Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
4.361 exploits
Nucleicritical
D-Link - Remote Command Execution
CVE-2021-45382CRITICALsob ataque
A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L
95RISCO
abrir
Nucleicritical
Emerson Dixell XWEB-500 - Arbitrary File Write
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /
23RISCO
abrir
Nucleimedium
Reprise License Manager 14.2 - Cross-Site Scripting
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_proce
18RISCO
abrir
Nucleicritical
Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Upload
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can uploa
50RISCO
abrir
Nucleicritical
Control Web Panel (CWP) - File Inclusion
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to c
65RISCO
abrir
Nucleihigh
Slims9 Bulian 9.4.2 - SQL Injection
Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.
18RISCO
abrir
Nucleimedium
osTicket 1.15.x - SQL Injection
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticate
18RISCO
abrir
Nucleicritical
Pascom CPS Server-Side Request Forgery
An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend To
23RISCO
abrir
Nucleihigh
Pascom CPS - Local File Inclusion
An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Pho
23RISCO
abrir
Nucleimedium
Sourcecodester Car Rental Management System 1.0 - Stored Cross-Site Scripting
Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter
18RISCO
abrir
Nucleimedium
Vehicle Service Management System - Stored Cross-Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the My Account Sec
18RISCO
abrir
Nucleimedium
Vehicle Service Management System 1.0 - Stored Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Mechanic List
18RISCO
abrir
Nucleimedium
ehicle Service Management System 1.0 - Cross-Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Category List
18RISCO
abrir
Nucleimedium
Vehicle Service Management System 1.0 - Stored Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List S
18RISCO
abrir
Nucleimedium
Vehicle Service Management System 1.0 - Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the
18RISCO
abrir
Nucleihigh
webp_server_go 0.4.0 - Path Traversal
An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary fi
18RISCO
abrir
Nucleihigh
Ligeo Archives Ligeo Basics - Server Side Request Forgery
Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacke
18RISCO
abrir
Nucleihigh
AntD Admin - Sensitive Information Disclosure
antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the
18RISCO
abrir
Nucleimedium
D-Link DIR850 ET850-1.08TRb03 - Open Redirect
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust
43RISCO
abrir
Nucleihigh
D-Link DAP-1620 - Local File Inclusion
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd]
50RISCO
abrir
Nucleimedium
Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads t
43RISCO
abrir
Nucleihigh
Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege
50RISCO
abrir
Nucleihigh
Telesquare TLR-2855KS6 - Arbitrary File Creation
An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.
43RISCO
abrir
Nucleicritical
Telesquare TLR-2855KS6 - Arbitrary File Deletion
An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system fil
60RISCO
abrir
Nucleicritical
SDT-CW3B1 1.1.0 - OS Command Injection
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISCO
abrir
Nucleicritical
Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Delete
Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to de
50RISCO
abrir
Nucleicritical
GenieACS => 1.2.8 - OS Command Injection
In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping
23RISCO
abrir
Nucleihigh
GeoVision GeoWebServer <= 5.3.3 - Local File Inclusion / Cross-Site Scripting
GeoVision Geowebserver 5.3.3 - Local FIle Inclusion
36RISCO
abrir
Nucleimedium
Keystone 6 Login Page - Open Redirect and Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in keystonejs/keystone
36RISCO
abrir
Nucleimedium
WordPress Visual Form Builder <3.0.8 - Information Disclosure
Visual Form Builder < 3.0.6 - Unauthenticated Information Disclosure
18RISCO
abrir
anteriorpágina 60 / 146próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.