Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8.860Nuclei 4.361Metasploit 3.491✓ só verificadosrecentespopularesrisco
4.361 exploits
Nucleicritical
Apache OFBiz <17.12.06 - Arbitrary Code Execution
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
60RISCO
abrir ↗Nucleimedium
EPrints 3.4.2 - Cross-Site Scripting
EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.
18RISCO
abrir ↗Nucleimedium
ImpressCMS <1.4.3 - Incorrect Authorization
ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated atta
23RISCO
abrir ↗Nucleihigh
ImpressCMS < 1.4.3 - SQL Injection
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
43RISCO
abrir ↗Nucleimedium
EPrints 3.4.2 - Cross-Site Scripting
EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.
18RISCO
abrir ↗Nucleimedium
Redwood Report2Web 4.3.4.5 & 4.5.3 - Cross-Site Scripting
A cross-site scripting (XSS) issue in the login panel in Redwood Report2Web 4.3.4.5 and 4.5.3 allows remote attackers to
18RISCO
abrir ↗Nucleimedium
Jenzabar 9.2x-9.2.2 - Cross-Site Scripting
Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.
23RISCO
abrir ↗Nucleimedium
Moodle Jitsi Meet 2.7-2.8.3 - Cross-Site Scripting
Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This
40RISCO
abrir ↗Nucleicritical
Microsoft Exchange Server SSRF Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir ↗Nucleimedium
Odoo <= 15.0 - Cross-Site Scripting
Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote att
28RISCO
abrir ↗Nucleimedium
Doctor Appointment System 1.0 - SQL Injection
SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated
18RISCO
abrir ↗Nucleicritical
Sercomm VD625 Smart Modems - CRLF Injection
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via
23RISCO
abrir ↗Nucleimedium
Clansphere CMS 2011.4 - Cross-Site Scripting
Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter.
18RISCO
abrir ↗Nucleimedium
Clansphere CMS 2011.4 - Cross-Site Scripting
Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "language" parameter.
18RISCO
abrir ↗Nucleicritical
Doctor Appointment System 1.0 - SQL Injection
SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL q
23RISCO
abrir ↗Nucleihigh
Doctor Appointment System 1.0 - SQL Injection
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malic
18RISCO
abrir ↗Nucleihigh
Doctor Appointment System 1.0 - SQL Injection
Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malic
18RISCO
abrir ↗Nucleihigh
Doctor Appointment System 1.0 - SQL Injection
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malic
18RISCO
abrir ↗Nucleihigh
Doctor Appointment System 1.0 - SQL Injection
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malic
18RISCO
abrir ↗Nucleimedium
Triconsole Datepicker Calendar <3.77 - Cross-Site Scripting
Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read
18RISCO
abrir ↗Nucleihigh
Grafana Unauthenticated Snapshot Creation
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of
40RISCO
abrir ↗Nucleimedium
FUDForum 3.1.0 - Cross-Site Scripting
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "
38RISCO
abrir ↗Nucleimedium
FUDForum 3.1.0 - Cross-Site Scripting
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "
38RISCO
abrir ↗Nucleicritical
YeaLink DM 3.6.0.20 - Remote Command Injection
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI,
95RISCO
abrir ↗Nucleicritical
Pega Infinity - Authentication Bypass
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to byp
75RISCO
abrir ↗Nucleicritical
Appspace 6.2.4 - Server-Side Request Forgery
Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.
30RISCO
abrir ↗Nucleicritical
Apache Tapestry - Remote Code Execution
Bypass of the fix for CVE-2019-0195
60RISCO
abrir ↗Nucleicritical
FatPipe WARP/IPVPN/MPVPN - Backdoor Account
FatPipe software administrative account with no password
43RISCO
abrir ↗Nucleimedium
FatPipe WARP/IPVPN/MPVPN - Authorization Bypass
Missing authorization vulnerability in FatPipe software
28RISCO
abrir ↗Nucleicritical
Apache Solr <=8.8.1 - Server-Side Request Forgery
SSRF vulnerability with the Replication handler
40RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.