Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
4.357 exploits
Nucleicritical
PrestaShop Responsive Mega Menu Module - Remote Code Execution
modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for Pre
30RISCO
abrir
Nucleihigh
WordPress 99 Robots WP Background Takeover Advertisements <=4.1.4 - Local File Inclusion
exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Direct
50RISCO
abrir
Nucleicritical
PrismaWEB - Credentials Disclosure
Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the
30RISCO
abrir
Nucleihigh
Drupal avatar_uploader v7.x-1.0-beta8 - Local File Inclusion
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
50RISCO
abrir
Nucleicritical
Blueimp jQuery-File-Upload v9.22.0 - Unrestricted File Upload
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISCO
abrir
Nucleicritical
Etherpad Lite <1.6.4 - Admin Authentication Bypass
Etherpad Lite before 1.6.4 is exploitable for admin access.
23RISCO
abrir
Nucleicritical
TBK DVR4104/DVR4216 Devices - Authentication Bypass
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
Nucleicritical
ZZZCMS ZZZPHP 1.6.3 – Remote PHP Code Execution (RCE)
ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/con
18RISCO
abrir
Nucleicritical
Apache Solr - Deserialization of Untrusted Data
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP
60RISCO
abrir
Nucleihigh
Apache Solr DataImportHandler <8.2.0 - Remote Code Execution
CVE-2019-0193HIGHsob ataque
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISCO
abrir
Nucleimedium
Apache Tomcat - Cross-Site Scripting
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided
50RISCO
abrir
Nucleicritical
Apache Struts <=2.5.20 - Remote Code Execution
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISCO
abrir
Nucleihigh
Apache Tomcat `CGIServlet` enableCmdLineArguments - Remote Code Execution
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISCO
abrir
Nucleihigh
Jenkins Script Security Plugin <=1.49 - Sandbox Bypass
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISCO
abrir
Nucleicritical
Jenkins Pipeline Groovy Plugin <=2.63 - Insecure Deserialization
CVE-2019-1003030CRITICALsob ataque
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RISCO
abrir
Nucleicritical
Kentico CMS Insecure Deserialization Remote Code Execution
CVE-2019-10068CRITICALsob ataque
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions
100RISCO
abrir
Nucleimedium
Apache HTTP Server <=2.4.39 - HTML Injection/Partial Cross-Site Scripting
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page
60RISCO
abrir
Nucleimedium
Apache HTTP server v2.4.0 to v2.4.39 - Open Redirect
In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential m
60RISCO
abrir
Nucleimedium
Timesheet Next Gen <=1.5.3 - Cross-Site Scripting
Timesheet Next Gen 1.5.3 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to ex
18RISCO
abrir
Nucleimedium
Babel - Open Redirect
Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is sup
18RISCO
abrir
Nucleicritical
Teclib GLPI <= 9.3.3 - Unauthenticated SQL Injection
Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php.
23RISCO
abrir
Nucleimedium
Jenkins <=2.196 - Cookie Exposure
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/
30RISCO
abrir
Nucleimedium
Jenkins build-metrics 1.3 - Cross-Site Scripting
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML
50RISCO
abrir
Nucleicritical
WordPress Google Maps <7.11.18 - SQL Injection
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize
40RISCO
abrir
Nucleihigh
BlogEngine.NET 3.3.7.0 - Local File Inclusion
BlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter.
18RISCO
abrir
Nucleicritical
mongo-express Remote Code Execution
CVE-2019-10758CRITICALsob ataque
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse
100RISCO
abrir
Nucleimedium
Nimble Streamer <=3.5.4-9 - Local File Inclusion
Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow
43RISCO
abrir
Nucleicritical
PHP-FPM Path Info Buffer Underflow - Remote Code Execution
CVE-2019-11043HIGHsob ataqueransomware
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
Nucleihigh
Debug Endpoint pprof - Exposure Detection
Kubernetes kubelet exposes /debug/pprof info on healthz port
50RISCO
abrir
Nucleihigh
Kubernetes API Server - YAML Parsing DoS (Billion Laughs)
Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack
41RISCO
abrir
anteriorpágina 25 / 146próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.