Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8.176Nuclei 4.202Metasploit 3.462✓ só verificadosrecentespopularesrisco
4.202 exploits
Nucleimedium
Opensis-Classic 8.0 - Cross-Site Scripting
Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute Ja
18RISCO
abrir ↗Nucleimedium
OS4Ed OpenSIS Community 8.0 - Local File Inclusion
OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), wh
43RISCO
abrir ↗Nucleihigh
D-Link DIR-605 - Information Disclosure
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name
88RISCO
abrir ↗Nucleihigh
IND780 - Local File Inclusion
A remote, unauthenticated, directory traversal vulnerability was identified within the web interface used by IND780 Adva
36RISCO
abrir ↗Nucleicritical
RegistrationMagic <= 5.0.1.7 - Authentication Bypass
RegistrationMagic <= 5.0.1.7 Authentication Bypass
43RISCO
abrir ↗Nucleihigh
Geoserver - Server-Side Request Forgery
GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.
43RISCO
abrir ↗Nucleihigh
Auerswald COMfortel 1400/2600/3600 IP - Authentication Bypass
Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.
30RISCO
abrir ↗Nucleicritical
Auerswald COMpact 5500R 7.8A and 8.0B Devices Backdoor
Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web
60RISCO
abrir ↗Nucleimedium
Cloudron 6.2 Cross-Site Scripting
In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
38RISCO
abrir ↗Nucleicritical
Aviatrix Controller 6.x before 6.5-1804.1922 - Remote Command Execution
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISCO
abrir ↗Nucleihigh
Gurock TestRail Application files.md5 Exposure
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat ac
50RISCO
abrir ↗Nucleicritical
Galera WebTemplate 1.0 Directory Traversal
Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd
18RISCO
abrir ↗Nucleimedium
Spotweb <= 1.5.1 - Cross Site Scripting
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote
18RISCO
abrir ↗Nucleimedium
Spotweb <= 1.5.1 - Cross Site Scripting (Reflected)
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote
18RISCO
abrir ↗Nucleimedium
Spotweb <= 1.5.1 - Cross Site Scripting
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote
18RISCO
abrir ↗Nucleimedium
Spotweb <= 1.5.1 - Cross Site Scripting
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote
18RISCO
abrir ↗Nucleimedium
Spotweb <= 1.5.1 - Cross Site Scripting
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote
18RISCO
abrir ↗Nucleimedium
Spotweb <= 1.5.1 - Cross Site Scripting
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote
18RISCO
abrir ↗Nucleihigh
MKdocs 1.2.2 - Directory Traversal
The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obt
23RISCO
abrir ↗Nucleihigh
Aurelia-Path < 1.1.7 - Prototype Pollution
Prototype pollution in aurelia-path
43RISCO
abrir ↗Nucleimedium
Grafana 8.0.0 <= v.8.2.2 - Angularjs Rendering Cross-Site Scripting
XSS vulnerability allowing arbitrary JavaScript execution
50RISCO
abrir ↗Nucleimedium
Redash Setup Configuration - Default Secrets Disclosure
Insecure default configuration
36RISCO
abrir ↗Nucleicritical
MinIO Operator Console Authentication Bypass
Authentication bypass issue in the Operator Console
48RISCO
abrir ↗Nucleihigh
Metabase - Local File Inclusion
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISCO
abrir ↗Nucleihigh
pfSense - Arbitrary File Write
diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data abo
40RISCO
abrir ↗Nucleihigh
ECOA Building Automation System - Directory Traversal Content Disclosure
ECOA BAS controller - Path Traversal-1
58RISCO
abrir ↗Nucleihigh
ECOA Building Automation System - Arbitrary File Retrieval
ECOA BAS controller - Path Traversal-3
41RISCO
abrir ↗Nucleimedium
Microsoft Exchange Server Pre-Auth POST Based Cross-Site Scripting
Microsoft Exchange Server Spoofing Vulnerability
70RISCO
abrir ↗Nucleihigh
Payara Micro Community 5.2021.6 Directory Traversal
Payara Micro Community 5.2021.6 and below allows Directory Traversal.
50RISCO
abrir ↗Nucleicritical
QVIS NVR/DVR - Remote Code Execution
QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.
18RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.