Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
4.201 exploits
Nucleihigh
ProFTPD mod_sql - Preauth User Backdoor
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
36RISCO
abrir
Nucleicritical
ProFTPd-1.3.3c - Backdoor Command Execution
ProFTPD 1.3.3c Backdoor Command Execution
63RISCO
abrir
Nucleimedium
MySQL - Authentication Bypass
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RISCO
abrir
Nucleihigh
Memcached Server SASL Authentication - Remote Code Execution
An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of
48RISCO
abrir
Nucleicritical
Cisco Smart Install - Configuration Download
CVE-2018-0171HIGHsob ataque
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentica
100RISCO
abrir
Nucleihigh
Apache HTTP Server - NULL Pointer Dereference
mod_md, DoS via Coredumps on specially crafted requests
30RISCO
abrir
Nucleicritical
NTPsec > 1.1.3 - 'ctl_getitem' Out-of-Bounds Read
An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read
50RISCO
abrir
Nucleihigh
PostgreSQL 9.3-12.3 Authenticated Remote Code Execution
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
Nucleicritical
Oracle WebLogic Server - Remote Code Execution (Insecure Deserialization)
CVE-2020-14644CRITICALsob ataque
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISCO
abrir
Nucleicritical
Oracle WebLogic Server - Remote Code Execution
CVE-2020-2883CRITICALsob ataque
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISCO
abrir
Nucleicritical
IBM Data Risk Manager - Hardcoded Credentials
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrativ
65RISCO
abrir
Nucleicritical
OpenSMTPD 6.4.0-6.6.1 - Remote Code Execution
CVE-2020-7247CRITICALsob ataque
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISCO
abrir
Nucleicritical
SolarWinds Serv-U FTP - Remote Code Execution
CVE-2021-35211CRITICALsob ataqueransomware
Serv-U Remote Memory Escape Vulnerability
100RISCO
abrir
Nucleicritical
RealTek AP Router SDK - Arbitrary Command Injection
CVE-2021-35394CRITICALsob ataque
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as
95RISCO
abrir
Nucleihigh
PowerDNS Authoritative Server - Denial of Service
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE
30RISCO
abrir
Nucleihigh
Oracle WebLogic Server - Unauthorized Access
CVE-2023-21839HIGHsob ataque
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISCO
abrir
Nucleicritical
VMWare Aria Operations - Remote Code Execution
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key g
75RISCO
abrir
Nucleicritical
Acronis Cyber Infrastructure - Default Password
CVE-2023-45249CRITICALsob ataque
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastruct
85RISCO
abrir
Nucleicritical
Apache ActiveMQ - Remote Code Execution
CVE-2023-46604CRITICALsob ataqueransomware
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
Nucleimedium
OpenSSH Terrapin Attack - Detection
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remot
50RISCO
abrir
Nucleihigh
Jenkins < 2.441 - Arbitrary File Read
CVE-2024-23897CRITICALsob ataqueransomware
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
Nucleicritical
Zimbra Collaboration Suite < 9.0.0 - Remote Code Execution
CVE-2024-45519CRITICALsob ataque
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISCO
abrir
Nucleihigh
CUPS - Remote Code Execution
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISCO
abrir
Nucleimedium
Citrix NetScaler ADC & Gateway - Reflected XSS / Open Redirect
Cross-Site Scripting (XSS)
33RISCO
abrir
Nucleihigh
MongoDB Server - Information Disclosure (MongoBleed)
CVE-2025-14847HIGHsob ataque
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
Nucleihigh
D-Link DIR-823X set_prohibiting - Command Injection
CVE-2025-29635HIGHsob ataque
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrar
88RISCO
abrir
Nucleicritical
Redis < 8.2.1 lua script - Integer Overflow
Lua library commands may lead to integer overflow and potential RCE
36RISCO
abrir
Nucleihigh
Redis Lua Sandbox < 8.2.2 - Cross-User Escape
Redis: Authenticated users can execute LUA scripts as a different user
28RISCO
abrir
Nucleihigh
Redis < 8.2.1 Lua Long-String Delimiter - Out-of-Bounds Read
Redis is vulnerable to DoS via specially crafted LUA scripts
28RISCO
abrir
Nucleicritical
Redis Lua Parser < 8.2.2 - Use After Free
Redis Lua Use-After-Free may lead to remote code execution
85RISCO
abrir
anteriorpágina 88 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.