Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
4.361 exploits
Nucleicritical
WordPress Automatic Plugin - Unauthenticated Options Change
WordPress Automatic Plugin <= 3.53.2 - Unauthenticated Arbitrary Options Update
48RISCO
abrir
Nucleihigh
GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability.
Path traversal in GLPI barcode plugin
75RISCO
abrir
Nucleihigh
Grafana v8.x - Arbitrary File Read
CVE-2021-43798HIGHsob ataque
Grafana path traversal
100RISCO
abrir
Nucleicritical
Pinterest Automatic < 4.14.4 - Unauthenticated Arbitrary Options Update
Pinterest Automatic <= 4.14.3 - Unuathenticated Arbitrary Options Update
43RISCO
abrir
Nucleimedium
Admidio - Cross-Site Scripting
Cross-site Scripting (XSS) when redirect an url
36RISCO
abrir
Nucleihigh
Gradio < 2.5.0 - Arbitrary File Read
Files on the host computer can be accessed from the Gradio interface
36RISCO
abrir
Nucleicritical
Zoho ManageEngine ServiceDesk Plus - Remote Code Execution
CVE-2021-44077CRITICALsob ataque
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RISCO
abrir
Nucleihigh
Caucho Resin >=4.0.52 <=4.0.56 - Directory traversal
There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remo
23RISCO
abrir
Nucleihigh
Alibaba Sentinel - Server-side request forgery (SSRF)
Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).
18RISCO
abrir
Nucleicritical
Reprise License Manager 14.2 - Authentication Bypass
An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or a
30RISCO
abrir
Nucleicritical
Apache Log4j2 Remote Code Injection
CVE-2021-44228CRITICALsob ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Nucleihigh
WAVLINK AC1200 - Information Disclosure
A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can al
18RISCO
abrir
Nucleicritical
3DPrint Lite < 1.9.1.5 - Arbitrary File Upload
3DPrint Lite < 1.9.1.5 - Unauthenticated Arbitrary File Upload
63RISCO
abrir
Nucleicritical
Rosario Student Information System Unauthenticated SQL Injection
An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allow
55RISCO
abrir
Nucleimedium
Apache Superset <=1.3.2 - Default Login
API sensitive information leak
18RISCO
abrir
Nucleihigh
Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization
Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization
36RISCO
abrir
Nucleicritical
ZoomSounds Plugin - Unauthenticated Arbitrary File Upload
ZoomSounds <= 5.96 - Unauthenticated Arbitrary File Upload
43RISCO
abrir
Nucleicritical
Zoho ManageEngine Desktop Central - Remote Code Execution
CVE-2021-44515CRITICALsob ataque
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server
95RISCO
abrir
Nucleimedium
Open Redirect in Host Authorization Middleware
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host"
18RISCO
abrir
Nucleicritical
Ivanti EPM Cloud Services Appliance Code Injection
CVE-2021-44529CRITICALsob ataqueransomware
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RISCO
abrir
Nucleicritical
Employee Records System 1.0 - Unauthenticated File Upload RCE
Employee Records System v1.0 Arbitrary File Upload RCE
63RISCO
abrir
Nucleihigh
Longjing Technology BEMS API 1.21 - Unauthenticated Arbitrary File Download
Longjing Technology BEMS API <= 1.21 Remote Arbitrary File Download
36RISCO
abrir
Nucleimedium
Thinfinity VirtualUI User Enumeration
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques
43RISCO
abrir
Nucleihigh
Oliver 5 Library Server <8.00.008.053 - Local File Inclusion
An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet functio
18RISCO
abrir
Nucleihigh
HD-Network Realtime Monitoring System 2.0 - Local File Inclusion
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_L
50RISCO
abrir
Nucleicritical
Apache Log4j2 - Remote Code Injection
CVE-2021-45046CRITICALsob ataqueransomware
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISCO
abrir
Nucleicritical
Thinfinity Iframe Injection
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection vi
50RISCO
abrir
Nucleicritical
Apache APISIX Dashboard <2.10.1 - API Unauthorized Access
security vulnerability on unauthorized access.
40RISCO
abrir
Nucleimedium
Gitea < 1.4.3 - Open Redirect
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
18RISCO
abrir
Nucleimedium
AppCMS - Cross-Site Scripting
AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php
18RISCO
abrir
anteriorpágina 59 / 146próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.