Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.934GitHub PoC 13.235VulnCheck XDB 8.150Nuclei 4.193Metasploit 3.462✓ só verificadosrecentespopularesrisco
4.193 exploits
Nucleimedium
All-in-One WP Migration < 7.87 - Unauthenticated Information Disclosure
All-in-One WP Migration and Backup <= 7.86 - Unauthenticated Information Disclosure via Error Logs
28RISCO
abrir ↗Nucleicritical
WP Time Capsule Plugin - Remote Code Execution
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISCO
abrir ↗Nucleimedium
Keycloak - Open Redirect
Keycloak: vulnerable redirect uri validation results in open redirec
28RISCO
abrir ↗Nucleicritical
LatePoint <= 5.0.11 - SQL Injection
LatePoint <= 5.0.11 - Unauthenticated Arbitrary User Password Change via SQL Injection
43RISCO
abrir ↗Nucleicritical
LatePoint <= 5.0.12 - Authentication Bypass
LatePoint <= 5.0.12 - Authentication Bypass
43RISCO
abrir ↗Nucleicritical
Ivanti Cloud Services Appliance - Path Traversal
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted func
100RISCO
abrir ↗Nucleimedium
123Solar 1.8.4.5 - Cross-Site Scripting
jeanmarc77 123solar detailed.php cross site scripting
28RISCO
abrir ↗Nucleicritical
pgAdmin 4 - Authentication Bypass
OAuth2 client id and secret exposed through the web browser in pgAdmin 4
63RISCO
abrir ↗Nucleicritical
WordPress File Upload <= 4.24.11 - Arbitrary File Read
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISCO
abrir ↗Nucleihigh
WP Popup Builder Popup Forms and Marketing Lead Generation <= 1.3.5 - Arbitrary Shortcode Execution
WP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add
48RISCO
abrir ↗Nucleimedium
Rank Math SEO < 1.0.229 - Unauthenticated User and Term Metadata Insert/Update/Deletion
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Missing Authorization to Unauthenticated User and Term Metadata Insert, Update, and Delete
28RISCO
abrir ↗Nucleicritical
TitanNit Web Control 2.01/Atemio 7600 - Remote Code Execution
OS Command Injection in Atelmo Atemio AM 520 HD Full HD Satellite Receiver
63RISCO
abrir ↗Nucleihigh
Automation By Autonami < 3.3.0 - SQL Injection
Automation By Autonami < 3.3.0 - Unauthenticated SQLi
36RISCO
abrir ↗Nucleicritical
WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update
WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update
43RISCO
abrir ↗Nucleicritical
GutenKit <= 2.1.0 - Arbitrary File Upload
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
68RISCO
abrir ↗Nucleicritical
Grafana Post-Auth DuckDB - SQL Injection To File Read
Grafana SQL Expressions allow for remote code execution
85RISCO
abrir ↗Nucleihigh
Polyaxon - Unauthenticated Directory Traversal
Directory Traversal in polyaxon/polyaxon
36RISCO
abrir ↗Nucleicritical
PaloAlto Networks Expedition - Remote Code Execution
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
100RISCO
abrir ↗Nucleihigh
Palo Alto Expedition - SQL Injection
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RISCO
abrir ↗Nucleihigh
PAN-OS Management Web Interface - Command Injection
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISCO
abrir ↗Nucleihigh
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Remote Code Execution
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution
61RISCO
abrir ↗Nucleicritical
Triofox - Improper Access Control
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to init
95RISCO
abrir ↗Nucleimedium
SureForms <= 1.13.1 - Sensitive Information Exposure
SureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure
28RISCO
abrir ↗Nucleihigh
WordPress Bookit < 2.5.1 - Unauthenticated Stripe Settings Update
Bookit < 2.5.1 – Unauthenticated Settings Update
28RISCO
abrir ↗Nucleicritical
JSONPath Plus < 10.3.0 - Remote Code Execution
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input
68RISCO
abrir ↗Nucleimedium
Plugin Oficial – Getnet para WooCommerce <= 1.8.0 - Cross-Site Scripting
Plugin Oficial – Getnet para WooCommerce <= 1.7.3 - Unauthenticated Reflected XSS
28RISCO
abrir ↗Nucleihigh
WP Directory Kit <= 1.4.3 - Unauthenticated SQL Injection
WP Directory Kit <= 1.4.3 - Unauthenticated SQL Injection via select_2_ajax() Function
36RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.