Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
4.201 exploits
Nucleicritical
TITool PrintMonitor - Blind SQL Injection
The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based b
23RISCO
abrir
Nucleicritical
Joomla! Component PrayerCenter 3.0.2 - SQL Injection
SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerabil
50RISCO
abrir
Nucleihigh
WordPress Site Editor <=1.1.1 - Local File Inclusion
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISCO
abrir
Nucleihigh
AxxonSoft Axxon Next - Local File Inclusion
AxxonSoft Axxon Next has Directory Traversal via an initial /css//..%2f substring in a URI.
23RISCO
abrir
Nucleihigh
uWSGI PHP Plugin Local File Inclusion
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversa
50RISCO
abrir
Nucleicritical
Drupal - Remote Code Execution
CVE-2018-7600CRITICALsob ataqueransomware
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
Nucleicritical
Drupal - Remote Code Execution
CVE-2018-7602CRITICALsob ataqueransomware
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISCO
abrir
Nucleimedium
YzmCMS v3.6 - Cross-Site Scripting
In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
38RISCO
abrir
Nucleimedium
CouchCMS <= 2.0 - Path Disclosure
Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.fun
30RISCO
abrir
Nucleihigh
DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code Execution
DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php
40RISCO
abrir
Nucleihigh
Acrolinx Server <5.2.5 - Local File Inclusion
Acrolinx Server before 5.2.5 on Windows allows Directory Traversal.
50RISCO
abrir
Nucleihigh
Schneider Electric U.motion Builder - SQL Injection
The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder software ve
18RISCO
abrir
Nucleicritical
Schneider Electric U.motion Builder - Remote Code Execution
CVE-2018-7841CRITICALsob ataque
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code
100RISCO
abrir
Nucleimedium
Apache ActiveMQ <=5.15.5 - Cross-Site Scripting
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console
30RISCO
abrir
Nucleimedium
IceWarp Webmail Server v10.2.1 - Cross Site Scripting
IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.
18RISCO
abrir
Nucleimedium
Ninja Forms < 3.6.26 - Cross-Site Scripting
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RISCO
abrir
Nucleimedium
Contact Form Generator <= 2.5.5 - Cross-Site Scripting
WordPress Contact Form Generator Plugin <= 2.5.5 is vulnerable to Cross Site Scripting (XSS)
36RISCO
abrir
Nucleicritical
HT Mega – Absolute Addons for Elementor <= 2.2.0 - Missing Authorization to Privilege Escalation
WordPress HT Mega Absolute Addons for Elementor plugin <= 2.2.0 - Unauthenticated Privilege Escalation vulnerability
43RISCO
abrir
Nucleicritical
Ivanti Sentry - Authentication Bypass
CVE-2023-38035CRITICALsob ataqueransomware
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an
100RISCO
abrir
Nucleimedium
Revive Adserver 5.4.1 - Cross-Site Scripting
A reflected XSS vulnerability exists in Revive Adserver 5.4.1 and earlier versions..
18RISCO
abrir
Nucleimedium
SuperWebMailer 9.00.0.01710 - Cross-Site Scripting
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwor
18RISCO
abrir
Nucleimedium
SuperWebMailer - Cross-Site Scripting
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter.
18RISCO
abrir
Nucleicritical
Adobe ColdFusion - Deserialization of Untrusted Data
CVE-2023-38203CRITICALsob ataqueransomware
Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE
95RISCO
abrir
Nucleihigh
Adobe ColdFusion - Access Control Bypass
CVE-2023-38205HIGHsob ataque
ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298
88RISCO
abrir
Nucleicritical
Dahua Smart Park Management - Arbitrary File Upload
Dahua Smart Park Management unrestricted upload
70RISCO
abrir
Nucleimedium
mooDating 1.2 - Cross-site scripting
mooSocial mooDating URL question cross site scripting
43RISCO
abrir
Nucleihigh
Fujitsu IP Series - Hardcoded Credentials
Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticat
18RISCO
abrir
Nucleimedium
MooDating 1.2 - Cross-Site Scripting
mooSocial mooDating URL friends cross site scripting
43RISCO
abrir
Nucleimedium
MooDating 1.2 - Cross-Site Scripting
mooSocial mooDating URL ajax_invite cross site scripting
43RISCO
abrir
Nucleimedium
MooDating 1.2 - Cross-Site Scripting
mooSocial mooDating URL pages cross site scripting
43RISCO
abrir
anteriorpágina 85 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.