Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8.156Nuclei 4.201Metasploit 3.462✓ só verificadosrecentespopularesrisco
4.201 exploits
Nucleicritical
vBulletin 5.0.0-5.5.4 - Remote Command Execution
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir ↗Nucleicritical
D-Link Routers - Remote Code Execution
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The i
100RISCO
abrir ↗Nucleimedium
WordPress Visualizer <3.3.1 - Cross-Site Scripting
A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute ar
18RISCO
abrir ↗Nucleicritical
Visualizer <3.3.1 - Blind Server-Side Request Forgery
A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-d
30RISCO
abrir ↗Nucleihigh
Metinfo 7.0.0 beta - SQL Injection
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?
23RISCO
abrir ↗Nucleihigh
Metinfo 7.0.0 beta - SQL Injection
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the adm
30RISCO
abrir ↗Nucleimedium
Motors Car Dealer & Classified Ads <= 1.4.0 - Unauthenticated settings import/export
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin
18RISCO
abrir ↗Nucleimedium
WordPress OneTone theme <= 3.0.6 – Unauthenticated Options Changes
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.
18RISCO
abrir ↗Nucleimedium
WordPress OneTone theme <= 3.0.6 – Unauthenticated Stored XSS
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.
18RISCO
abrir ↗Nucleihigh
WordPress Ultimate FAQs <= 1.8.24 – Unauthenticated Options Import and Export
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options im
18RISCO
abrir ↗Nucleimedium
WordPress Ultimate FAQs <= 1.8.24 – Unauthenticated HTML Content Injection
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
18RISCO
abrir ↗Nucleicritical
Yachtcontrol Webapplication 1.0 - Remote Command Injection
Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user vi
30RISCO
abrir ↗Nucleicritical
Zabbix <=4.4 - Authentication Bypass
An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass
30RISCO
abrir ↗Nucleihigh
MetInfo 7.0.0 beta - SQL Injection
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchPa
30RISCO
abrir ↗Nucleicritical
Jfrog Artifactory <6.17.0 - Default Admin Password
JFrog Artifactory does not enforce default admin password change
55RISCO
abrir ↗Nucleimedium
Kirona Dynamic Resource Scheduler - Information Disclosure
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REG
50RISCO
abrir ↗Nucleicritical
D-Link DIR-868L/817LW - Information Disclosure
There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 route
30RISCO
abrir ↗Nucleihigh
Oracle Fusion Middleware WebCenter Sites 12.2.1.3.0 - Broken Access Control
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The suppo
40RISCO
abrir ↗Nucleimedium
Oracle Fusion Middleware WebCenter Sites 12.2.1.3.0 - SQL Injection
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The suppo
18RISCO
abrir ↗Nucleimedium
Oracle Business Intelligence - Path Traversal
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publi
50RISCO
abrir ↗Nucleihigh
Oracle Business Intelligence/XML Publisher - XML External Entity Injection
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publi
100RISCO
abrir ↗Nucleicritical
Oracle WebLogic Server - Remote Command Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir ↗Nucleicritical
Oracle WebLogic Server Administration Console - Remote Code Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISCO
abrir ↗Nucleihigh
Oracle Business Intelligence Publisher - XML External Entity Injection
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publi
18RISCO
abrir ↗Nucleicritical
Atlassian Confluence Server - Path Traversal
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir ↗Nucleihigh
Atlassian Confluence Download Attachments - Remote Code Execution
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RISCO
abrir ↗Nucleimedium
Atlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect Authorization
The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote
23RISCO
abrir ↗Nucleimedium
Jira < 8.1.1 - Cross-Site Scripting
The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows
18RISCO
abrir ↗Nucleimedium
Jira - Incorrect Authorization
The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and fr
30RISCO
abrir ↗Nucleimedium
Spring Cloud Config Server - Local File Inclusion
Directory Traversal with spring-cloud-config-server
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.