Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.432exploits catalogados
34.424CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DB
WordPress Plugin Simple Ads Manager 2.5.94 - Arbitrary File Upload
CVE-2015-2825webappsphp02 abr 2015
Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPres
28RISCO
abrir
Exploit-DBVexDay Proof
WebGate eDVR Manager 2.6.4 - Connect Method Stack Buffer Overflow
CVE-2015-2097remotewindows02 abr 2015
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary c
28RISCO
abrir
Exploit-DB
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
CVE-2014-7227webappsmultiple02 abr 2015
20RISCO
abrir
Exploit-DB
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
CVE-2014-62771webappsmultiple02 abr 2015
20RISCO
abrir
Exploit-DB
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
CVE-2014-7910webappsmultiple02 abr 2015
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISCO
abrir
Exploit-DB
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
CVE-2014-7169CRITICALsob ataquewebappsmultiple02 abr 2015
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Simple Ads Manager - Multiple SQL Injections
CVE-2015-2824webappsphp02 abr 2015
Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attacke
23RISCO
abrir
Exploit-DB
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
CVE-2014-5288webappsmultiple02 abr 2015
A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.
23RISCO
abrir
Exploit-DB
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
CVE-2014-5287webappsmultiple02 abr 2015
A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input i
23RISCO
abrir
Exploit-DB
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
CVE-2014-3659webappsmultiple02 abr 2015
20RISCO
abrir
Exploit-DB
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
CVE-2014-3671webappsmultiple02 abr 2015
20RISCO
abrir
Exploit-DBVexDay Proof
Ceragon FibeAir IP-10 - SSH Private Key Exposure (Metasploit)
CVE-2015-0936remotelinux01 abr 2015
Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remot
60RISCO
abrir
Exploit-DB
Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities
CVE-2014-9145webappsphp31 mar 2015
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
Exploit-DB
Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities
CVE-2014-9146webappsphp31 mar 2015
Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web s
23RISCO
abrir
Exploit-DB
Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities
CVE-2014-1222webappsphp31 mar 2015
Directory traversal vulnerability in kcfinder/browse.php in Vtiger CRM before 6.0.0 Security patch 1 allows remote authe
23RISCO
abrir
Exploit-DB
Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities
CVE-2014-9148webappsphp31 mar 2015
Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update"
28RISCO
abrir
Exploit-DB
Palo Alto Traps Server 3.1.2.1546 - Persistent Cross-Site Scripting
CVE-2015-2223webappswindows31 mar 2015
Multiple cross-site scripting (XSS) vulnerabilities in the web-based console management interface in Palo Alto Networks
23RISCO
abrir
Exploit-DB
Airties Air5650TT - Remote Stack Overflow
CVE-2015-2797remotemultiple31 mar 2015
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 502
60RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - ByteArray With Workers Use-After-Free (Metasploit)
CVE-2015-0313HIGHsob ataqueremotewindows31 mar 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RISCO
abrir
Exploit-DB
Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities
CVE-2014-9147webappsphp31 mar 2015
Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup fil
28RISCO
abrir
Exploit-DB
Fedora 21 setroubleshootd 3.2.22 - Local Privilege Escalation
CVE-2015-1815locallinux30 mar 2015
The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to ex
28RISCO
abrir
Exploit-DB
WordPress Plugin Slider REvolution 4.1.4 - Arbitrary File Download
CVE-2015-1579webappsphp30 mar 2015
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RISCO
abrir
Exploit-DB
Joomla! Component Contact Form Maker 1.0.1 - SQL Injection
CVE-2015-2798webappsphp30 mar 2015
SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary S
23RISCO
abrir
Exploit-DB
WordPress Plugin Slider REvolution 4.1.4 - Arbitrary File Download
CVE-2014-9734webappsphp30 mar 2015
Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote att
28RISCO
abrir
Exploit-DB
WebGate WinRDS 2.0.8 - StopSiteAllChannel Stack Overflow
CVE-2015-2094remotewindows27 mar 2015
Stack-based buffer overflow in the WESPPlayback.WESPPlaybackCtrl.1 control in WebGate WinRDS allows remote attackers to
28RISCO
abrir
Exploit-DBVexDay Proof
Acunetix 9.5 - OLE Automation Array Remote Code Execution
CVE-2014-6332HIGHsob ataqueremotewindows27 mar 2015
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISCO
abrir
Exploit-DB
Berta CMS - Arbitrary File Upload
CVE-2015-2780webappsphp27 mar 2015
Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a cra
28RISCO
abrir
Exploit-DB
WebGate eDVR Manager 2.6.4 - SiteName Stack Overflow
CVE-2015-2098remotewindows27 mar 2015
Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspe
28RISCO
abrir
Exploit-DB
WebGate Control Center 4.8.7 - GetThumbnail Stack Overflow
CVE-2015-2099remotewindows27 mar 2015
Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vec
28RISCO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7227remotehardware26 mar 2015
20RISCO
abrir
anteriorpágina 197 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.