Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
4.202 exploits
Nucleihigh
Ultimate Addons for Elementor <= 1.24.1 - Registration Bypass
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the w
36RISCO
abrir
Nucleihigh
Artica Proxy Community Edition <4.30.000000 - Local File Inclusion
Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parame
30RISCO
abrir
Nucleicritical
Netsweeper <=6.4.3 - Python Code Injection
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain
40RISCO
abrir
Nucleimedium
Contentful <=2020-05-21 - Cross-Site Scripting
Contentful through 2020-05-21 for Python allows reflected XSS, as demonstrated by the api parameter to the-example-app.p
18RISCO
abrir
Nucleihigh
Grafana 3.0.1-7.0.1 - Server-Side Request Forgery
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows
60RISCO
abrir
Nucleihigh
Microweber <1.1.20 - Information Disclosure
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose
23RISCO
abrir
Nucleimedium
Bitrix24 <=20.0.0 - Cross-Site Scripting
The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/
18RISCO
abrir
Nucleicritical
rConfig 3.9 - Authentication Bypass(Admin Login)
lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account cr
40RISCO
abrir
Nucleicritical
wpDiscuz <= 5.3.5 - SQL Injection
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute
23RISCO
abrir
Nucleihigh
WordPress acf-to-rest-api <=3.1.0 - Insecure Direct Object Reference
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object r
23RISCO
abrir
Nucleimedium
Extreme Management Center 8.4.1.24 - Cross-Site Scripting
Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
18RISCO
abrir
Nucleihigh
Artica Pandora FMS 7.44 - Remote Code Execution
Artica Pandora FMS 7.44 allows remote command execution via the events feature.
40RISCO
abrir
Nucleihigh
Intelbras TIP 200/200 LITE/300 - Local File Inclusion
Intelbras TIP 200 60.61.75.15, TIP 200 LITE 60.61.75.15, and TIP 300 65.61.75.22 devices allow cgi-bin/cgiServer.exx?pag
18RISCO
abrir
Nucleicritical
Airflow Experimental <1.10.11 - REST API Auth Bypass
CVE-2020-13927CRITICALsob ataque
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th
100RISCO
abrir
Nucleimedium
Apache Kylin - Exposed Configuration File
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.
40RISCO
abrir
Nucleicritical
Apache Unomi <1.5.2 - Remote Code Execution
Remote Code Execution in Apache Unomi
50RISCO
abrir
Nucleimedium
Apache APISIX - Insufficiently Protected Credentials
In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the
40RISCO
abrir
Nucleicritical
WordPress PayPal Pro <1.1.65 - SQL Injection
The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.
40RISCO
abrir
Nucleihigh
NexusDB <4.50.23 - Local File Inclusion
NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal.
23RISCO
abrir
Nucleihigh
D-Link DSL 2888a - Authentication Bypass/Remote Command Execution
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attac
18RISCO
abrir
Nucleicritical
WSO2 API Manager <=3.1.0 - Blind XML External Entity Injection
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection
48RISCO
abrir
Nucleimedium
OX Appsuite - Cross-Site Scripting
OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).
18RISCO
abrir
Nucleicritical
OsTicket < 1.14.3 - Server Side Request Forgery
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
60RISCO
abrir
Nucleimedium
Quixplorer <=2.4.1 - Cross-Site Scripting
Quixplorer <=2.4.1 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied
28RISCO
abrir
Nucleimedium
Cute Editor for ASP.NET 6.4 - Cross-Site Scripting
Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user
18RISCO
abrir
Nucleimedium
QCube Cross-Site-Scripting
A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQ
18RISCO
abrir
Nucleihigh
PHP-Fusion 9.03.50 - Remote Code Execution
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr
50RISCO
abrir
Nucleihigh
D-Link DCS-2530L/DCS-2670L - Administrator Password Disclosure
CVE-2020-25078HIGHsob ataque
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RISCO
abrir
Nucleimedium
Pritunl VPN Server 1.29.2145.25 - Username Enumeration
Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Ini
18RISCO
abrir
Nucleicritical
WordPress File Manager Plugin - Remote Code Execution
CVE-2020-25213CRITICALsob ataque
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir
anteriorpágina 116 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.