Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.106exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
4.350 exploits
Nucleimedium
LearnPress < 4.2.5.5 - Cross-Site Scripting
LearnPress < 4.2.5.5 - Reflected Cross-Site Scripting
28RISCO
abrir
Nucleicritical
10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion
10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion
18RISCO
abrir
Nucleimedium
WordPress Core - Post Author Email Disclosure
WordPress < 6.3.2 - Unauthenticated Post Author Email Disclosure
28RISCO
abrir
Nucleicritical
WP Hotel Booking <= 2.0.7 - SQL Injection
WP Hotel Booking < 2.0.8 - Unauthenticated SQLi
30RISCO
abrir
Nucleihigh
News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Local File Inclusion
News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Remote Code Execution via Local File Inclusion
36RISCO
abrir
Nucleicritical
ColumbiaSoft DocumentLocator - Improper Authentication
ColumbiaSoft Document Locator WebTools login improper authentication
48RISCO
abrir
Nucleimedium
phpMyFAQ < 3.2.0 - Cross-site Scripting
Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
36RISCO
abrir
Nucleimedium
Citrix StoreFront - Cross-Site Scripting
  Cross-site scripting (XSS)
50RISCO
abrir
Nucleicritical
WordPress WPB Show Core <= 2.2 - Server-Side Request Forgery
WPB Show Core <= 2.2 - Unauthenticated Server Side Request Forgery
18RISCO
abrir
Nucleicritical
Hotel Booking Lite < 4.8.5 - Arbitrary File Download & Deletion
Hotel Booking Lite < 4.8.5 - Unauthenticated Arbitrary File Download & Deletion
18RISCO
abrir
Nucleimedium
WordPress Popup Builder <= 4.2.3 - Unauthenticated Stored XSS
Popup Builder < 4.2.3 - Unauthenticated Stored XSS
48RISCO
abrir
Nucleicritical
Mlflow - Arbitrary File Write
MLflow Arbitrary File Write
55RISCO
abrir
Nucleihigh
Ray Static File - Local File Inclusion
Ray Static File Local File Include
41RISCO
abrir
Nucleihigh
Ray API - Local File Inclusion
Ray Log File Local File Include
48RISCO
abrir
Nucleihigh
VertaAI ModelDB - Path Traversal
ModelDB Local File Include
36RISCO
abrir
Nucleimedium
System Dashboard < 2.8.10 - Cross-Site Scripting
System Dashboard < 2.8.10 - XSS via Header Injection
28RISCO
abrir
Nucleihigh
Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File Read
Ozeki SMS Gateway <= 10.3.208 Unauthenticated Arbitrary File Read
36RISCO
abrir
Nucleicritical
JS Help Desk <= 2.8.2 - SQL Injection
JS Help Desk – AI-Powered Support & Ticketing System 2.8.2 - Unauthenticated SQL Injection via 'js-support-ticket-token-tkstatus' Cookie
36RISCO
abrir
Nucleicritical
PAN-OS Management Web Interface - Authentication Bypass
CVE-2024-0012CRITICALsob ataqueransomware
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir
Nucleicritical
SpiderFlow Crawler Platform - Remote Code Execution
spider-flow FunctionController.java FunctionService.saveFunction code injection
33RISCO
abrir
Nucleicritical
Github Enterprise - Remote Code Execution
Unsafe Reflection in Github Enterprise Server leading to Command Injection
58RISCO
abrir
Nucleicritical
Fortra GoAnywhere MFT - Authentication Bypass
Authentication Bypass in GoAnywhere MFT
85RISCO
abrir
Nucleimedium
EventON (Free < 2.2.8, Premium < 4.5.5) - Information Disclosure
EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure
60RISCO
abrir
Nucleimedium
Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect
Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect
28RISCO
abrir
Nucleihigh
Ncast busiFacade - Remote Command Execution
Guangzhou Yingke Electronic Technology Ncast Guest Login IPSetup.php information disclosure
60RISCO
abrir
Nucleimedium
Travelpayouts <= 1.1.16 - Open Redirect
Travelpayouts <= 1.1.15 - Open Redirect
28RISCO
abrir
Nucleicritical
Likeshop < 2.5.7.20210311 - Arbitrary File Upload
Likeshop HTTP POST Request File.php userFormImage unrestricted upload
78RISCO
abrir
Nucleimedium
WordPress Simple Job Board - Unauthorized Data Access
Simple Job Board <= 2.10.8 - Missing Authorization to Unauthenticated Information Disclosure
28RISCO
abrir
Nucleihigh
SolarWinds Security Event Manager - Unauthenticated RCE
SolarWinds Security Event Manager Deserialization of Untrusted Data Remote Code Execution Vulnerability
78RISCO
abrir
Nucleicritical
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
43RISCO
abrir

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.