Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
4.201 exploits
Nucleihigh
WordPress wpCentral <1.5.1 - Information Disclosure
The wpCentral plugin before 1.5.1 for WordPress allows disclosure of the connection key.
18RISCO
abrir
Nucleihigh
exacqVision Web Service - Remote Code Execution
exacqVision Software - Improper Verification of Cryptographic Signature
28RISCO
abrir
Nucleicritical
Zyxel NAS Firmware 5.21- Remote Code Execution
CVE-2020-9054CRITICALsob ataque
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
100RISCO
abrir
Nucleimedium
Oracle iPlanet Web Server 7.0.x - Image Injection
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration c
18RISCO
abrir
Nucleihigh
Oracle iPlanet Web Server 7.0.x - Authentication Bypass
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/vers
40RISCO
abrir
Nucleimedium
Jira Subversion ALM for Enterprise <8.8.2 - Cross-Site Scripting
Subversion ALM for the enterprise before 8.8.2 allows reflected XSS at multiple locations.
18RISCO
abrir
Nucleihigh
D-Link DIR-610 Devices - Information Disclosure
D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE
23RISCO
abrir
Nucleihigh
rConfig <3.9.4 - Sensitive Information Disclosure
An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved
23RISCO
abrir
Nucleicritical
Apache Spark - Authentication Bypass
In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (s
23RISCO
abrir
Nucleihigh
SkyWalking SQLI
**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is
30RISCO
abrir
Nucleihigh
Apache Tomcat Remote Command Execution
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a)
30RISCO
abrir
Nucleimedium
Apache OFBiz 17.12.03 - Cross-Site Scripting
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISCO
abrir
Nucleicritical
FasterXML jackson-databind - Deserialization Remote Code Execution
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela
23RISCO
abrir
Nucleicritical
FasterXML Jackson Databind <=2.9.10.4 - Remote Code Execution
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela
23RISCO
abrir
Nucleicritical
Craft CMS < 3.3.0 - Server-Side Template Injection
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed
40RISCO
abrir
Nucleicritical
Cisco Small Business RV Series - OS Command Injection
Cisco Small Business RV Series Routers Vulnerabilities
50RISCO
abrir
Nucleimedium
Advantech R-SeeNet - Cross-Site Scripting
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web application
43RISCO
abrir
Nucleicritical
Advantech R-SeeNet 2.4.12 - OS Command Injection
An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.
55RISCO
abrir
Nucleimedium
D-Link DIR-3040 1.13B03 - Information Disclosure
An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. A specially craft
40RISCO
abrir
Nucleicritical
Lantronix PremierWave 2050 8.9.0.0R4 - Remote Command Injection
An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix Prem
55RISCO
abrir
Nucleicritical
VMware vSphere Client (HTML5) - Remote Code Execution
CVE-2021-21972CRITICALsob ataqueransomware
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
Nucleimedium
VMware vSphere - Server-Side Request Forgery
CVE-2021-21973MEDIUMsob ataque
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of UR
100RISCO
abrir
Nucleihigh
vRealize Operations Manager API - Server-Side Request Forgery
CVE-2021-21975HIGHsob ataqueransomware
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir
Nucleicritical
VMware View Planner <4.6 SP1- Remote Code Execution
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input val
60RISCO
abrir
Nucleicritical
VMware vSphere Client (HTML5) - Remote Code Execution
CVE-2021-21985CRITICALsob ataqueransomware
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISCO
abrir
Nucleicritical
VMware vCenter Server - Arbitrary File Upload
CVE-2021-22005CRITICALsob ataqueransomware
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
Nucleimedium
vCenter Server - Improper Access Control
CVE-2021-22017MEDIUMsob ataque
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A mali
70RISCO
abrir
Nucleihigh
Spring Cloud Netflix Hystrix Dashboard <2.2.10 - Remote Code Execution
Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to exe
23RISCO
abrir
Nucleihigh
VMWare Workspace ONE UEM - Server-Side Request Forgery
CVE-2021-22054HIGHsob ataque
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and
100RISCO
abrir
Nucleimedium
FortiWeb - Cross Site Scripting
An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version
23RISCO
abrir
anteriorpágina 89 / 141próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.