Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.032exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.260VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
3.502 exploits
Metasploit300
UPnP SSDP M-SEARCH Information Discovery
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RISCO
abrir ↗Metasploit300
UPnP SSDP M-SEARCH Information Discovery
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RISCO
abrir ↗Metasploit300
UPnP SSDP M-SEARCH Information Discovery
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP
50RISCO
abrir ↗Metasploit300
D-Link DIR-300A / DIR-320 / DIR-615D HTTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
JBoss Vulnerability Scanner
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4
78RISCO
abrir ↗Metasploit300
D-Link DIR-615H HTTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
D-Link DIR-300B / DIR-600B / DIR-815 / DIR-645 HTTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
Microsoft IIS HTTP Internal IP Disclosure
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RISCO
abrir ↗Metasploit300
JBoss Status Servlet Information Gathering
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remot
30RISCO
abrir ↗Metasploit300
JBoss Vulnerability Scanner
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISCO
abrir ↗Metasploit300
Peplink Balance routers SQLi
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw
50RISCO
abrir ↗Metasploit300
JBoss Vulnerability Scanner
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir ↗Metasploit300
Apache Axis2 Brute Force Utility
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISCO
abrir ↗Metasploit300
Atlassian Crowd XML Entity Expansion Remote File Access
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible bef
50RISCO
abrir ↗Metasploit300
Apache "mod_userdir" User Enumeration
Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists a
50RISCO
abrir ↗Metasploit300
JBoss Status Servlet Information Gathering
Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 a
30RISCO
abrir ↗Metasploit300
Twonky Server Log Leak Authentication Bypass
Hard-coded encryption keys in Twonky Server
36RISCO
abrir ↗Metasploit300
Twonky Server Log Leak Authentication Bypass
Unauthenticated log access in Twonky Server
75RISCO
abrir ↗Metasploit300
SolarWinds Serv-U Unauthenticated Arbitrary File Read
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir ↗Metasploit300
Ruby On Rails File Content Disclosure ('doubletap')
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir ↗Metasploit300
WordPress DukaPress Plugin File Read Vulnerability
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2
50RISCO
abrir ↗Metasploit300
Wordpress XML-RPC Username/Password Login Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗← anteriorpágina 117 / 117
Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.