Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
4.193 exploits
Nucleimedium
Gradio - Open Redirect
Open Redirect in gradio-app/gradio
28RISCO
abrir
Nucleihigh
Sonatype Nexus Repository Manager 3 - Local File Inclusion
Nexus Repository 3 - Path Traversal
61RISCO
abrir
Nucleihigh
Zitadel - User Registration Bypass
Zitadel User Registration Bypass Vulnerability
36RISCO
abrir
Nucleimedium
Scoold < 1.64.0 - Authentication Bypass
Semicolon Path Injection on API /api;/config
36RISCO
abrir
Nucleihigh
Symfony Profiler - Remote Access via Injected Arguments
Ability to change environment from query in symfony/runtime
48RISCO
abrir
Nucleicritical
WordPress Stacks Mobile App Builder <=5.2.3 - Authentication Bypass
WordPress Stacks Mobile App Builder plugin <= 5.2.3 - Account Takeover vulnerability
63RISCO
abrir
Nucleicritical
WP Query Console <= 1.0 - Remote Code Execution
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RISCO
abrir
Nucleicritical
WordPress Easy Digital Downloads <= 3.2.12 - SQL Injection
WordPress Easy Digital Downloads plugin <= 3.2.12 - SQL Injection vulnerability
43RISCO
abrir
Nucleicritical
Aviatrix Controller - Remote Code Execution
CVE-2024-50603CRITICALsob ataque
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutraliza
100RISCO
abrir
Nucleihigh
Cleo Harmony < 5.8.0.21 - Arbitary File Read
CVE-2024-50623CRITICALsob ataqueransomware
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RISCO
abrir
Nucleihigh
Nexus Repository 2 - Remote Code Execution
Nexus Repository 2 - Remote Code Execution
56RISCO
abrir
Nucleicritical
Hash Form <= 1.1.0 - Arbitrary File Upload
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISCO
abrir
Nucleimedium
GestioIP - Reflected Cross-Site Scripting
The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and en
48RISCO
abrir
Nucleihigh
DATAGERRY - Improper Access Control
The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability.
48RISCO
abrir
Nucleicritical
openSIS Classic v9.1 - SQL Injection
SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The
63RISCO
abrir
Nucleimedium
TOTOLINK CX-A3002RU - Remote Code Execution
An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300R
28RISCO
abrir
Nucleicritical
Cleo Harmony < 5.8.0.24 - File Upload Vulnerability
CVE-2024-55956CRITICALsob ataqueransomware
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can impo
95RISCO
abrir
Nucleicritical
Craft CMS - Remote Code Execution via Template Path Manipulation
CVE-2024-56145CRITICALsob ataque
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RISCO
abrir
Nucleimedium
Astro - Information Disclosure
Server source code is exposed to the public if sourcemaps are enabled
36RISCO
abrir
Nucleicritical
Apache Pinot < 1.3.0 - Authentication Bypass
Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not required
65RISCO
abrir
Nucleimedium
Apache NiFi - Information Disclosure
Apache NiFi: Missing Complete Authorization for Parameter and Service References
23RISCO
abrir
Nucleicritical
D-Link DIR-859 - Information Disclosure
A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals
55RISCO
abrir
Nucleihigh
Netgear DGN2200 - Improper Authentication
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individua
36RISCO
abrir
Nucleicritical
TP-Link Archer C20 - Authentication Bypass
18RISCO
abrir
Nucleicritical
TP-LINK WR840N v6 up to 0.9.1 4.16 - Improper Authentication
15RISCO
abrir
Nucleimedium
DedeCMS - Open Redirect via download.php
Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the inpu
28RISCO
abrir
Nucleimedium
TP-Link Archer A20 v3 Router - Cross-site Scripting
The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listi
28RISCO
abrir
Nucleihigh
WpStickyBar <= 2.1.0 - SQL Injection
WpStickyBar <= 2.1.0 - Unauthenticated SQLi
68RISCO
abrir
Nucleihigh
SimpleHelp <= 5.5.7 - Unauthenticated Path Traversal
CVE-2024-57727CRITICALsob ataqueransomware
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enabl
100RISCO
abrir
Nucleicritical
Yii2 PHP Framework < 2.0.52 - Remote Code Execution
CVE-2024-58136CRITICALsob ataque
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regres
95RISCO
abrir
anteriorpágina 74 / 140próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.