Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
3.462 exploits
Metasploit300
Microsoft SRV.SYS WriteAndX Invalid DataOffset
srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1
50RISCO
abrir
Metasploit300
Adobe XML External Entity Injection
CVE-2009-3960MEDIUMsob ataqueransomware
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Service
100RISCO
abrir
Metasploit300
Microsoft SRV2.SYS SMB Negotiate ProcessID Function Table Dereference
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISCO
abrir
Metasploit300
Microsoft SRV2.SYS SMB2 Logoff Remote Kernel NULL Pointer Dereference
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISCO
abrir
Metasploit300
Microsoft Windows 7 / Server 2008 R2 SMB Client Infinite Loop
Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB serv
50RISCO
abrir
Metasploit300
Microsoft Windows SRV.SYS SrvSmbQueryFsInformation Pool Overflow DoS
The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2
60RISCO
abrir
Metasploit300
NFS Mount Scanner
NFS exports system-critical data to the world, e.g. / or a password file.
23RISCO
abrir
Metasploit300
rsh Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
SAP Host Agent Information Disclosure
The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attackers to obtain sensitiv
23RISCO
abrir
Metasploit300
rsh Authentication Scanner
The rsh/rlogin service is running.
23RISCO
abrir
Metasploit300
rlogin Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
rlogin Authentication Scanner
The rsh/rlogin service is running.
23RISCO
abrir
Metasploit300
rexec Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
rexec Authentication Scanner
The rsh/rlogin service is running.
23RISCO
abrir
Metasploit300
SAP URL Scanner
CVE-2010-0738MEDIUMsob ataqueransomware
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISCO
abrir
Metasploit300
SAP /sap/bc/soap/rfc SOAP Service RFC_SYSTEM_INFO Function Sensitive Information Gathering
SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an
23RISCO
abrir
Metasploit300
Indusoft WebStudio NTWebServer Remote File Access
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote att
30RISCO
abrir
Metasploit300
X11 No-Auth Scanner
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
23RISCO
abrir
Metasploit300
TeamViewer Unquoted URI Handler SMB Redirect
TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could
23RISCO
abrir
Metasploit300
Cross Platform Webkit File Dropper
WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbi
50RISCO
abrir
Metasploit300
Viproy CUCDM IP Phone XML Services - Call Forwarding Tool
The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application
23RISCO
abrir
Metasploit300
Viproy CUCDM IP Phone XML Services - Speed Dial Attack Tool
The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application
23RISCO
abrir
Metasploit300
MS12-020 Microsoft Remote Desktop Checker
The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows V
60RISCO
abrir
Metasploit300
PostgreSQL Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
PostgreSQL Database Name Command Line Flag Injection
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows re
30RISCO
abrir
Metasploit300
Portmapper Amplification Scanner
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
Metasploit300
PcAnywhere Login Scanner
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
Oracle RDBMS Login Utility
A Unix account has a default, null, blank, or missing password.
50RISCO
abrir
Metasploit300
NTP Clock Variables Disclosure
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
Metasploit300
NTP "NAK to the Future"
Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authen
40RISCO
abrir
anteriorpágina 115 / 116próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.