Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
4.361 exploits
Nucleicritical
EVlink City < R8 V3.4.0.1 - Authentication Bypass
A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to
30RISCO
abrir
Nucleimedium
Revive Adserver <5.1.0 - Open Redirect
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg
50RISCO
abrir
Nucleimedium
Ruby on Rails - Open Redirect via Host Header Injection
The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Sp
40RISCO
abrir
Nucleicritical
Rocket.Chat <=3.13 - NoSQL Injection
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISCO
abrir
Nucleicritical
F5 iControl REST - Remote Command Execution
CVE-2021-22986CRITICALsob ataqueransomware
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
Nucleimedium
MERCUSYS Mercury X18G 1.0.5 Router - Local File Inclusion
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (
23RISCO
abrir
Nucleihigh
Lodash Template - Server-Side Template Injection (RCE)
Command Injection
41RISCO
abrir
Nucleihigh
elFinder < 2.1.58 - Remote Code Execution
Remote Code Execution (RCE)
41RISCO
abrir
Nucleicritical
10Web Photo Gallery < 1.5.55 - SQL Injection
Photo Gallery by 10Web < 1.5.55 - Unauthenticated SQL Injection
18RISCO
abrir
Nucleihigh
WordPress Modern Events Calendar Lite <5.16.5 - Authenticated Arbitrary File Upload
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RISCO
abrir
Nucleihigh
WordPress Modern Events Calendar Lite <5.16.5 - Sensitive Information Disclosure
Modern Events Calendar Lite < 5.16.5 - Unauthenticated Events Export
50RISCO
abrir
Nucleihigh
WordPress Like Button Rating <2.6.32 - Server-Side Request Forgery
Like Button Rating < 2.6.32 - Unauthenticated Full-Read SSRF
18RISCO
abrir
Nucleihigh
WordPress BackupGuard <1.6.0 - Authenticated Arbitrary File Upload
Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload
60RISCO
abrir
Nucleimedium
WordPress Ninja Forms <3.4.34 - Open Redirect
Ninja Forms < 3.4.34 - Administrator Open Redirect
18RISCO
abrir
Nucleimedium
WordPress Advanced Order Export For WooCommerce <3.1.8 - Authenticated Cross-Site Scripting
Advanced Order Export For WooCommerce < 3.1.8 - Reflected Cross-Site Scripting (XSS)
43RISCO
abrir
Nucleihigh
User Profile Picture < 2.5.0 - Sensitive Information Disclosure
User Profile Picture < 2.5.0 - Sensitive Information Disclosure
18RISCO
abrir
Nucleicritical
The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass
The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass
23RISCO
abrir
Nucleimedium
WordPress JH 404 Logger <=1.1 - Cross-Site Scripting
JH 404 Logger <= 1.1 - Unauthenticated Stored Cross-Site Scripting (XSS)
18RISCO
abrir
Nucleimedium
WordPress PhastPress <1.111 - Open Redirect
PhastPress < 1.111 - Open Redirect
18RISCO
abrir
Nucleicritical
WooCommerce Help Scout - Arbitrary File Upload
WooCommerce Help Scout < 2.9.1 - Unauthenticated Arbitrary File Upload leading to RCE
18RISCO
abrir
Nucleimedium
GiveWP <= 2.9.7 - Cross-Site Scripting
GiveWP < 2.10.0 - Reflected Cross Site Scripting (XSS)
18RISCO
abrir
Nucleimedium
WordPress OpenID Connect Generic Client 3.8.0-3.8.1 - Cross-Site Scripting
OpenID Connect Generic Client 3.8.0-3.8.1 - Reflected Cross Site Scripting (XSS) via Login Error
18RISCO
abrir
Nucleicritical
Controlled Admin Access WordPress Plugin <= 1.4.0 - Improper Access Control & Privilege Escalation
Controlled Admin Access < 1.5.2 - Improper Access Control & Privilege Escalation
18RISCO
abrir
Nucleimedium
All Thrive Themes and Plugins - Unauthenticated Option Update
All Thrive Themes and Plugins - Unauthenticated Option Update
18RISCO
abrir
Nucleicritical
Multiple Thrive Themes < 2.0.0 - Arbitrary File Upload
All Thrive Themes Legacy Themes < 2.0.0 - Unauthenticated Arbitrary File Upload and Option Deletion
18RISCO
abrir
Nucleihigh
AccessAlly <3.5.7 - Sensitive Information Leakage
AccessAlly < 3.5.7 - $_SERVER Superglobal Leakage
18RISCO
abrir
Nucleihigh
Patreon WordPress <1.7.0 - Unauthenticated Local File Inclusion
Patreon WordPress < 1.7.0 - Unauthenticated Local File Disclosure
18RISCO
abrir
Nucleimedium
WordPress Goto Tour & Travel Theme <2.0 - Cross-Site Scripting
Goto - Tour & Travel < 2.0 - Unauthenticated Reflected XSS
18RISCO
abrir
Nucleicritical
WordPress Imagements <=1.2.5 - Arbitrary File Upload
Imagements <= 1.2.5 - Unauthenticated Arbitrary File Upload to RCE
18RISCO
abrir
Nucleimedium
WordPress Realteo <=1.2.3 - Cross-Site Scripting
Realteo < 1.2.4 - Unauthenticated Reflected Cross-Site Scripting (XSS)
18RISCO
abrir
anteriorpágina 45 / 146próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.