Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
4.217 exploits
Nucleicritical
Redis Sandbox Escape - Remote Code Execution
CVE-2022-0543CRITICALsob ataque
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISCO
abrir
Nucleicritical
CouchDB Erlang Distribution - Remote Command Execution
CVE-2022-24706CRITICALsob ataque
Remote Code Execution Vulnerability in Packaging
100RISCO
abrir
Nucleihigh
muhttpd <=1.1.5 - Local Inclusion
do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL wi
23RISCO
abrir
Nucleicritical
Redis < 8.2.1 lua script - Integer Overflow
Lua library commands may lead to integer overflow and potential RCE
36RISCO
abrir
Nucleihigh
Redis Lua Sandbox < 8.2.2 - Cross-User Escape
Redis: Authenticated users can execute LUA scripts as a different user
28RISCO
abrir
Nucleihigh
Redis < 8.2.1 Lua Long-String Delimiter - Out-of-Bounds Read
Redis is vulnerable to DoS via specially crafted LUA scripts
28RISCO
abrir
Nucleicritical
Redis Lua Parser < 8.2.2 - Use After Free
Redis Lua Use-After-Free may lead to remote code execution
85RISCO
abrir
Nucleicritical
Palo Alto Networks PAN-OS - Authentication Bypass
CVE-2026-0257HIGHsob ataqueransomware
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RISCO
abrir
Nucleicritical
SonicWall SMA1000 - Server-Side Request Forgery
CVE-2026-15409CRITICALsob ataque
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
98RISCO
abrir
Nucleicritical
BeyondTrust Remote Support - Unauthenticated WebSocket RCE
CVE-2026-1731CRITICALsob ataqueransomware
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RISCO
abrir
Nucleicritical
Apache Camel camel-coap - Remote Code Execution
Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution
63RISCO
abrir
Nucleihigh
Vite Dev Server - Arbitrary File Read
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
36RISCO
abrir
Nucleicritical
Marimo <= 0.20.4 - Pre-Auth Terminal WebSocket RCE
CVE-2026-39987CRITICALsob ataque
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
Nucleihigh
Next.js WebSocket Upgrade Handler - SSRF
Next.js: Server-side request forgery in applications using WebSocket upgrades
68RISCO
abrir
Nucleicritical
Samba Printing Subsystem - Remote Code Execution
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISCO
abrir
Nucleicritical
Joomla SP Page Builder <= 6.6.1 - Unauthenticated Arbitrary File Upload RCE
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
63RISCO
abrir
Nucleicritical
Joomla SP LMS <= 4.1.3 - Remote Code Execution
Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4
63RISCO
abrir
anteriorpágina 141 / 141

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.