Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
3.462 exploits
Metasploit300
Peplink Balance routers SQLi
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw
50RISCO
abrir
Metasploit300
Sielco Sistemi Winlog Remote File Access
Multiple directory traversal vulnerabilities in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA bef
43RISCO
abrir
Metasploit300
Moxa UDP Device Discovery
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 52
48RISCO
abrir
Metasploit300
Indusoft WebStudio NTWebServer Remote File Access
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote att
30RISCO
abrir
Metasploit300
SAP /sap/bc/soap/rfc SOAP Service RFC_SYSTEM_INFO Function Sensitive Information Gathering
SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an
23RISCO
abrir
Metasploit300
NETGEAR Administrator Password Disclosure
CVE-2017-5521HIGHsob ataque
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R
100RISCO
abrir
Metasploit300
ManageEngine DataSecurity Plus Xnode Enumeration
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode
40RISCO
abrir
Metasploit300
ManageEngine ADAudit Plus Xnode Enumeration
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode
40RISCO
abrir
Metasploit300
SAP URL Scanner
CVE-2010-0738MEDIUMsob ataqueransomware
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISCO
abrir
Metasploit300
SAP Host Agent Information Disclosure
The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attackers to obtain sensitiv
23RISCO
abrir
Metasploit300
rsh Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
rsh Authentication Scanner
The rsh/rlogin service is running.
23RISCO
abrir
Metasploit300
rlogin Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
rlogin Authentication Scanner
The rsh/rlogin service is running.
23RISCO
abrir
Metasploit300
rexec Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
FortiOS Path Traversal Credential Gatherer
CVE-2018-13379CRITICALsob ataqueransomware
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
Metasploit300
Firefox PDF.js Browser File Theft
CVE-2015-4495HIGHsob ataque
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
100RISCO
abrir
Metasploit300
rexec Authentication Scanner
The rsh/rlogin service is running.
23RISCO
abrir
Metasploit300
MS12-020 Microsoft Remote Desktop Checker
The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows V
60RISCO
abrir
Metasploit300
PostgreSQL Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
DNS Record Scanner and Enumerator
A DNS server allows zone transfers.
30RISCO
abrir
Metasploit300
PostgreSQL Database Name Command Line Flag Injection
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows re
30RISCO
abrir
Metasploit300
CrushFTP Unauthenticated Arbitrary File Read
CVE-2024-4040CRITICALsob ataque
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir
Metasploit300
CrushFTP AWS4-HMAC Authentication Bypass
35RISCO
abrir
Metasploit300
Brocade Enable Login Check Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
Check Point Security Gateway Arbitrary File Read
CVE-2024-24919HIGHsob ataqueransomware
Information disclosure
100RISCO
abrir
Metasploit300
Telnet Service Encryption Key ID Overflow Detection
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISCO
abrir
Metasploit300
Argus Surveillance DVR 4.0.0.0 - Directory Traversal
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F
60RISCO
abrir
Metasploit300
Apache Rave User Information Disclosure
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain s
60RISCO
abrir
Metasploit300
Android Open Source Platform (AOSP) Browser UXSS
The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribu
23RISCO
abrir
anteriorpágina 112 / 116próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.