Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
4.361 exploits
Nucleimedium
XWiki < 4.10.15 - Email Disclosure
XWiki Platform Solr search discloses email addresses of users
40RISCO
abrir
Nucleicritical
D-Link D-View 8 v2.0.1.28 - Authentication Bypass
Authentication Bypass in D-Link D-View 8
55RISCO
abrir
Nucleicritical
JS Help Desk <= 2.8.1 - SQL Injection
WordPress JS Help Desk – Best Help Desk & Support Plugin <= 2.8.1 is vulnerable to SQL Injection
63RISCO
abrir
Nucleimedium
Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)
Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)
28RISCO
abrir
Nucleicritical
MajorDoMo thumb.php - OS Command Injection
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE:
50RISCO
abrir
Nucleihigh
Apache OFBiz < 18.12.11 - Server Side Request Forgery
Apache OFBiz: Arbitrary file properties reading and SSRF attack
30RISCO
abrir
Nucleicritical
Jordy Meow AI Engine - Unrestricted File Upload
WordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability
75RISCO
abrir
Nucleihigh
Gradio Hugging Face - Local File Inclusion
Make the `/file` secure against file traversal attacks
33RISCO
abrir
Nucleicritical
Apache OFBiz < 18.12.11 - Remote Code Execution
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
60RISCO
abrir
Nucleicritical
WP Sessions Time Monitoring Full Automatic <= 1.0.8 - SQL Injection
WP Sessions Time Monitoring Full Automatic < 1.0.9 - Unauthenticated SQL injection
36RISCO
abrir
Nucleicritical
WordPress AI ChatBot (WPBot) <= 4.8.9 - SQL Injection
AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response
63RISCO
abrir
Nucleimedium
Winter CMS Local File Inclusion - (LFI)
Winter CMS Local File Inclusion through Server Side Template Injection
35RISCO
abrir
Nucleihigh
Digiever DS-2105 Pro - Command Injection
CVE-2023-52163HIGHsob ataque
Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects
88RISCO
abrir
Nucleicritical
Viessmann Vitogate 300 - Hardcoded Password
Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
70RISCO
abrir
Nucleimedium
WordPress FastDup <= 2.1.9 Sensitive Information Exposure - Directory Listing
FastDup – Fastest WordPress Migration & Duplicator < 2.2 - Directory Listing to Account Takeover and Sensitive Data Exposure
28RISCO
abrir
Nucleicritical
Essential Blocks < 4.4.3 - Local File Inclusion
Essential Blocks < 4.4.3 - Unauthenticated Local File Inclusion
75RISCO
abrir
Nucleicritical
LearnPress < 4.2.5.8 - Remote Code Execution
LearnPress <= 4.2.5.7 - Command Injection
56RISCO
abrir
Nucleihigh
Hongjing e-HR 2020 - SQL Injection
Hongjing e-HR Login Interface loadhistroyorgtree sql injection
36RISCO
abrir
Nucleimedium
WP Go Maps (formerly WP Google Maps) < 9.0.29 - Cross-Site Scripting
WP Go Maps (formerly WP Google Maps) <= 9.0.28 - Reflected Cross-Site Scripting
28RISCO
abrir
Nucleicritical
WordPress WP Clone <= 2.4.2 - Database Backup Exposure
Clone < 2.4.3 - Unauthenticated Backup Download
36RISCO
abrir
Nucleimedium
Payment Gateway for Telcell < 2.0.4 - Open Redirect
Payment Gateway for Telcell <= 2.0.1 - Unauthenticated Open Redirect
28RISCO
abrir
Nucleicritical
WordPress File Manager <= 7.2.1 - Directory Traversal
File Manager And File Manager Pro (Multiple Versions) - Directory Traversal
43RISCO
abrir
Nucleihigh
mlflow - Path Traversal
Path Traversal: '\..\filename' in mlflow/mlflow
36RISCO
abrir
Nucleicritical
WordPress POST SMTP Mailer <= 2.8.7 - Authorization Bypass
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RISCO
abrir
Nucleicritical
Hikvision IP ping.php - Command Execution
Hikvision Intercom Broadcasting System ping.php os command injection
70RISCO
abrir
Nucleihigh
Mlflow <2.9.2 - Path Traversal
Path Traversal: '\..\filename' in mlflow/mlflow
58RISCO
abrir
Nucleicritical
Better Search Replace < 1.4.5 - PHP Object Injection
Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection
68RISCO
abrir
Nucleimedium
WP Recipe Maker <= 9.1.0 - Reflected XSS via Referer Header
WP Recipe Maker <= 9.1.0 - Reflected Cross-Site Scripting via Referer
28RISCO
abrir
Nucleihigh
Mlflow <2.8.0 - Local File Inclusion
Path Traversal: '\..\filename'
43RISCO
abrir
Nucleicritical
Shield Security WP Plugin <= 18.5.9 - Local File Inclusion
Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusion
55RISCO
abrir
anteriorpágina 67 / 146próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.