Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8.176Nuclei 4.202Metasploit 3.462✓ só verificadosrecentespopularesrisco
3.462 exploits
Metasploit300
Nginx Source Code Disclosure/Download
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or
60RISCO
abrir ↗Metasploit300
Netgear SPH200D Directory Traversal Vulnerability
Netgear SPH200D <= 1.0.4.80 Path Traversal via HTTP GET
28RISCO
abrir ↗Metasploit300
Nagios XI Scanner
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RISCO
abrir ↗Metasploit300
Nagios XI Scanner
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RISCO
abrir ↗Metasploit300
Nagios XI Scanner
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user
30RISCO
abrir ↗Metasploit300
Nagios XI Scanner
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RISCO
abrir ↗Metasploit300
Nagios XI Scanner
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post au
23RISCO
abrir ↗Metasploit300
Lotus Domino Password Hash Collector
IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.n
43RISCO
abrir ↗Metasploit300
MS15-034 HTTP Protocol Stack Request Handling HTTP.SYS Memory Information Disclosure
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir ↗Metasploit300
MS09-020 IIS6 WebDAV Unicode Authentication Bypass
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode U
60RISCO
abrir ↗Metasploit300
MS09-020 IIS6 WebDAV Unicode Authentication Bypass
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-
60RISCO
abrir ↗Metasploit300
Meteocontrol WEBlog Password Extractor
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pag
50RISCO
abrir ↗Metasploit300
Meteocontrol WEBlog Password Extractor
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext info
23RISCO
abrir ↗Metasploit300
cups-browsed Information Disclosure
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISCO
abrir ↗Metasploit300
LiteSpeed Source Code Disclosure/Download
LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scrip
50RISCO
abrir ↗Metasploit300
Linksys E1500 Directory Traversal Vulnerability
Linksys Routers apply.cgi Path Traversal
28RISCO
abrir ↗Metasploit300
Linknat Vos Manager Traversal
Linknat VOS Manager Path Traversal File Disclosure
36RISCO
abrir ↗Metasploit300
Joomla Bruteforce Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
Jenkins-CI Unauthenticated Script-Console Scanner
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RISCO
abrir ↗Metasploit300
JBoss Vulnerability Scanner
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISCO
abrir ↗Metasploit300
JBoss Vulnerability Scanner
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4
78RISCO
abrir ↗Metasploit300
JBoss Vulnerability Scanner
Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 a
30RISCO
abrir ↗Metasploit300
JBoss Vulnerability Scanner
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir ↗Metasploit300
JBoss Vulnerability Scanner
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remot
30RISCO
abrir ↗Metasploit300
Dahua DVR Auth Bypass Scanner
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
60RISCO
abrir ↗Metasploit300
Multiple DVR Manufacturers Configuration Disclosure
Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Wel
60RISCO
abrir ↗Metasploit300
JBoss Status Servlet Information Gathering
Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 a
30RISCO
abrir ↗Metasploit300
JBoss Status Servlet Information Gathering
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remot
30RISCO
abrir ↗Metasploit300
EasyCafe Server Remote File Access
EasyCafe Server 2.2.14 Remote File Disclosure via Opcode 0x43
36RISCO
abrir ↗Metasploit300
Microsoft IIS HTTP Internal IP Disclosure
IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (whic
30RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.