Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
3.462 exploits
Metasploit300
Nginx Source Code Disclosure/Download
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or
60RISCO
abrir
Metasploit300
Netgear SPH200D Directory Traversal Vulnerability
Netgear SPH200D <= 1.0.4.80 Path Traversal via HTTP GET
28RISCO
abrir
Metasploit300
Nagios XI Scanner
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RISCO
abrir
Metasploit300
Nagios XI Scanner
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RISCO
abrir
Metasploit300
Nagios XI Scanner
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user
30RISCO
abrir
Metasploit300
Nagios XI Scanner
CVE-2019-15949HIGHsob ataque
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RISCO
abrir
Metasploit300
Nagios XI Scanner
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post au
23RISCO
abrir
Metasploit300
Lotus Domino Password Hash Collector
IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.n
43RISCO
abrir
Metasploit300
MS15-034 HTTP Protocol Stack Request Handling HTTP.SYS Memory Information Disclosure
CVE-2015-1635CRITICALsob ataque
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir
Metasploit300
MS09-020 IIS6 WebDAV Unicode Authentication Bypass
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode U
60RISCO
abrir
Metasploit300
MS09-020 IIS6 WebDAV Unicode Authentication Bypass
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-
60RISCO
abrir
Metasploit300
Meteocontrol WEBlog Password Extractor
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pag
50RISCO
abrir
Metasploit300
Meteocontrol WEBlog Password Extractor
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext info
23RISCO
abrir
Metasploit300
cups-browsed Information Disclosure
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISCO
abrir
Metasploit300
LiteSpeed Source Code Disclosure/Download
LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scrip
50RISCO
abrir
Metasploit300
Linksys E1500 Directory Traversal Vulnerability
Linksys Routers apply.cgi Path Traversal
28RISCO
abrir
Metasploit300
Linknat Vos Manager Traversal
Linknat VOS Manager Path Traversal File Disclosure
36RISCO
abrir
Metasploit300
Joomla Bruteforce Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
Jenkins-CI Unauthenticated Script-Console Scanner
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RISCO
abrir
Metasploit300
JBoss Vulnerability Scanner
CVE-2010-0738MEDIUMsob ataqueransomware
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISCO
abrir
Metasploit300
JBoss Vulnerability Scanner
CVE-2010-1428HIGHsob ataqueransomware
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4
78RISCO
abrir
Metasploit300
JBoss Vulnerability Scanner
Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 a
30RISCO
abrir
Metasploit300
JBoss Vulnerability Scanner
CVE-2017-12149CRITICALsob ataqueransomware
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir
Metasploit300
JBoss Vulnerability Scanner
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remot
30RISCO
abrir
Metasploit300
Dahua DVR Auth Bypass Scanner
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
60RISCO
abrir
Metasploit300
Multiple DVR Manufacturers Configuration Disclosure
Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Wel
60RISCO
abrir
Metasploit300
JBoss Status Servlet Information Gathering
Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 a
30RISCO
abrir
Metasploit300
JBoss Status Servlet Information Gathering
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remot
30RISCO
abrir
Metasploit300
EasyCafe Server Remote File Access
EasyCafe Server 2.2.14 Remote File Disclosure via Opcode 0x43
36RISCO
abrir
Metasploit300
Microsoft IIS HTTP Internal IP Disclosure
IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (whic
30RISCO
abrir
anteriorpágina 112 / 116próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.