Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
3.502 exploits
Metasploit500
SIPfoundry sipXezPhone 0.35a CSeq Field Overflow
CVE-2006-352410 jul 2006
Buffer overflow in SIPfoundry sipXtapi released before 20060324 allows remote attackers to execute arbitrary code via a
50RISCO
abrir
Metasploit300
Webmin File Disclosure
CVE-2006-339230 jun 2006
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISCO
abrir
Metasploit200
Private Wire Gateway Buffer Overflow
CVE-2006-325226 jun 2006
Buffer overflow in the Online Registration Facility for Algorithmic Research PrivateWire VPN software up to 3.7 allows r
50RISCO
abrir
Metasploit200
MS06-025 Microsoft RRAS Service Overflow
CVE-2006-237013 jun 2006
Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Serve
60RISCO
abrir
Metasploit400
MS06-025 Microsoft RRAS Service RASMAN Registry Overflow
CVE-2006-237013 jun 2006
Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Serve
60RISCO
abrir
Metasploit200
Cesar FTP 0.99g MKD Command Buffer Overflow
CVE-2006-296112 jun 2006
Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (applicat
50RISCO
abrir
Metasploit400
Qbik WinGate WWW Proxy Server URL Processing Overflow
CVE-2006-292607 jun 2006
Stack-based buffer overflow in the WWW Proxy Server of Qbik WinGate 6.1.1.1077 allows remote attackers to cause a denial
60RISCO
abrir
Metasploit600
SpamAssassin spamd Remote Command Execution
CVE-2006-244706 jun 2006
SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute a
60RISCO
abrir
Metasploit400
Symantec Remote Management Buffer Overflow
CVE-2006-263024 mai 2006
Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitr
60RISCO
abrir
Metasploit300
Cyrus IMAPD pop3d popsubfolders USER Buffer Overflow
CVE-2006-250221 mai 2006
Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allow
50RISCO
abrir
Metasploit300
RealVNC NULL Authentication Mode Bypass
CVE-2006-236915 mai 2006
RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers t
60RISCO
abrir
Metasploit200
FreeSSHd 1.0.9 Key Exchange Algorithm String Buffer Overflow
CVE-2006-240712 mai 2006
Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other produc
60RISCO
abrir
Metasploit200
FreeFTPd 1.0.10 Key Exchange Algorithm String Buffer Overflow
CVE-2006-240712 mai 2006
Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other produc
60RISCO
abrir
Metasploit600
AWStats migrate Remote Command Execution
CVE-2006-223704 mai 2006
The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbit
50RISCO
abrir
Metasploit300
Oracle DB SQL Injection via DBMS_EXPORT_EXTENSION
CVE-2006-208126 abr 2006
Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via the GET_DOMAIN_INDEX_METADA
43RISCO
abrir
Metasploit300
Juniper SSL-VPN IVE JuniperSetupDLL.dll ActiveX Control Buffer Overflow
CVE-2006-208626 abr 2006
Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juni
50RISCO
abrir
Metasploit200
Novell Messenger Server 2.0 Accept-Language Overflow
CVE-2006-099213 abr 2006
Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute ar
60RISCO
abrir
Metasploit600
MS06-014 Microsoft Internet Explorer COM CreateObject Code Execution
CVE-2006-000311 abr 2006
Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and dis
60RISCO
abrir
Metasploit600
MS06-014 Microsoft Internet Explorer COM CreateObject Code Execution
CVE-2006-470411 abr 2006
Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScript
50RISCO
abrir
Metasploit300
UltraVNC 1.0.1 Client Buffer Overflow
CVE-2006-165204 abr 2006
Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-ass
50RISCO
abrir
Metasploit600
PAJAX Remote Command Execution
CVE-2006-155130 mar 2006
Eval injection vulnerability in pajax_call_dispatcher.php in PAJAX 0.5.1 and earlier allows remote attackers to execute
50RISCO
abrir
Metasploit300
MS06-013 Microsoft Internet Explorer createTextRange() Code Execution
CVE-2006-135919 mar 2006
Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arb
50RISCO
abrir
Metasploit200
Mercur v5.0 IMAP SP3 SELECT Buffer Overflow
CVE-2006-125517 mar 2006
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause
50RISCO
abrir
Metasploit200
Mercur Messaging 2005 IMAP Login Buffer Overflow
CVE-2006-125517 mar 2006
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause
50RISCO
abrir
Metasploit200
PeerCast URL Handling Buffer Overflow
CVE-2006-114808 mar 2006
Multiple stack-based buffer overflows in the procConnectArgs function in servmgr.cpp in PeerCast before 0.1217 allow rem
60RISCO
abrir
Metasploit200
PeerCast URL Handling Buffer Overflow
CVE-2006-114808 mar 2006
Multiple stack-based buffer overflows in the procConnectArgs function in servmgr.cpp in PeerCast before 0.1217 allow rem
60RISCO
abrir
Metasploit0
Mail.app Image Attachment Command Execution
CVE-2006-039501 mar 2006
The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an
50RISCO
abrir
Metasploit0
Mail.app Image Attachment Command Execution
CVE-2007-616501 mar 2006
Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDoub
50RISCO
abrir
Metasploit300
Microsoft Internet Explorer isComponentInstalled Overflow
CVE-2006-101624 fev 2006
Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Win
50RISCO
abrir
Metasploit600
Safari Archive Metadata Command Execution
CVE-2006-084821 fev 2006
The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to ex
50RISCO
abrir
anteriorpágina 101 / 117próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.