Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8.176Nuclei 4.202Metasploit 3.462✓ só verificadosrecentespopularesrisco
3.462 exploits
Metasploit300
HP Intelligent Management ReportImgServlt Directory Traversal
Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Netw
23RISCO
abrir ↗Metasploit300
HP Intelligent Management IctDownloadServlet Directory Traversal
Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Netw
23RISCO
abrir ↗Metasploit300
HP Intelligent Management FaultDownloadServlet Directory Traversal
Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Netw
23RISCO
abrir ↗Metasploit300
HP Intelligent Management BIMS DownloadServlet Directory Traversal
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Soft
30RISCO
abrir ↗Metasploit300
HTTP Host Header Injection Detection
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the emai
60RISCO
abrir ↗Metasploit300
Novell Groupwise Agents HTTP Directory Traversal
Directory traversal vulnerability in the agent HTTP interfaces in Novell GroupWise 8.0 before Support Pack 3 and 2012 be
30RISCO
abrir ↗Metasploit300
Embedthis GoAhead Embedded Web Server Directory Traversal
EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remot
23RISCO
abrir ↗Metasploit300
GlassFish Brute Force Utility
Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Applicati
50RISCO
abrir ↗Metasploit300
Carlo Gavazzi Energy Meters - Login Brute Force, Extract Info and Dump Plant Database
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Vers
18RISCO
abrir ↗Metasploit300
FortiMail Unauthenticated Login Bypass Scanner
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 an
40RISCO
abrir ↗Metasploit300
Cambium ePMP 1000 Account Password Reset
In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the
30RISCO
abrir ↗Metasploit300
Cambium ePMP 1000 'ping' Command Injection (up to v2.5)
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RISCO
abrir ↗Metasploit300
Cambium ePMP 1000 'get_chart' Command Injection (v3.1-3.5-RC7)
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RISCO
abrir ↗Metasploit300
Emby Version Scanner
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
40RISCO
abrir ↗Metasploit300
Emby SSRF HTTP Scanner
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
40RISCO
abrir ↗Metasploit300
ElasticSearch Snapshot API Directory Traversal
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unsp
60RISCO
abrir ↗Metasploit300
D-Link DIR-300B / DIR-600B / DIR-815 / DIR-645 HTTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
D-Link DIR-615H HTTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
D-Link DIR-300A / DIR-320 / DIR-615D HTTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
MS09-020 IIS6 WebDAV Unicode Auth Bypass Directory Scanner
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode U
60RISCO
abrir ↗Metasploit300
MS09-020 IIS6 WebDAV Unicode Auth Bypass Directory Scanner
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-
60RISCO
abrir ↗Metasploit300
Dell iDRAC Default Login
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
rexec Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
ColdFusion Server Check
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow re
100RISCO
abrir ↗Metasploit300
Cambium cnPilot r200/r201 Login Scanner and Config Dump
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration fil
18RISCO
abrir ↗Metasploit300
Cisco Network Access Manager Directory Traversal Vulnerability
Directory traversal vulnerability in Cisco Network Admission Control (NAC) Manager 4.8.x allows remote attackers to read
23RISCO
abrir ↗Metasploit300
Cassandra Web File Read Vulnerability
Cassandra Web 0.5.0 - Remote File Read
36RISCO
abrir ↗Metasploit300
Binom3 Web Management Login Scanner, Config and Password File Dump
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Lack of authentication for rem
23RISCO
abrir ↗Metasploit300
Apache Axis2 Brute Force Utility
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.