Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.432exploits catalogados
34.424CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
Publish-It - '.PUI' Local Buffer Overflow (SEH) (Metasploit)
CVE-2014-0980localwindows19 mar 2015
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RISCO
abrir
Exploit-DB
Citrix Nitro SDK - Command Injection
CVE-2015-2838webappslinux19 mar 2015
Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote
23RISCO
abrir
Exploit-DB
Citrix Command Center - Credential Disclosure
CVE-2015-2682webappsxml19 mar 2015
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via
28RISCO
abrir
Exploit-DBVexDay Proof
Exim - 'GHOST' glibc gethostbyname Buffer Overflow (Metasploit)
CVE-2015-0235remotelinux18 mar 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RISCO
abrir
Exploit-DB
Websense Appliance Manager - Command Injection
CVE-2015-2746webappsjava18 mar 2015
The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON
28RISCO
abrir
Exploit-DBVexDay Proof
Fortinet Single Sign On - Stack Overflow
CVE-2015-2281doswindows18 mar 2015
Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attac
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - PCRE Regex (Metasploit)
CVE-2015-0318remotewindows17 mar 2015
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442
60RISCO
abrir
Exploit-DB
Moodle 2.5.9/2.6.8/2.7.5/2.8.3 - Block Title Handler Cross-Site Scripting
CVE-2015-2269webappsphp17 mar 2015
Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript-static.js in Moodle through 2.5.9, 2.6.x before 2.
23RISCO
abrir
Exploit-DB
WordPress Plugin WPML 3.1.9 - Multiple Vulnerabilities
CVE-2015-2314webappsphp16 mar 2015
SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary S
23RISCO
abrir
Exploit-DBVexDay Proof
ElasticSearch - Search Groovy Sandbox Bypass (Metasploit)
CVE-2015-1427CRITICALsob ataqueremotejava16 mar 2015
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISCO
abrir
Exploit-DBVexDay Proof
IPass Control Pipe - Remote Command Execution (Metasploit)
CVE-2015-0925remotewindows16 mar 2015
The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via
50RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin SEO by Yoast 1.7.3.3 - Blind SQL Injection
CVE-2015-2292webappsphp16 mar 2015
Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin be
23RISCO
abrir
Exploit-DB
WordPress Plugin WPML 3.1.9 - Multiple Vulnerabilities
CVE-2015-2315webappsphp16 mar 2015
Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject
23RISCO
abrir
Exploit-DB
WordPress Plugin WPML 3.1.9 - Multiple Vulnerabilities
CVE-2015-2791webappsphp16 mar 2015
The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts
28RISCO
abrir
Exploit-DB
Foxit Reader 7.0.6.1126 - Unquoted Service Path Privilege Escalation
CVE-2015-2789localwindows16 mar 2015
Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.
23RISCO
abrir
Exploit-DB
Intel Network Adapter Diagnostic Driver - IOCTL Handling
CVE-2015-2291HIGHsob ataqueransomwaredoswindows14 mar 2015
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISCO
abrir
Exploit-DB
WoltLab Community Gallery - Persistent Cross-Site Scripting
CVE-2015-2275webappsphp13 mar 2015
Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to i
23RISCO
abrir
Exploit-DB
ArcSight Logger - Arbitrary File Upload / Code Execution
CVE-2014-7884remotelinux13 mar 2015
Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated att
28RISCO
abrir
Exploit-DB
Citrix Netscaler NS10.5 - WAF Bypass (Via HTTP Header Pollution)
CVE-2015-2841webappsxml12 mar 2015
Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restriction
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - ByteArray UncompressViaZlibVariant Use-After-Free (Metasploit)
CVE-2015-0311HIGHsob ataqueremotewindows12 mar 2015
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Window
100RISCO
abrir
Exploit-DB
Ubuntu 15.04 (Development) - 'Upstart' Logrotation Privilege Escalation
CVE-2015-2285locallinux12 mar 2015
The logrotation script (/etc/cron.daily/upstart) in the Ubuntu Upstart package before 1.13.2-0ubuntu9, as used in Ubuntu
23RISCO
abrir
Exploit-DB
Foxit Products GIF Conversion - 'DataSubBlock' Memory Corruption
CVE-2015-2790doswindows11 mar 2015
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory c
28RISCO
abrir
Exploit-DB
Foxit Products GIF Conversion - 'LZWMinimumCodeSize' Memory Corruption
CVE-2015-2790doswindows11 mar 2015
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory c
28RISCO
abrir
Exploit-DBVexDay Proof
ElasticSearch - Remote Code Execution
CVE-2015-1427CRITICALsob ataqueremotelinux11 mar 2015
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Text Services Memory Corruption (MS15-020)
CVE-2015-0081doswindows11 mar 2015
Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
28RISCO
abrir
Exploit-DB
CS-Cart 4.2.4 - Cross-Site Request Forgery
CVE-2015-2701webappsphp11 mar 2015
Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of
23RISCO
abrir
Exploit-DB
CodoForum 2.5.1 - Arbitrary File Download
CVE-2014-9261webappsphp10 mar 2015
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which
23RISCO
abrir
Exploit-DB
GeniXCMS 0.0.1 - Multiple Vulnerabilities
CVE-2015-2680webappsphp10 mar 2015
Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack th
23RISCO
abrir
Exploit-DB
GeniXCMS 0.0.1 - Multiple Vulnerabilities
CVE-2015-2679webappsphp10 mar 2015
Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary S
23RISCO
abrir
Exploit-DB
GeniXCMS 0.0.1 - Multiple Vulnerabilities
CVE-2015-2678webappsphp10 mar 2015
Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject
23RISCO
abrir
anteriorpágina 199 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.