Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
4.217 exploits
Nucleihigh
aiohttp - Directory Traversal
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
Nucleimedium
Avada < 7.11.7 - Information Disclosure
Avada <= 7.11.6 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing
33RISCO
abrir
Nucleicritical
Rejetto HTTP File Server - Template injection
CVE-2024-23692CRITICALsob ataque
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
Nucleicritical
Progress Kemp Flowmon - Command Injection
Flowmon Unauthenticated Command Injection Vulnerability
85RISCO
abrir
Nucleicritical
JetBrains TeamCity > 2023.11.3 - Authentication Bypass
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
55RISCO
abrir
Nucleicritical
Exrick XMall - SQL Injection
xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.
43RISCO
abrir
Nucleicritical
Ruijie RG-NBS2009G-P - Improper Authentication
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the syst
48RISCO
abrir
Nucleimedium
SuperWebMailer 9.31.0.01799 - Cross-Site Scripting
SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the comp
28RISCO
abrir
Nucleicritical
TotoLink Router setMacFilterRules - Command Injection
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param
36RISCO
abrir
Nucleicritical
TotoLink Router setPortForwardRules - Command Injection
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param
43RISCO
abrir
Nucleimedium
CrateDB Database - Arbitrary File Read
CrateDB database has an arbitrary file read vulnerability
28RISCO
abrir
Nucleimedium
WPS Hide Login <= 1.9.15.2 - Login Page Disclosure
WPS Hide Login <= 1.9.15.2 - Login Page Disclosure
48RISCO
abrir
Nucleihigh
MindsDB -DNS Rebinding SSRF Protection Bypass
MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding
43RISCO
abrir
Nucleimedium
JumpServer < 3.10.0 - Open Redirect
JumpServer Open Redirect Vulnerability
28RISCO
abrir
Nucleihigh
Traccar - Unrestricted File Upload
Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
48RISCO
abrir
Nucleicritical
Masteriyo LMS <= 1.7.2 - Unauthenticated Privilege Escalation
WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerability
43RISCO
abrir
Nucleihigh
Check Point Quantum Gateway - Information Disclosure
CVE-2024-24919HIGHsob ataqueransomware
Information disclosure
100RISCO
abrir
Nucleicritical
Unauthenticated Remote Code Execution – Bricks <= 1.9.6
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
Nucleimedium
Liferay Portal - Open Redirect
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 be
28RISCO
abrir
Nucleicritical
ZenML ZenML Server - Improper Authentication
ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because t
58RISCO
abrir
Nucleihigh
WyreStorm Apollo VX20 - Information Disclosure
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext password
75RISCO
abrir
Nucleihigh
Linksys RE7000 - Command Injection
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter
41RISCO
abrir
Nucleimedium
Fujian Kelixin Communication - Command Injection
Fujian Kelixin Communication Command and Dispatch Platform pwd_update.php sql injection
28RISCO
abrir
Nucleihigh
Avid NEXIS Agent - Arbitrary File Read
Authenticated Arbitrary File Read affecting Avid NEXIS
36RISCO
abrir
Nucleihigh
ReCrystallize Server - Authentication Bypass
ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind
48RISCO
abrir
Nucleicritical
InstaWP Connect <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
63RISCO
abrir
Nucleihigh
SOPlanning - Remote Code Execution
Remote Code Execution through File Upload in SOPlanning before 1.52.02
43RISCO
abrir
Nucleicritical
Mura/Masa CMS - SQL Injection
MasaCMS SQL Injection vulnerability
85RISCO
abrir
Nucleicritical
Change Detection - Server Side Template Injection
Server Side Template Injection in Jinja2 allows Remote Command Execution
85RISCO
abrir
Nucleicritical
WP-Recall <= 16.26.5 - SQL Injection
WordPress WP-Recall plugin <= 16.26.5 - SQL Injection vulnerability
43RISCO
abrir
anteriorpágina 124 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.