Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
4.201 exploits
Nucleihigh
Piwigo 13.7.0 - SQL Injection
Piwigo SQL Injection vulnerability in "User-Agent"
36RISCO
abrir
Nucleihigh
XWiki Platform - Remote Code Execution
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-skin-ui
65RISCO
abrir
Nucleihigh
Copyparty <= 1.8.2 - Directory Traversal
Path traversal in copyparty
48RISCO
abrir
Nucleimedium
Zimbra Collaboration Suite (ZCS) v.8.8.15 - Cross-Site Scripting
CVE-2023-37580MEDIUMsob ataque
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
70RISCO
abrir
Nucleihigh
Issabel PBX 4.0.0-6 - Directory Listing
An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
18RISCO
abrir
Nucleicritical
Online Piggery Management System v1.0 - Unauthenticated File Upload
Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by send
43RISCO
abrir
Nucleimedium
EyouCms v1.6.3 - Information Disclosure
eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/re
23RISCO
abrir
Nucleicritical
MLflow Absolute Path Traversal
Absolute Path Traversal in mlflow/mlflow
55RISCO
abrir
Nucleicritical
NextGen Mirth Connect - Remote Code Execution
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary com
40RISCO
abrir
Nucleimedium
IceWarp 11.4.6.0 - Cross-Site Scripting
IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.
18RISCO
abrir
Nucleicritical
PrestaShop Theme Volty CMS Blog - SQL Injection
Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter a
18RISCO
abrir
Nucleimedium
PrestaShop fieldpopupnewsletter Module - Cross Site Scripting
FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerabi
18RISCO
abrir
Nucleihigh
PrestaShop MyPrestaModules - PhpInfo Disclosure
MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInf
30RISCO
abrir
Nucleimedium
IceWarp Mail Server v10.4.5 - Cross-Site Scripting
IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color
18RISCO
abrir
Nucleicritical
WBCE 1.6.0 - SQL Injection
SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute
18RISCO
abrir
Nucleimedium
Mingsoft MCMS < 5.3.1 - Cross-Site Scripting
Mingsoft MCMS HTTP POST Request search.do cross site scripting
23RISCO
abrir
Nucleihigh
LiteSpeed Cache <= 5.7 - Unauthenticated Stored XSS
WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability
68RISCO
abrir
Nucleicritical
WS_FTP Server - Insecure Deserialization
CVE-2023-40044CRITICALsob ataqueransomware
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability
100RISCO
abrir
Nucleimedium
Stock Ticker <= 3.23.2 - Cross-Site Scripting
WordPress Stock Ticker Plugin <= 3.23.3 is vulnerable to Cross Site Scripting (XSS)
36RISCO
abrir
Nucleihigh
Post Grid <= 2.2.50 - Information Exposure via REST API
WordPress Post Grid Plugin <= 2.2.50 is vulnerable to Sensitive Data Exposure
36RISCO
abrir
Nucleimedium
Axigen WebMail - Cross-Site Scripting
Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0
28RISCO
abrir
Nucleicritical
LG Simple Editor <= v3.21.0 - Command Injection
LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability
65RISCO
abrir
Nucleimedium
EWWW Image Optimizer <= 7.2.0 - Unauthenticated Information Disclosure
WordPress EWWW Image Optimizer Plugin <= 7.2.0 is vulnerable to Sensitive Data Exposure
48RISCO
abrir
Nucleicritical
PHPJabbers Food Delivery Script - SQL Injection
PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.
18RISCO
abrir
Nucleicritical
PHPJabbers Food Delivery Script v3.0 - SQL Injection
PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.
18RISCO
abrir
Nucleimedium
PHPJabbers Yacht Listing Script v1.0 - Cross-Site Scripting
There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Yacht Listing S
18RISCO
abrir
Nucleimedium
PHPJabbers Fundraising Script v1.0 - Cross-Site Scripting
PHPJabbers Fundraising Script v1.0 is vulnerable to Cross Site Scripting (XSS) via the "action" parameter of index.php.
18RISCO
abrir
Nucleimedium
PHPJabbers Make an Offer Widget v1.0 - Cross-Site Scripting
There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer W
18RISCO
abrir
Nucleimedium
PHPJabbers Ticket Support Script v3.2 - Cross-Site Scripting
There is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support S
18RISCO
abrir
Nucleimedium
PHPJabbers Callback Widget v1.0 - Cross-Site Scripting
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widge
18RISCO
abrir
anteriorpágina 84 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.