Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8.176Nuclei 4.202Metasploit 3.462✓ só verificadosrecentespopularesrisco
3.462 exploits
Metasploit300
Varnish Cache CLI Login Utility
The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy serve
50RISCO
abrir ↗Metasploit300
VMware Authentication Daemon Login Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
VMware Web Login Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
VMware Server Directory Traversal Vulnerability
Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on L
60RISCO
abrir ↗Metasploit300
Apple Remote Desktop Root Vulnerability
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RISCO
abrir ↗Metasploit300
VNC Authentication Scanner
A Windows NT domain user or administrator account has a default, null, blank, or missing password.
23RISCO
abrir ↗Metasploit300
VNC Authentication None Detection
RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers t
60RISCO
abrir ↗Metasploit300
WinRM Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
TrendMicro OfficeScanNT Listener Traversal Arbitrary File Access
Directory traversal vulnerability in the UpdateAgent function in TmListen.exe in the OfficeScanNT Listener service in th
23RISCO
abrir ↗Metasploit300
Check For and Prep the Pyrotechnic Devices (Airbags, Battery Clamps, etc.)
The airbag detonation algorithm allows injury to passenger-car occupants via predictable Security Access (SA) data to th
18RISCO
abrir ↗Metasploit300
Linux DoS Xen 4.2.0 2012-5525
The get_page_from_gfn hypercall function in Xen 4.2 allows local PV guest OS administrators to cause a denial of service
18RISCO
abrir ↗Metasploit300
Cisco Secure ACS Unauthorized Password Change
The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 before 5.1.0.44.6 and 5.2 before 5.2.
23RISCO
abrir ↗Metasploit300
Haserl Arbitrary File Reader
Lack of verification in haserl, a component of Alpine Linux Configuration Framework, before 0.9.36 allows local users to
18RISCO
abrir ↗Metasploit300
Cisco ASA Authentication Bypass (EXTRABACON)
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Service
100RISCO
abrir ↗Metasploit300
Diagnostics Agent in Solution Manager, stores unencrypted credentials for Solution Manager server
Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as So
18RISCO
abrir ↗Metasploit300
Bypass the macOS TCC Framework
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue
78RISCO
abrir ↗Metasploit300
Ulterius Server File Download Vulnerability
The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory
60RISCO
abrir ↗Metasploit300
TYPO3 sa-2010-020 Remote File Disclosure
The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before
43RISCO
abrir ↗Metasploit300
Windows Pulse Secure Connect Client Saved Password Extractor
Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settin
23RISCO
abrir ↗Metasploit300
Windows Gather TeamViewer Passwords
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for dif
86RISCO
abrir ↗Metasploit300
Novell File Reporter Agent Arbitrary File Delete
NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pa
23RISCO
abrir ↗Metasploit300
Windows Gather Forensics Duqu Registry Check
Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Wind
88RISCO
abrir ↗Metasploit300
Oracle RDBMS Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
FannyBMP or DementiaWheel Detection Registry Check
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 all
100RISCO
abrir ↗Metasploit300
PcAnywhere Login Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
Portmapper Amplification Scanner
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir ↗Metasploit300
PostgreSQL Database Name Command Line Flag Injection
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows re
30RISCO
abrir ↗Metasploit300
PostgreSQL Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir ↗Metasploit300
MS12-020 Microsoft Remote Desktop Checker
The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows V
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.