Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.666exploits catalogados
32.032CVEs com exploração pública
1.932testados em laboratório
4.191 exploits
Nucleicritical
JetBrains TeamCity > 2023.11.3 - Authentication Bypass
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
55RISCO
abrir
Nucleicritical
Exrick XMall - SQL Injection
xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.
43RISCO
abrir
Nucleicritical
Ruijie RG-NBS2009G-P - Improper Authentication
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the syst
48RISCO
abrir
Nucleimedium
SuperWebMailer 9.31.0.01799 - Cross-Site Scripting
SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the comp
28RISCO
abrir
Nucleicritical
TotoLink Router setMacFilterRules - Command Injection
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param
36RISCO
abrir
Nucleicritical
TotoLink Router setPortForwardRules - Command Injection
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param
43RISCO
abrir
Nucleimedium
CrateDB Database - Arbitrary File Read
CrateDB database has an arbitrary file read vulnerability
28RISCO
abrir
Nucleimedium
WPS Hide Login <= 1.9.15.2 - Login Page Disclosure
WPS Hide Login <= 1.9.15.2 - Login Page Disclosure
48RISCO
abrir
Nucleihigh
MindsDB -DNS Rebinding SSRF Protection Bypass
MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding
43RISCO
abrir
Nucleimedium
JumpServer < 3.10.0 - Open Redirect
JumpServer Open Redirect Vulnerability
28RISCO
abrir
Nucleihigh
Traccar - Unrestricted File Upload
Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
48RISCO
abrir
Nucleicritical
Masteriyo LMS <= 1.7.2 - Unauthenticated Privilege Escalation
WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerability
43RISCO
abrir
Nucleihigh
Check Point Quantum Gateway - Information Disclosure
CVE-2024-24919HIGHsob ataqueransomware
Information disclosure
100RISCO
abrir
Nucleicritical
Unauthenticated Remote Code Execution – Bricks <= 1.9.6
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
Nucleimedium
Liferay Portal - Open Redirect
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 be
28RISCO
abrir
Nucleicritical
ZenML ZenML Server - Improper Authentication
ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because t
58RISCO
abrir
Nucleihigh
WyreStorm Apollo VX20 - Information Disclosure
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext password
75RISCO
abrir
Nucleihigh
Linksys RE7000 - Command Injection
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter
41RISCO
abrir
Nucleihigh
GeoServer Demo Request Endpoint - Server Side Request Forgery
GeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost
36RISCO
abrir
Nucleicritical
Telesquare TLR-2005KSH - Remote Command Execution
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RISCO
abrir
Nucleimedium
VvvebJs < 1.7.5 - Arbitrary File Upload
Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute
28RISCO
abrir
Nucleihigh
MLflow < 2.11.3 - Path Traversal
Local File Inclusion (LFI) via URI Fragment Parsing in mlflow/mlflow
41RISCO
abrir
Nucleimedium
Unlimited Elements for Elementor <= 1.5.93 - Cross Site Scripting
WordPress Unlimited Elements for Elementor plugin <= 1.5.93 - Reflected Cross Site Scripting (XSS) vulnerability
36RISCO
abrir
Nucleicritical
Ivanti EPM - Remote Code Execution
CVE-2024-29824CRITICALsob ataque
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RISCO
abrir
Nucleicritical
Apache StreamPipes <= 0.93.0 - Use of Cryptographically Weak PRNG in Recovery Token Generation
Apache StreamPipes, Apache StreamPipes: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token Generation
63RISCO
abrir
Nucleihigh
GLPI 10.0.10-10.0.14 - SQL Injection
GLPI contains an SQL injection through the saved searches
48RISCO
abrir
Nucleicritical
Cacti cmd_realtime.php - Command Injection
Cacti command injection in cmd_realtime.php
85RISCO
abrir
Nucleimedium
WP Go Maps <= 9.0.29 - Cross-Site Scripting
WordPress WP Go Maps plugin <= 9.0.29 - Reflected Cross Site Scripting (XSS) vulnerability
36RISCO
abrir
Nucleicritical
Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - NsaRescueAngel Backdoor Account
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326
85RISCO
abrir
Nucleicritical
Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - Command Injection
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISCO
abrir
anteriorpágina 68 / 140próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.