Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
4.193 exploits
Nucleimedium
Netgear R6850 - Information Disclosure
An information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without
28RISCO
abrir
Nucleicritical
ASUS DSL-AC88U - Authentication Bypass
ASUS Router - Improper Authentication
55RISCO
abrir
Nucleimedium
NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure
WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure
40RISCO
abrir
Nucleimedium
Fides Privacy Center ≤ 2.39.1 - Server-Side URL Disclosure
Fides Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
28RISCO
abrir
Nucleicritical
MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template
MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template
43RISCO
abrir
Nucleihigh
Flowise 1.6.5 - Authentication Bypass
An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted sc
68RISCO
abrir
Nucleihigh
F-logic DataCube3 - SQL Injection
SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the
48RISCO
abrir
Nucleimedium
CHAOS 5.0.1 'sendCommandHandler' - Cross-Site Scripting
Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via th
28RISCO
abrir
Nucleicritical
CData API Server < 23.4.8844 - Path Traversal
A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedde
63RISCO
abrir
Nucleicritical
CData Connect < 23.4.8846 - Path Traversal
A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded J
43RISCO
abrir
Nucleihigh
CData Arc < 23.4.8839 - Path Traversal
A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty
36RISCO
abrir
Nucleihigh
TOTOLINK EX1800T TOTOLINK EX1800T - Command Injection
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized e
43RISCO
abrir
Nucleihigh
Next.js - Server Side Request Forgery (SSRF)
Next.js Server-Side Request Forgery in Server Actions
36RISCO
abrir
Nucleihigh
HSC Mailinspector 5.2.17-3 through 5.2.18 - Local File Inclusion
An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability
36RISCO
abrir
Nucleimedium
GP Premium <= 2.4.0 - Cross-Site Scripting
GP Premium <= 2.4.0 - Reflected Cross-Site Scripting
28RISCO
abrir
Nucleicritical
Wordpress Country State City Dropdown <=2.7.2 - SQL Injection
Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
68RISCO
abrir
Nucleihigh
LyLme-Spage - Arbitary File Upload
An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to exec
43RISCO
abrir
Nucleihigh
OpenAPI Generator <= 7.5.0 - Arbitrary File Read/Delete
OpenAPI Generator Online - Arbitrary File Read/Delete
36RISCO
abrir
Nucleicritical
Mitel MiCollab <= 9.8.0.33 - SQL Injection
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to cond
75RISCO
abrir
Nucleicritical
Web Directory Free < 1.7.0 - SQL Injection
Web Directory Free < 1.7.0 - Unauthenticated SQL Injection
75RISCO
abrir
Nucleihigh
openSIS < 9.1 - SQL Injection
SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingL
36RISCO
abrir
Nucleimedium
TileServer API - Cross Site Scripting
tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data
28RISCO
abrir
Nucleimedium
WordPress 12 Step Meeting List Plugin <= 3.14.33 - Cross-Site Scripting
WordPress 12 Step Meeting List plugin <= 3.14.33 - Cross Site Scripting (XSS) vulnerability
36RISCO
abrir
Nucleihigh
Wordpress WPMobile.App >= 11.42 - Cross-Site Scripting
WordPress WPMobile.App plugin <= 11.41 - Cross Site Scripting (XSS) vulnerability
36RISCO
abrir
Nucleicritical
WP Hotel Booking <= 2.1.0 - SQL Injection
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
63RISCO
abrir
Nucleicritical
Apache OFBiz - Directory Traversal & Remote Code Execution
Apache OFBiz: Path traversal leading to a RCE
85RISCO
abrir
Nucleihigh
Reposilite >= 3.3.0, < 3.5.12 - Arbitrary File Read
Path traversal while serving Reposilite javadoc expanded files
36RISCO
abrir
Nucleicritical
GeoServer RCE in Evaluating Property Name Expressions
CVE-2024-36401CRITICALsob ataque
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir
Nucleicritical
GeoServer and GeoTools - Remote Code Execution
GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressions
65RISCO
abrir
Nucleicritical
SuiteCRM - SQL Injection
SuiteCRM unauthenticated SQL Injection
43RISCO
abrir
anteriorpágina 73 / 140próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.