Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.934GitHub PoC 13.235VulnCheck XDB 8.150Nuclei 4.193Metasploit 3.462✓ só verificadosrecentespopularesrisco
4.193 exploits
Nucleimedium
WP Content Copy Protection & No Right Click - Open Redirect
WP Content Copy Protection & No Right Click (premium) < 15.3 - Open Redirect
28RISCO
abrir ↗Nucleimedium
EasySpider 0.6.2 - Arbitrary File Read
NaiboWang EasySpider HTTP GET Request server.js path traversal
28RISCO
abrir ↗Nucleihigh
Social Auto Poster <= 5.3.14 - Stored Cross-Site Scripting
Social Auto Poster <= 5.3.14 - Unauthenticated Stored Cross-Site Scripting
36RISCO
abrir ↗Nucleihigh
AnythingLLM - Information Disclosure
Exposure of Sensitive Information in mintplex-labs/anything-llm
41RISCO
abrir ↗Nucleimedium
SmartSearchWP < 2.4.6 - OpenAI Key Disclosure
SmartSearchWP < 2.4.6 - Unauthenticated OpenAI Key Disclosure
28RISCO
abrir ↗Nucleimedium
SmartSearchWP <= 2.4.4 - Unauthenticated Log Purge
SmartSearchWP <= 2.4.4 - Unauthenticated Log Purge
28RISCO
abrir ↗Nucleimedium
Gitea 1.22.0 - Cross-Site Scripting
Inproper Sanitation of field leading to stored XSS
55RISCO
abrir ↗Nucleimedium
Journyx 11.5.4 - Reflected Cross Site Scripting
Journyx Reflected Cross Site Scripting
28RISCO
abrir ↗Nucleihigh
Journyx - XML External Entities Injection (XXE)
Journyx Unauthenticated XML External Entities Injection
48RISCO
abrir ↗Nucleihigh
PerkinElmer ProcessPlus <= 1.11.6507.0 - Local File Inclusion
Unauthenticated Local File Inclusion
36RISCO
abrir ↗Nucleihigh
Automation Anywhere Automation 360 - Server-Side Request Forgery
Server-Side Request Forgery in Automation 360
40RISCO
abrir ↗Nucleihigh
TrueBooker <= 1.0.2 - SQL Injection
TrueBooker < 1.0.3 - Multiple Unauthenticated SQLi
63RISCO
abrir ↗Nucleicritical
Viral Signup <= 2.1 - SQL Injection
Viral Signup <= 2.1 - Unauthenticated SQLi
63RISCO
abrir ↗Nucleihigh
Opti Marketing <= 2.0.9 - SQL Injection
Opti Marketing <= 2.0.9 - Unauthenticated SQLi
63RISCO
abrir ↗Nucleimedium
Calibre <= 7.15.0 - Reflected Cross-Site Scripting (XSS)
Calibre Reflected Cross-Site Scripting (XSS)
33RISCO
abrir ↗Nucleihigh
AVTECH IP Camera - Command Injection
Command Injection in AVTech AVM1203 (IP Camera)
68RISCO
abrir ↗Nucleimedium
WSO2 User Registration - Arbitrary Account Creation
Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User Signup
28RISCO
abrir ↗Nucleimedium
Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 - Command Injection
Raisecom MSG1200/MSG2100E/MSG2200/MSG2300 Web Interface list_base_config.php os command injection
70RISCO
abrir ↗Nucleihigh
Bylancer Quicklancer 2.4 G - SQL Injection
Bylancer Quicklancer GET Parameter listing sql injection
28RISCO
abrir ↗Nucleimedium
Shield Security Plugin < 20.0.6 - Cross-Site Scripting
Shield Security < 20.0.6 - Reflected XSS
28RISCO
abrir ↗Nucleicritical
AJ-Report < 1.4.1 - Remote Code Execution
anji-plus AJ-Report Authentication Bypass
75RISCO
abrir ↗Nucleicritical
TOTOLINK CP450 v4.1.0cu.747_B20191224 - Hard-Coded Password Vulnerability
TOTOLINK CP450 Telnet Service product.ini hard-coded password
68RISCO
abrir ↗Nucleimedium
TVT DVR Sensitive Device - Information Disclosure
TVT DVR TD-2104TS-CL queryDevInfo information disclosure
60RISCO
abrir ↗Nucleihigh
W&B Weave Server - Remote Arbitrary File Leak
W&B Weave server remote arbitrary file leak and privilege escalation
36RISCO
abrir ↗Nucleimedium
Ninja Forms 3.8.6-3.8.10 - Cross-Site Scripting
Ninja Forms 3.8.6-3.8.10 - Reflected XSS
28RISCO
abrir ↗Nucleihigh
Samsung MagicINFO 9 Server 21.1050.0 - Remote Code Execution
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2
100RISCO
abrir ↗Nucleicritical
Kemp LoadMaster Load Balancer - Unauthenticated Command Injection
Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection
75RISCO
abrir ↗Nucleicritical
Ivanti vTM - Authentication Bypass
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.