Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8.156Nuclei 4.201Metasploit 3.462✓ só verificadosrecentespopularesrisco
4.201 exploits
Nucleimedium
SAP Knowledge Warehouse <=7.5.0 - Cross-Site Scripting
A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage
43RISCO
abrir ↗Nucleicritical
Visual Tools DVR VX16 4.2.28.0 - Unauthenticated OS Command Injection
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharac
50RISCO
abrir ↗Nucleihigh
KONGA 0.14.9 - Privilege Escalation
Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to pri
23RISCO
abrir ↗Nucleicritical
Sitecore Experience Platform Pre-Auth RCE
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it
100RISCO
abrir ↗Nucleicritical
BillQuick Web Suite SQL Injection
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution
95RISCO
abrir ↗Nucleihigh
WP DSGVO Tools (GDPR) <= 3.1.23 - Unauthenticated Arbitrary Post Deletion
WP DSGVO Tools (GDPR) <= 3.1.23 Unauthenticated Arbitrary Post Deletion
36RISCO
abrir ↗Nucleimedium
Thinfinity VirtualUI User Enumeration
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques
43RISCO
abrir ↗Nucleihigh
Oliver 5 Library Server <8.00.008.053 - Local File Inclusion
An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet functio
18RISCO
abrir ↗Nucleihigh
HD-Network Realtime Monitoring System 2.0 - Local File Inclusion
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_L
50RISCO
abrir ↗Nucleicritical
Apache Log4j2 - Remote Code Injection
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISCO
abrir ↗Nucleicritical
Thinfinity Iframe Injection
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection vi
50RISCO
abrir ↗Nucleicritical
Apache APISIX Dashboard <2.10.1 - API Unauthorized Access
security vulnerability on unauthorized access.
40RISCO
abrir ↗Nucleimedium
Gitea < 1.4.3 - Open Redirect
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
18RISCO
abrir ↗Nucleimedium
AppCMS - Cross-Site Scripting
AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php
18RISCO
abrir ↗Nucleicritical
D-Link - Remote Command Execution
A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L
95RISCO
abrir ↗Nucleicritical
Emerson Dixell XWEB-500 - Arbitrary File Write
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /
23RISCO
abrir ↗Nucleimedium
Reprise License Manager 14.2 - Cross-Site Scripting
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_proce
18RISCO
abrir ↗Nucleicritical
Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Upload
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can uploa
50RISCO
abrir ↗Nucleicritical
Control Web Panel (CWP) - File Inclusion
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to c
65RISCO
abrir ↗Nucleihigh
Slims9 Bulian 9.4.2 - SQL Injection
Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.
18RISCO
abrir ↗Nucleimedium
osTicket 1.15.x - SQL Injection
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticate
18RISCO
abrir ↗Nucleicritical
Pascom CPS Server-Side Request Forgery
An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend To
23RISCO
abrir ↗Nucleihigh
Pascom CPS - Local File Inclusion
An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Pho
23RISCO
abrir ↗Nucleimedium
Sourcecodester Car Rental Management System 1.0 - Stored Cross-Site Scripting
Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter
18RISCO
abrir ↗Nucleimedium
Vehicle Service Management System - Stored Cross-Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the My Account Sec
18RISCO
abrir ↗Nucleimedium
Vehicle Service Management System 1.0 - Stored Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Mechanic List
18RISCO
abrir ↗Nucleimedium
ehicle Service Management System 1.0 - Cross-Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Category List
18RISCO
abrir ↗Nucleimedium
Vehicle Service Management System 1.0 - Stored Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List S
18RISCO
abrir ↗Nucleimedium
Vehicle Service Management System 1.0 - Cross Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the
18RISCO
abrir ↗Nucleihigh
webp_server_go 0.4.0 - Path Traversal
An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary fi
18RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.