Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
3.502 exploits
Metasploit300
Nagios XI Scanner
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RISCO
abrir
Metasploit300
Nagios XI Scanner
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post au
23RISCO
abrir
Metasploit300
rexec Authentication Scanner
The rsh/rlogin service is running.
23RISCO
abrir
Metasploit300
rexec Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
rlogin Authentication Scanner
The rsh/rlogin service is running.
23RISCO
abrir
Metasploit300
SSH Version Scanner
Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2
28RISCO
abrir
Metasploit300
rlogin Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
SSH Login Check Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
SSH Username Enumeration
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
Metasploit300
rsh Authentication Scanner
The rsh/rlogin service is running.
23RISCO
abrir
Metasploit300
rsh Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
SAP Host Agent Information Disclosure
The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attackers to obtain sensitiv
23RISCO
abrir
Metasploit300
MS15-034 HTTP Protocol Stack Request Handling HTTP.SYS Memory Information Disclosure
CVE-2015-1635CRITICALsob ataque
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir
Metasploit300
MS09-020 IIS6 WebDAV Unicode Authentication Bypass
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-
60RISCO
abrir
Metasploit300
SAP URL Scanner
CVE-2010-0738MEDIUMsob ataqueransomware
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISCO
abrir
Metasploit300
SAP /sap/bc/soap/rfc SOAP Service RFC_SYSTEM_INFO Function Sensitive Information Gathering
SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an
23RISCO
abrir
Metasploit300
Indusoft WebStudio NTWebServer Remote File Access
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote att
30RISCO
abrir
Metasploit300
Moxa UDP Device Discovery
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 52
48RISCO
abrir
Metasploit300
Sielco Sistemi Winlog Remote File Access
Multiple directory traversal vulnerabilities in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA bef
43RISCO
abrir
Metasploit300
Microsoft Windows Authenticated Logged In Users Enumeration
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
SMB Group Policy Preference Saved Passwords Enumeration
CVE-2014-1812HIGHsob ataqueransomware
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo
98RISCO
abrir
Metasploit300
MS09-020 IIS6 WebDAV Unicode Authentication Bypass
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode U
60RISCO
abrir
Metasploit300
Meteocontrol WEBlog Password Extractor
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext info
23RISCO
abrir
Metasploit300
Meteocontrol WEBlog Password Extractor
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pag
50RISCO
abrir
Metasploit300
SMB Login Check Scanner
A Windows NT domain user or administrator account has a default, null, blank, or missing password.
23RISCO
abrir
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0144HIGHsob ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0145HIGHsob ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0143HIGHsob ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0146HIGHsob ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0147HIGHsob ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
anteriorpágina 114 / 117próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.