Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8.860Nuclei 4.361Metasploit 3.491✓ só verificadosrecentespopularesrisco
4.361 exploits
Nucleicritical
Apache OFBiz <17.12.07 - Arbitrary Code Execution
Unsafe deserialization in Apache OFBiz
60RISCO
abrir ↗Nucleimedium
Php-mod/curl Library <2.3.2 - Cross-Site Scripting
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key paramet
28RISCO
abrir ↗Nucleimedium
Sidekiq <=6.2.0 - Cross-Site Scripting
Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explore
18RISCO
abrir ↗Nucleihigh
Intelbras WIN 300/WRN 342 - Credentials Disclosure
The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover creden
30RISCO
abrir ↗Nucleicritical
ZEROF Web Server 1.0 - SQL Injection
ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.
18RISCO
abrir ↗Nucleicritical
IPeakCMS 3.5 - SQL Injection
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the
43RISCO
abrir ↗Nucleihigh
ffay lanproxy Directory Traversal
ffay lanproxy 0.1 allows Directory Traversal to read /../conf/config.properties to obtain credentials for a connection t
23RISCO
abrir ↗Nucleihigh
Dzzoffice 2.02.1 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers
18RISCO
abrir ↗Nucleimedium
Knowage Suite 7.3 - Cross-Site Scripting
Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrar
18RISCO
abrir ↗Nucleicritical
VoipMonitor <24.61 - Remote Code Execution
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISCO
abrir ↗Nucleihigh
Ivanti Avalanche 6.3.2 - Local File Inclusion
Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal
40RISCO
abrir ↗Nucleicritical
PrestaShop 1.7.7.0 - SQL Injection
The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller
23RISCO
abrir ↗Nucleimedium
Microsoft Exchange Server - Cross-Site Scripting
Microsoft Exchange Server Remote Code Execution Vulnerability
50RISCO
abrir ↗Nucleimedium
CHIYU TCP/IP Converter - Carriage Return Line Feed Injection
A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology I
23RISCO
abrir ↗Nucleimedium
CHIYU TCP/IP Converter - Cross-Site Scripting
Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU T
40RISCO
abrir ↗Nucleicritical
Laravel with Ignition <= v8.4.2 Debug Mode - Remote Code Execution
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗Nucleicritical
CentOS Web Panel - SQL Injection
The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST param
23RISCO
abrir ↗Nucleicritical
CentOS Web Panel - OS Command Injection
The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root R
30RISCO
abrir ↗Nucleihigh
Home Assistant HACS - Local File Inclusion
Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks aga
18RISCO
abrir ↗Nucleimedium
SIS Informatik REWE GO SP17 <7.7 - Cross-Site Scripting
SIS SIS-REWE Go before 7.7 SP17 allows XSS: rewe/prod/web/index.php (affected parameters are config, version, win, db, p
18RISCO
abrir ↗Nucleimedium
Akkadian Provisioning Manager - Information Disclosure
Akkadian Provisioning Manager Engine (PME) Shell Escape via 'vi' editor interface
36RISCO
abrir ↗Nucleimedium
BeyondTrust Secure Remote Access Base <=6.0.1 - Cross-Site Scripting
A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Sof
43RISCO
abrir ↗Nucleihigh
Hitachi Vantara Pentaho/Business Intelligence Server - Authentication Bypass
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The
60RISCO
abrir ↗Nucleimedium
WebCTRL OEM <= 6.5 - Cross-Site Scripting
The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for re
43RISCO
abrir ↗Nucleicritical
Tenda Router AC11 - Remote Command Injection
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerabili
95RISCO
abrir ↗Nucleicritical
Apache Struts2 S2-062 - Remote Code Execution
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
60RISCO
abrir ↗Nucleicritical
Layer5 Meshery 0.5.2 - SQL Injection
A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL comman
40RISCO
abrir ↗Nucleimedium
SysAid 20.4.74 - Cross-Site Scripting
SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.
18RISCO
abrir ↗Nucleicritical
ASUS GT-AC2900 - Authentication Bypass
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630
95RISCO
abrir ↗Nucleicritical
Maian Cart <=3.8 - Remote Code Execution
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.