Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
3.502 exploits
Metasploit300
Cambium cnPilot r200/r201 File Path Traversal
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web ad
18RISCO
abrir ↗Metasploit300
Cambium cnPilot r200/r201 Command Execution as 'root'
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web
30RISCO
abrir ↗Metasploit300
Novell eDirectory eMBox Unauthenticated File Access
The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on clien
50RISCO
abrir ↗Metasploit300
Novell eDirectory DHOST Predictable Session Cookie
The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote att
50RISCO
abrir ↗Metasploit300
Active Directory Certificate Services (ADCS) privilege escalation (Certifried)
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISCO
abrir ↗Metasploit300
Netlogon Weak Cryptographic Authentication
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir ↗Metasploit300
Veritas Backup Exec Server Registry Access
VERITAS Backup Exec Server (beserver.exe) 9.0 through 10.0 for Windows allows remote unauthenticated attackers to modify
30RISCO
abrir ↗Metasploit300
Veritas Backup Exec Windows Remote File Access
VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for
60RISCO
abrir ↗Metasploit300
Android Browser RCE Through Google Play Store XFO
The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribu
23RISCO
abrir ↗Metasploit300
Samba read_nttrans_ea_list Integer Overflow
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.
50RISCO
abrir ↗Metasploit300
NTP Clock Variables Disclosure
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir ↗Metasploit300
NTP "NAK to the Future"
Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authen
40RISCO
abrir ↗Metasploit300
NTP Monitor List Scanner
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir ↗Metasploit300
NNTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
NFS Mount Scanner
NFS exports system-critical data to the world, e.g. / or a password file.
23RISCO
abrir ↗Metasploit300
NFS Mount Scanner
Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.
23RISCO
abrir ↗Metasploit300
MySQL Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
MSSQL Login Utility
A Windows NT domain user or administrator account has a default, null, blank, or missing password.
23RISCO
abrir ↗Metasploit300
Novell ZENworks Configuration Management Preboot Service Remote File Access
Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1
23RISCO
abrir ↗Metasploit300
Tomcat Application Manager Login Utility
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RISCO
abrir ↗Metasploit300
Tomcat Application Manager Login Utility
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which all
60RISCO
abrir ↗Metasploit300
Tomcat Application Manager Login Utility
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RISCO
abrir ↗Metasploit300
Tomcat Application Manager Login Utility
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RISCO
abrir ↗Metasploit300
Apache Tomcat User Enumeration
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, al
60RISCO
abrir ↗Metasploit300
Apache Reverse Proxy Bypass Vulnerability Scanner
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does
60RISCO
abrir ↗Metasploit300
Ruby on Rails XML Processor YAML Deserialization Scanner
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISCO
abrir ↗Metasploit300
Ruby on Rails JSON Processor YAML Deserialization Scanner
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly
60RISCO
abrir ↗Metasploit300
PcAnywhere Login Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
Portmapper Amplification Scanner
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.