.0 - Remote Code Execution
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the lo
40RISCO
abrir
Nucleicritical
Apache <= 2.4.48 Mod_Proxy - Server-Side Request Forgery
CVE-2021-40438CRITICALsob ataque
mod_proxy SSRF
100RISCO
abrir
Nucleicritical
Zoho ManageEngine ADSelfService Plus v6113 - Unauthenticated Remote Command Execution
CVE-2021-40539CRITICALsob ataqueransomware
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISCO
abrir
Nucleihigh
Apache 2.4.49 - Path Traversal and Remote Code Execution
CVE-2021-41773HIGHsob ataqueransomware
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
Nucleimedium
PlaceOS 1.2109.1 - Open Redirection
PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.
23RISCO
abrir
Nucleimedium
i-Panel Administration System 2.0 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enable
38RISCO
abrir
Nucleimedium
GitLab GraphQL API User Enumeration
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Priv
70RISCO
abrir
Nucleimedium
Resourcespace - Cross-Site Scripting
ResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_ss
40RISCO
abrir
Nucleicritical
Apache 2.4.49/2.4.50 - Path Traversal and Remote Code Execution
CVE-2021-42013CRITICALsob ataqueransomware
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
Nucleimedium
SAP Knowledge Warehouse <=7.5.0 - Cross-Site Scripting
A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage
43RISCO
abrir
Nucleicritical
Visual Tools DVR VX16 4.2.28.0 - Unauthenticated OS Command Injection
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharac
50RISCO
abrir
Nucleihigh
KONGA 0.14.9 - Privilege Escalation
Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to pri
23RISCO
abrir
Nucleicritical
Sitecore Experience Platform Pre-Auth RCE
CVE-2021-42237CRITICALsob ataqueransomware
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it
100RISCO
abrir
Nucleicritical
BillQuick Web Suite SQL Injection
CVE-2021-42258CRITICALsob ataqueransomware
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution
95RISCO
abrir
Nucleihigh
WP DSGVO Tools (GDPR) <= 3.1.23 - Unauthenticated Arbitrary Post Deletion
WP DSGVO Tools (GDPR) <= 3.1.23 Unauthenticated Arbitrary Post Deletion
36RISCO
abrir
Nucleimedium
NetBiblio WebOPAC - Cross-Site Scripting
Reflected XSS in NetBiblio WebOPAC search functionality
28RISCO
abrir
Nucleimedium
myfactory FMS - Cross-Site Scripting
myfactory.FMS before 7.1-912 allows XSS via the UID parameter.
38RISCO
abrir
Nucleimedium
myfactory FMS - Cross-Site Scripting
myfactory.FMS before 7.1-912 allows XSS via the Error parameter.
38RISCO
abrir
Nucleimedium
Apereo CAS Cross-Site Scripting
Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
18RISCO
abrir
Nucleicritical
D-Link DIR-615 - Unauthorized Access
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without auth
30RISCO
abrir
Nucleimedium
Sourcecodester Online Event Booking and Reservation System 2.3.0 - Cross-Site Scripting
An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via th
18RISCO
abrir
Nucleicritical
Online Event Booking and Reservation System 2.3.0 - SQL Injection
A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-manag
23RISCO
abrir
Nucleicritical
TOTOLINK EX1200T 4.1.2cu.5215 - Authentication Bypass
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
30RISCO
abrir
anteriorpágina 111 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.