Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8.860Nuclei 4.361Metasploit 3.491✓ só verificadosrecentespopularesrisco
4.361 exploits
Nucleicritical
WordPress Automatic Plugin - Unauthenticated Options Change
WordPress Automatic Plugin <= 3.53.2 - Unauthenticated Arbitrary Options Update
48RISCO
abrir ↗Nucleihigh
GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability.
Path traversal in GLPI barcode plugin
75RISCO
abrir ↗Nucleicritical
Pinterest Automatic < 4.14.4 - Unauthenticated Arbitrary Options Update
Pinterest Automatic <= 4.14.3 - Unuathenticated Arbitrary Options Update
43RISCO
abrir ↗Nucleimedium
Admidio - Cross-Site Scripting
Cross-site Scripting (XSS) when redirect an url
36RISCO
abrir ↗Nucleihigh
Gradio < 2.5.0 - Arbitrary File Read
Files on the host computer can be accessed from the Gradio interface
36RISCO
abrir ↗Nucleicritical
Zoho ManageEngine ServiceDesk Plus - Remote Code Execution
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RISCO
abrir ↗Nucleihigh
Caucho Resin >=4.0.52 <=4.0.56 - Directory traversal
There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remo
23RISCO
abrir ↗Nucleihigh
Alibaba Sentinel - Server-side request forgery (SSRF)
Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).
18RISCO
abrir ↗Nucleicritical
Reprise License Manager 14.2 - Authentication Bypass
An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or a
30RISCO
abrir ↗Nucleicritical
Apache Log4j2 Remote Code Injection
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗Nucleihigh
WAVLINK AC1200 - Information Disclosure
A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can al
18RISCO
abrir ↗Nucleicritical
3DPrint Lite < 1.9.1.5 - Arbitrary File Upload
3DPrint Lite < 1.9.1.5 - Unauthenticated Arbitrary File Upload
63RISCO
abrir ↗Nucleicritical
Rosario Student Information System Unauthenticated SQL Injection
An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allow
55RISCO
abrir ↗Nucleihigh
Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization
Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization
36RISCO
abrir ↗Nucleicritical
ZoomSounds Plugin - Unauthenticated Arbitrary File Upload
ZoomSounds <= 5.96 - Unauthenticated Arbitrary File Upload
43RISCO
abrir ↗Nucleicritical
Zoho ManageEngine Desktop Central - Remote Code Execution
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server
95RISCO
abrir ↗Nucleimedium
Open Redirect in Host Authorization Middleware
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host"
18RISCO
abrir ↗Nucleicritical
Ivanti EPM Cloud Services Appliance Code Injection
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RISCO
abrir ↗Nucleicritical
Employee Records System 1.0 - Unauthenticated File Upload RCE
Employee Records System v1.0 Arbitrary File Upload RCE
63RISCO
abrir ↗Nucleihigh
Longjing Technology BEMS API 1.21 - Unauthenticated Arbitrary File Download
Longjing Technology BEMS API <= 1.21 Remote Arbitrary File Download
36RISCO
abrir ↗Nucleimedium
Thinfinity VirtualUI User Enumeration
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques
43RISCO
abrir ↗Nucleihigh
Oliver 5 Library Server <8.00.008.053 - Local File Inclusion
An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet functio
18RISCO
abrir ↗Nucleihigh
HD-Network Realtime Monitoring System 2.0 - Local File Inclusion
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_L
50RISCO
abrir ↗Nucleicritical
Apache Log4j2 - Remote Code Injection
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISCO
abrir ↗Nucleicritical
Thinfinity Iframe Injection
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection vi
50RISCO
abrir ↗Nucleicritical
Apache APISIX Dashboard <2.10.1 - API Unauthorized Access
security vulnerability on unauthorized access.
40RISCO
abrir ↗Nucleimedium
Gitea < 1.4.3 - Open Redirect
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
18RISCO
abrir ↗Nucleimedium
AppCMS - Cross-Site Scripting
AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php
18RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.