Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
4.217 exploits
Nucleimedium
Next.js Middleware - Server-Side Request Forgery
Next.js Improper Middleware Redirect Handling Leads to SSRF
28RISCO
abrir
Nucleimedium
JumpServer - Open Redirect via Referer Header
JumpServer has an Open Redirect Vulnerability
28RISCO
abrir
Nucleihigh
Astro Cloudflare Adapter - Server Side Request Forgery
Astro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpoint
36RISCO
abrir
Nucleimedium
WordPress 3D FlipBook Plugin <= 1.16.17 - Sensitive Information Exposure
WordPress 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery Plugin <= 1.16.16 - Sensitive Data Exposure Vulnerability
28RISCO
abrir
Nucleihigh
GeoServer - XML External Entity Injection
CVE-2025-58360HIGHsob ataque
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISCO
abrir
Nucleicritical
Flowise <= 3.0.5 - Account Takeover
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISCO
abrir
Nucleicritical
FOGProject <= 1.5.10.1673 - Authentication Bypass
FOG's authentication bypass leads to full SQL DB dump
68RISCO
abrir
Nucleilow
Vite Dev Server - Path Traversal
Vite middleware may serve files starting with the same name with the public directory
23RISCO
abrir
Nucleihigh
Mockoon < 9.2.0 - Path Traversal
Mockoon has a Path Traversal and LFI in the static file serving endpoint
36RISCO
abrir
Nucleimedium
WordPress Gerencianet Oficial <= 3.1.3 - Unauthenticated Order Status Disclosure
WordPress Gerencianet Oficial plugin <= 3.1.3 - Sensitive Data Exposure vulnerability
28RISCO
abrir
Nucleicritical
Windows Server Update Service - Insecure Deserialization
CVE-2025-59287CRITICALsob ataque
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISCO
abrir
Nucleihigh
esm.sh <= v136 - Local File Inclusion
Local File Inclusion in esm.sh
36RISCO
abrir
Nucleimedium
esm.sh <= v136 - Arbitrary File Write via Path Traversal
esm.sh writes arbitrary files via path traversal in `X-Zone-Id` header
48RISCO
abrir
Nucleicritical
Service Finder Bookings - Authentication Bypass
Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie
63RISCO
abrir
Nucleimedium
Jenkins Sidepanel - Unauthorized Agent/Queue Exposure
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intent
28RISCO
abrir
Nucleicritical
Flowise - Remote Code Execution
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
Nucleimedium
Ajax Load More < 7.6.1 - Unauthenticated Sensitive Information Exposure
WordPress Ajax Load More Plugin <= 7.6.0.2 - Sensitive Data Exposure Vulnerability
28RISCO
abrir
Nucleihigh
WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload
Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.116 - Authenticated (Administrator+) Arbitrary File Upload
36RISCO
abrir
Nucleimedium
ownCloud Guests - User Enumeration
ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endp
28RISCO
abrir
Nucleihigh
Atarim < 4.2.2 - Sensitive Information Exposure
WordPress Atarim plugin <= 4.2.1 - Sensitive Data Exposure vulnerability
36RISCO
abrir
Nucleicritical
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
63RISCO
abrir
Nucleimedium
DokuWiki <= 2025-05-14a Librarian - Reflected Cross-Site Scripting
Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitra
28RISCO
abrir
Nucleihigh
Traccar(Windows) 6.1- 6.8.1 - Local File Inclusion
Traccar Unauthenticated Local File Inclusion on Windows - Leakage of Traccar Config File
36RISCO
abrir
Nucleimedium
WordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected)
WordPress Qwizcards <= 3.9.4 - Reflected XSS
28RISCO
abrir
Nucleicritical
Oracle Identity Manager REST WebServices - Authentication Bypass
CVE-2025-61757CRITICALsob ataque
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RISCO
abrir
Nucleicritical
Oracle E-Business Suite 12.2.3–12.2.14 – Remote Code Execution
CVE-2025-61882CRITICALsob ataqueransomware
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISCO
abrir
Nucleihigh
Oracle E-Business Suite - Server-Side Request Forgery
CVE-2025-61884HIGHsob ataqueransomware
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions
100RISCO
abrir
Nucleimedium
Open Redirect via Organization Switching
An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites
28RISCO
abrir
Nucleicritical
ChanCMS <= 3.1. - Remote Code Execution
yanyutao0402 ChanCMS collect.js getArticle deserialization
28RISCO
abrir
Nucleimedium
LibreChat <= 0.7.9 - HTML Injection via Accept-Language Header
HTML Injection in Accept-Language Header in danny-avila/librechat
28RISCO
abrir
anteriorpágina 135 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.