Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
4.361 exploits
Nucleihigh
XStream 1.4.18 - Remote Code Execution
CVE-2021-39144HIGHsob ataque
XStream is vulnerable to a Remote Command Execution attack
100RISCO
abrir
Nucleihigh
XStream 1.4.18 - Arbitrary Code Execution
XStream is vulnerable to an Arbitrary Code Execution attack
41RISCO
abrir
Nucleihigh
XStream <1.4.18 - Server-Side Request Forgery
A Server-Side Forgery Request vulnerability in XStream via HashMap unmarshaling
41RISCO
abrir
Nucleimedium
Cachet <=2.3.18 - SQL Injection
Unauthenticated SQL Injection
36RISCO
abrir
Nucleimedium
GLPI 9.2/<9.5.6 - Information Disclosure
Disclosure of GLPI and server information in telemetry endpoint
28RISCO
abrir
Nucleihigh
Grafana Snapshot - Authentication Bypass
CVE-2021-39226CRITICALsob ataque
Snapshot authentication bypass in grafana
95RISCO
abrir
Nucleihigh
WordPress True Ranker <2.2.4 - Local File Inclusion
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISCO
abrir
Nucleihigh
WordPress DZS Zoomsounds <=6.50 - Local File Inclusion
ZoomSounds <= 6.45 Unauthenticated Directory Traversal and Sensitive Information Dislosure
68RISCO
abrir
Nucleimedium
WordPress Under Construction <1.19 - Cross-Site Scripting
underConstruction <= 1.18 - Reflected Cross-Site Scripting
28RISCO
abrir
Nucleimedium
WordPress Easy Social Icons Plugin < 3.0.9 - Cross-Site Scripting
Easy Social Icons <= 3.0.8 - Reflected Cross-Site Scripting
28RISCO
abrir
Nucleimedium
WordPress BulletProof Security 5.1 Information Disclosure
BulletProof Security <= 5.1 Sensitive Information Disclosure
70RISCO
abrir
Nucleihigh
OptinMonster Plugin < 2.6.5 - Unprotected REST-API
OptinMonster <= 2.6.4 Unprotected REST-API Endpoints
41RISCO
abrir
Nucleimedium
FV Flowplayer Video Player WordPress plugin - Authenticated Cross-Site Scripting
FV Flowplayer Video Player <= 7.5.0.727 - 7.5.2.727 Reflected Cross-Site Scripting
28RISCO
abrir
Nucleihigh
Hospital Management System 1.0 - Cross-Site Scripting
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searc
18RISCO
abrir
Nucleihigh
BIQS IT Biqs-drive v1.83 Local File Inclusion
A local file inclusion (LFI) vulnerability exists in version BIQS IT Biqs-drive v1.83 and below when sending a specific
18RISCO
abrir
Nucleimedium
EyouCMS 1.5.4 Open Redirect
EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function
18RISCO
abrir
Nucleimedium
Reolink E1 Zoom Camera <=3.0.0.716 - Private Key Disclosure
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory.
18RISCO
abrir
Nucleihigh
Reolink E1 Zoom Camera <=3.0.0.716 - Information Disclosure
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapp
18RISCO
abrir
Nucleimedium
IRTS OP5 Monitor - Cross-Site Scripting
OP5 Monitor 8.3.1, 8.3.2, and OP5 8.3.3 are vulnerable to Cross Site Scripting (XSS).
28RISCO
abrir
Nucleicritical
Cobbler <3.3.0 - Remote Code Execution
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the lo
40RISCO
abrir
Nucleicritical
Apache <= 2.4.48 Mod_Proxy - Server-Side Request Forgery
CVE-2021-40438CRITICALsob ataqueransomware
mod_proxy SSRF
100RISCO
abrir
Nucleicritical
Zoho ManageEngine ADSelfService Plus v6113 - Unauthenticated Remote Command Execution
CVE-2021-40539CRITICALsob ataqueransomware
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISCO
abrir
Nucleimedium
Opensis-Classic 8.0 - Cross-Site Scripting
Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute Ja
18RISCO
abrir
Nucleimedium
OS4Ed OpenSIS Community 8.0 - Local File Inclusion
OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), wh
43RISCO
abrir
Nucleihigh
D-Link DIR-605 - Information Disclosure
CVE-2021-40655HIGHsob ataque
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name
88RISCO
abrir
Nucleihigh
IND780 - Local File Inclusion
A remote, unauthenticated, directory traversal vulnerability was identified within the web interface used by IND780 Adva
36RISCO
abrir
Nucleicritical
RegistrationMagic <= 5.0.1.7 - Authentication Bypass
RegistrationMagic <= 5.0.1.7 Authentication Bypass
43RISCO
abrir
Nucleihigh
Geoserver - Server-Side Request Forgery
GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.
43RISCO
abrir
Nucleihigh
Auerswald COMfortel 1400/2600/3600 IP - Authentication Bypass
Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.
30RISCO
abrir
Nucleicritical
Auerswald COMpact 5500R 7.8A and 8.0B Devices Backdoor
Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web
60RISCO
abrir
anteriorpágina 56 / 146próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.