Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.026exploits catalogados
36.942CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.254VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
3.502 exploits
Metasploit300
MS17-010 SMB RCE Detection
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir ↗Metasploit300
Viproy CUCDM IP Phone XML Services - Call Forwarding Tool
The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application
23RISCO
abrir ↗Metasploit300
Cambium ePMP 1000 'get_chart' Command Injection (v3.1-3.5-RC7)
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RISCO
abrir ↗Metasploit300
Emby Version Scanner
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
40RISCO
abrir ↗Metasploit300
Emby SSRF HTTP Scanner
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
40RISCO
abrir ↗Metasploit300
ElasticSearch Snapshot API Directory Traversal
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unsp
60RISCO
abrir ↗Metasploit300
NETGEAR Administrator Password Disclosure
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R
100RISCO
abrir ↗Metasploit300
PostgreSQL Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
MS17-010 SMB RCE Detection
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir ↗Metasploit300
MS12-020 Microsoft Remote Desktop Checker
The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows V
60RISCO
abrir ↗Metasploit300
Viproy CUCDM IP Phone XML Services - Speed Dial Attack Tool
The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application
23RISCO
abrir ↗Metasploit300
rexec Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
MS17-010 SMB RCE Detection
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir ↗Metasploit300
rlogin Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
CouchDB Enum Utility
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISCO
abrir ↗Metasploit300
Varnish Cache CLI File Read
The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy serve
50RISCO
abrir ↗Metasploit300
UPnP SSDP M-SEARCH Information Discovery
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attacke
60RISCO
abrir ↗Metasploit300
VNC Authentication None Detection
RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers t
60RISCO
abrir ↗Metasploit300
WordPress Subscribe Comments File Read Vulnerability
Subscribe to Comments <= 2.1.2 - Local File Includion
36RISCO
abrir ↗Metasploit300
WordPress Simple Backup File Read Vulnerability
Simple Backup <= 2.7.10 - Arbitrary File Download via Path Traversal
36RISCO
abrir ↗Metasploit300
WordPress NextGEN Gallery Directory Read Vulnerability
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
23RISCO
abrir ↗Metasploit300
WordPress Mobile Edition File Read Vulnerability
Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary
30RISCO
abrir ↗Metasploit300
DNS Amplification Scanner
The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive querie
30RISCO
abrir ↗Metasploit300
Energizer DUO Trojan Scanner
UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Aru
43RISCO
abrir ↗Metasploit300
Apple Airport ACPP Authentication Scanner
The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fi
23RISCO
abrir ↗Metasploit300
Cross Platform Webkit File Dropper
WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbi
50RISCO
abrir ↗Metasploit300
DNS Amplification Scanner
The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Serve
30RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.