Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.409exploits catalogados
37.196CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DB
WebGate eDVR Manager 2.6.4 - SiteName Stack Overflow
CVE-2015-2098remotewindows27 mar 2015
Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspe
28RISCO
abrir
Exploit-DB
WebGate Control Center 4.8.7 - GetThumbnail Stack Overflow
CVE-2015-2099remotewindows27 mar 2015
Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vec
28RISCO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3659remotehardware26 mar 2015
20RISCO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7196remotehardware26 mar 2015
20RISCO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3671remotehardware26 mar 2015
20RISCO
abrir
Exploit-DB
pfSense 2.2 - Multiple Vulnerabilities
CVE-2015-2295webappsphp26 mar 2015
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before
35RISCO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7169CRITICALsob ataqueremotehardware26 mar 2015
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISCO
abrir
Exploit-DB
WebGate eDVR Manager - Remote Stack Buffer Overflow
CVE-2015-2097remotewindows26 mar 2015
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary c
28RISCO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7910remotehardware26 mar 2015
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISCO
abrir
Exploit-DB
RM Downloader 2.7.5.400 - Local Buffer Overflow
CVE-2009-1646localwindows26 mar 2015
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RISCO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7169CRITICALsob ataqueremotehardware26 mar 2015
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISCO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3659remotehardware26 mar 2015
20RISCO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7227remotehardware26 mar 2015
20RISCO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-62771remotehardware26 mar 2015
20RISCO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7227remotehardware26 mar 2015
20RISCO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-62771remotehardware26 mar 2015
20RISCO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3671remotehardware26 mar 2015
20RISCO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-6271CRITICALsob ataqueremotehardware26 mar 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7910remotehardware26 mar 2015
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISCO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7196remotehardware26 mar 2015
20RISCO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-6271CRITICALsob ataqueremotehardware26 mar 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Remote Code Execution (Add Admin)
CVE-2014-9014webappsphp25 mar 2015
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b
28RISCO
abrir
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Remote Code Execution (Add Admin)
CVE-2014-9013webappsphp25 mar 2015
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth
35RISCO
abrir
Exploit-DB
Adobe Flash Player - Arbitrary Code Execution
CVE-2015-0313HIGHsob ataqueremotewindows25 mar 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox - Proxy Prototype Privileged JavaScript Injection (Metasploit)
CVE-2014-8636remotemultiple24 mar 2015
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with
50RISCO
abrir
Exploit-DBVexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' Local Buffer Overflow
CVE-2011-5165localwindows22 mar 2015
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISCO
abrir
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Arbitrary File Download
CVE-2014-9014webappsphp22 mar 2015
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b
28RISCO
abrir
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Arbitrary File Download
CVE-2014-9013webappsphp22 mar 2015
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth
35RISCO
abrir
Exploit-DB
Telescope 0.9.2 - Markdown Persistent Cross-Site Scripting
CVE-2014-5144webappsphp21 mar 2015
Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary
23RISCO
abrir
Exploit-DB
EMC M&R (Watch4net) - Credential Disclosure
CVE-2015-0514webappsjava19 mar 2015
EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-cen
23RISCO
abrir
anteriorpágina 199 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.