Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
3.502 exploits
Metasploit300
Cassandra Web File Read Vulnerability
Cassandra Web 0.5.0 - Remote File Read
36RISCO
abrir ↗Metasploit300
Cambium cnPilot r200/r201 SNMP Enumeration
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access
18RISCO
abrir ↗Metasploit300
Cambium ePMP 1000 SNMP Enumeration
An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration
18RISCO
abrir ↗Metasploit300
Cambium ePMP 1000 SNMP Enumeration
An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community string
18RISCO
abrir ↗Metasploit300
SNMP Enumeration Module
An account on a router, firewall, or other network device has a default, null, blank, or missing password.
18RISCO
abrir ↗Metasploit300
SNMP Enumeration Module
An SNMP community name is the default (e.g. public), null, or missing.
33RISCO
abrir ↗Metasploit300
SNMP Community Login Scanner
An account on a router, firewall, or other network device has a default, null, blank, or missing password.
18RISCO
abrir ↗Metasploit300
SSH Username Enumeration
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir ↗Metasploit300
SSH Username Enumeration
OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations
50RISCO
abrir ↗Metasploit300
SSH Username Enumeration
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user d
60RISCO
abrir ↗Metasploit300
SSH Username Enumeration
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir ↗Metasploit300
SSH Login Check Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
SSH Version Scanner
Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2
28RISCO
abrir ↗Metasploit300
Tomcat Application Manager Login Utility
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which all
60RISCO
abrir ↗Metasploit300
FortiOS Path Traversal Credential Gatherer
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir ↗Metasploit300
Tomcat Application Manager Login Utility
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RISCO
abrir ↗Metasploit300
Firefox PDF.js Browser File Theft
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
100RISCO
abrir ↗Metasploit300
Viproy CUCDM IP Phone XML Services - Call Forwarding Tool
The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application
23RISCO
abrir ↗Metasploit300
Viproy CUCDM IP Phone XML Services - Speed Dial Attack Tool
The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application
23RISCO
abrir ↗Metasploit300
FannyBMP or DementiaWheel Detection Registry Check
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 all
100RISCO
abrir ↗Metasploit300
Apple Remote Desktop Root Vulnerability
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RISCO
abrir ↗Metasploit300
VMware Server Directory Traversal Vulnerability
Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on L
60RISCO
abrir ↗Metasploit300
VMware Web Login Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
VMware Authentication Daemon Login Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
Varnish Cache CLI Login Utility
The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy serve
50RISCO
abrir ↗Metasploit300
Varnish Cache CLI File Read
The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy serve
50RISCO
abrir ↗Metasploit300
UPnP SSDP M-SEARCH Information Discovery
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attacke
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.