Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.032exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
3.502 exploits
Metasploit300
UPnP SSDP M-SEARCH Information Discovery
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RISCO
abrir
Metasploit300
UPnP SSDP M-SEARCH Information Discovery
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RISCO
abrir
Metasploit300
UPnP SSDP M-SEARCH Information Discovery
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP
50RISCO
abrir
Metasploit300
D-Link DIR-300A / DIR-320 / DIR-615D HTTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
JBoss Vulnerability Scanner
CVE-2010-1428HIGHsob ataqueransomware
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4
78RISCO
abrir
Metasploit300
D-Link DIR-615H HTTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
D-Link DIR-300B / DIR-600B / DIR-815 / DIR-645 HTTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
Microsoft IIS HTTP Internal IP Disclosure
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RISCO
abrir
Metasploit300
JBoss Status Servlet Information Gathering
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remot
30RISCO
abrir
Metasploit300
JBoss Vulnerability Scanner
CVE-2010-0738MEDIUMsob ataqueransomware
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISCO
abrir
Metasploit300
Peplink Balance routers SQLi
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw
50RISCO
abrir
Metasploit300
JBoss Vulnerability Scanner
CVE-2017-12149CRITICALsob ataqueransomware
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir
Metasploit300
Apache Axis2 Brute Force Utility
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISCO
abrir
Metasploit300
Atlassian Crowd XML Entity Expansion Remote File Access
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible bef
50RISCO
abrir
Metasploit300
Apache "mod_userdir" User Enumeration
Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists a
50RISCO
abrir
Metasploit300
JBoss Status Servlet Information Gathering
Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 a
30RISCO
abrir
Metasploit300
Twonky Server Log Leak Authentication Bypass
Hard-coded encryption keys in Twonky Server
36RISCO
abrir
Metasploit300
Twonky Server Log Leak Authentication Bypass
Unauthenticated log access in Twonky Server
75RISCO
abrir
Metasploit300
SolarWinds Serv-U Unauthenticated Arbitrary File Read
CVE-2024-28995HIGHsob ataque
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir
Metasploit300
Ruby On Rails File Content Disclosure ('doubletap')
CVE-2019-5418HIGHsob ataque
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
Metasploit300
WordPress DukaPress Plugin File Read Vulnerability
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2
50RISCO
abrir
Metasploit300
Wordpress XML-RPC Username/Password Login Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
anteriorpágina 117 / 117

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.