Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8.156Nuclei 4.201Metasploit 3.462✓ só verificadosrecentespopularesrisco
4.201 exploits
Nucleihigh
Apache Flink - Local File Inclusion
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir ↗Nucleihigh
Apache Airflow <1.10.14 - Authentication Bypass
Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a maliciou
23RISCO
abrir ↗Nucleicritical
Apache Struts 2.0.0-2.5.25 - Remote Code Execution
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir ↗Nucleimedium
Z-Blog <=1.5.2 - Open Redirect
Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect"
18RISCO
abrir ↗Nucleimedium
Jeesns 1.4.2 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts o
18RISCO
abrir ↗Nucleimedium
Jeesns 1.4.2 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to ex
18RISCO
abrir ↗Nucleimedium
Jeesns 1.4.2 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to e
18RISCO
abrir ↗Nucleihigh
FHEM 6.0 - Local File Inclusion
Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a fil
23RISCO
abrir ↗Nucleimedium
Vtiger CRM v7.2.0 - Directory Listing
Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directori
18RISCO
abrir ↗Nucleimedium
Apache OFBiz <=16.11.07 - Cross-Site Scripting
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
40RISCO
abrir ↗Nucleimedium
qdPM 9.1 - Cross-site Scripting
qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.
18RISCO
abrir ↗Nucleihigh
Apache Kylin 3.0.1 - Command Injection Vulnerability
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the
100RISCO
abrir ↗Nucleicritical
Gridx 1.3 - Remote Code Execution
Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attack
23RISCO
abrir ↗Nucleimedium
ZZcms - Cross-Site Scripting
There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php
18RISCO
abrir ↗Nucleicritical
WeiPHP 5.0 - SQL Injection
SQL injection vulnerability in the wp_where function in WeiPHP 5.0.
18RISCO
abrir ↗Nucleihigh
Palo Alto Networks PAN-OS Web Interface - Cross Site-Scripting
PAN-OS: Reflected Cross-Site Scripting (XSS) vulnerability in management web interface
41RISCO
abrir ↗Nucleicritical
WordPress File Manager Plugin - Remote Code Execution
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir ↗Nucleicritical
Sophos UTM Preauth - Remote Code Execution
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RISCO
abrir ↗Nucleimedium
Xinuo Openserver 5/6 - Cross-Site scripting
A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote at
38RISCO
abrir ↗Nucleicritical
D-Link DNS-320 - Unauthenticated Remote Code Execution
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead
95RISCO
abrir ↗Nucleicritical
Oracle WebLogic Server - Remote Code Execution
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RISCO
abrir ↗Nucleihigh
ThinkAdmin 6 - Local File Inclusion
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RISCO
abrir ↗Nucleihigh
Commvault CommCell - Local File Inclusion
In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, D
18RISCO
abrir ↗Nucleimedium
HashiCorp Consul/Consul Enterprise <=1.9.4 - Cross-Site Scripting
HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scriptin
18RISCO
abrir ↗Nucleihigh
Cisco SD-WAN vManage Software - Local File Inclusion
Cisco SD-WAN vManage Directory Traversal Vulnerability
41RISCO
abrir ↗Nucleimedium
Event Espresso Core-Reg 4.10.7.p - Cross-Site Scripting
A cross-site scripting (XSS) vulnerability in wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/
18RISCO
abrir ↗Nucleicritical
Alerta < 8.1.0 - Authentication Bypass
LDAP authentication bypass in Alerta
55RISCO
abrir ↗Nucleihigh
PrestaShop Product Comments <4.2.0 - SQL Injection
Blind SQL injection during the CommentGrade process
33RISCO
abrir ↗Nucleihigh
XStream <1.4.15 - Server-Side Request Forgery
Server-Side Forgery Request can be activated unmarshalling with XStream
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.