Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
3.502 exploits
Metasploit300
Cassandra Web File Read Vulnerability
Cassandra Web 0.5.0 - Remote File Read
36RISCO
abrir
Metasploit300
Cambium cnPilot r200/r201 SNMP Enumeration
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access
18RISCO
abrir
Metasploit300
Cambium ePMP 1000 SNMP Enumeration
An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration
18RISCO
abrir
Metasploit300
Cambium ePMP 1000 SNMP Enumeration
An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community string
18RISCO
abrir
Metasploit300
SNMP Enumeration Module
An account on a router, firewall, or other network device has a default, null, blank, or missing password.
18RISCO
abrir
Metasploit300
SNMP Enumeration Module
An SNMP community name is guessable.
23RISCO
abrir
Metasploit300
SNMP Enumeration Module
An SNMP community name is the default (e.g. public), null, or missing.
33RISCO
abrir
Metasploit300
SNMP Community Login Scanner
An account on a router, firewall, or other network device has a default, null, blank, or missing password.
18RISCO
abrir
Metasploit300
SNMP Community Login Scanner
An SNMP community name is guessable.
23RISCO
abrir
Metasploit300
SSH Username Enumeration
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir
Metasploit300
SSH Username Enumeration
OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations
50RISCO
abrir
Metasploit300
SSH Username Enumeration
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user d
60RISCO
abrir
Metasploit300
SSH Username Enumeration
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
Metasploit300
SSH Login Check Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
SSH Version Scanner
Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2
28RISCO
abrir
Metasploit300
Tomcat Application Manager Login Utility
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which all
60RISCO
abrir
Metasploit300
FortiOS Path Traversal Credential Gatherer
CVE-2018-13379CRITICALsob ataqueransomware
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
Metasploit300
Tomcat Application Manager Login Utility
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RISCO
abrir
Metasploit300
Firefox PDF.js Browser File Theft
CVE-2015-4495HIGHsob ataque
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
100RISCO
abrir
Metasploit300
DNS Record Scanner and Enumerator
A DNS server allows zone transfers.
30RISCO
abrir
Metasploit300
Viproy CUCDM IP Phone XML Services - Call Forwarding Tool
The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application
23RISCO
abrir
Metasploit300
Viproy CUCDM IP Phone XML Services - Speed Dial Attack Tool
The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application
23RISCO
abrir
Metasploit300
FannyBMP or DementiaWheel Detection Registry Check
CVE-2010-2568HIGHsob ataque
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 all
100RISCO
abrir
Metasploit300
Apple Remote Desktop Root Vulnerability
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RISCO
abrir
Metasploit300
VMware Server Directory Traversal Vulnerability
Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on L
60RISCO
abrir
Metasploit300
VMware Web Login Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
VMware Authentication Daemon Login Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
Varnish Cache CLI Login Utility
The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy serve
50RISCO
abrir
Metasploit300
Varnish Cache CLI File Read
The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy serve
50RISCO
abrir
Metasploit300
UPnP SSDP M-SEARCH Information Discovery
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attacke
60RISCO
abrir
anteriorpágina 111 / 117próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.