Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
3.502 exploits
Metasploit300
JBoss Vulnerability Scanner
CVE-2017-12149CRITICALsob ataqueransomware
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir
Metasploit300
JBoss Vulnerability Scanner
CVE-2010-0738MEDIUMsob ataqueransomware
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISCO
abrir
Metasploit300
Peplink Balance routers SQLi
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw
50RISCO
abrir
Metasploit300
NETGEAR Administrator Password Disclosure
CVE-2017-5521HIGHsob ataque
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R
100RISCO
abrir
Metasploit300
JBoss Vulnerability Scanner
CVE-2010-1428HIGHsob ataqueransomware
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4
78RISCO
abrir
Metasploit300
JBoss Vulnerability Scanner
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remot
30RISCO
abrir
Metasploit300
JBoss Vulnerability Scanner
Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 a
30RISCO
abrir
Metasploit300
Jenkins-CI Unauthenticated Script-Console Scanner
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RISCO
abrir
Metasploit300
Joomla Bruteforce Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
Ruby on Rails JSON Processor YAML Deserialization Scanner
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly
60RISCO
abrir
Metasploit300
Ruby on Rails XML Processor YAML Deserialization Scanner
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISCO
abrir
Metasploit300
Apache Reverse Proxy Bypass Vulnerability Scanner
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does
60RISCO
abrir
Metasploit300
RIPS Scanner Directory Traversal
RIPS Scanner v0.54 Path Traversal
36RISCO
abrir
Metasploit300
NTP "NAK to the Future"
Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authen
40RISCO
abrir
Metasploit300
NTP Monitor List Scanner
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
Metasploit300
Apache Tomcat User Enumeration
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, al
60RISCO
abrir
Metasploit300
Tomcat Application Manager Login Utility
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RISCO
abrir
Metasploit300
Tomcat Application Manager Login Utility
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RISCO
abrir
Metasploit300
Tomcat Application Manager Login Utility
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which all
60RISCO
abrir
Metasploit300
ManageEngine DataSecurity Plus Xnode Enumeration
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode
40RISCO
abrir
Metasploit300
ManageEngine ADAudit Plus Xnode Enumeration
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode
40RISCO
abrir
Metasploit300
Tomcat Application Manager Login Utility
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RISCO
abrir
Metasploit300
NNTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
NFS Mount Scanner
NFS exports system-critical data to the world, e.g. / or a password file.
23RISCO
abrir
Metasploit300
NFS Mount Scanner
Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.
23RISCO
abrir
Metasploit300
MySQL Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
MSSQL Login Utility
A Windows NT domain user or administrator account has a default, null, blank, or missing password.
23RISCO
abrir
Metasploit300
HP Intelligent Management BIMS DownloadServlet Directory Traversal
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Soft
30RISCO
abrir
Metasploit300
Novell ZENworks Configuration Management Preboot Service Remote File Access
Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1
23RISCO
abrir
Metasploit300
rsh Authentication Scanner
The rsh/rlogin service is running.
23RISCO
abrir
anteriorpágina 112 / 117próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.