Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
Microsoft Windows < 8.1 (x86/x64) - User Profile Service Privilege Escalation (MS15-003)
CVE-2015-0004localwindows18 jan 2015
The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2
23RISCO
abrir
Exploit-DB
Lorex LH300 Series - ActiveX Buffer Overflow (PoC)
CVE-2014-1201doshardware18 jan 2015
Buffer overflow in the INetViewX ActiveX control in the Lorex Edge LH310 and Edge+ LH320 series with firmware 7-35-28-1B
28RISCO
abrir
Exploit-DB
Sim Editor 6.6 - Local Stack Buffer Overflow
CVE-2015-1171localwindows16 jan 2015
Stack-based buffer overflow in GSM SIM Utility (aka SIM Card Editor) 6.6 allows remote attackers to execute arbitrary co
50RISCO
abrir
Exploit-DB
WordPress Plugin Pie Register 2.0.13 - Privilege Escalation
CVE-2014-8802webappsphp16 jan 2015
The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-regist
23RISCO
abrir
Exploit-DB
ManageEngine Desktop Central - Create Administrator
CVE-2014-7862webappsmultiple15 jan 2015
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote at
60RISCO
abrir
Exploit-DB
Ansible Tower 2.0.2 - Multiple Vulnerabilities
CVE-2015-1481webappsmultiple14 jan 2015
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a s
23RISCO
abrir
Exploit-DB
Ansible Tower 2.0.2 - Multiple Vulnerabilities
CVE-2015-1482webappsmultiple14 jan 2015
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive inform
23RISCO
abrir
Exploit-DB
Ansible Tower 2.0.2 - Multiple Vulnerabilities
CVE-2015-1368webappsmultiple14 jan 2015
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attacker
23RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin WP Symposium 14.11 - Arbitrary File Upload (Metasploit)
CVE-2014-10021remotephp13 jan 2015
Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote
50RISCO
abrir
Exploit-DB
Dell iDRAC IPMI 1.5 - Insufficient Session ID Randomness
CVE-2014-8272webappshardware13 jan 2015
The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57
28RISCO
abrir
Exploit-DB
Gecko CMS 2.3 - Multiple Vulnerabilities
CVE-2015-1422webappsphp13 jan 2015
Multiple cross-site scripting (XSS) vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote attackers to inject arbitrary
23RISCO
abrir
Exploit-DB
Gecko CMS 2.3 - Multiple Vulnerabilities
CVE-2015-1423webappsphp13 jan 2015
Multiple SQL injection vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote administrators to execute arbitrary SQL com
23RISCO
abrir
Exploit-DBVexDay Proof
Lexmark MarkVision Enterprise - Arbitrary File Upload (Metasploit)
CVE-2014-8741remotejava13 jan 2015
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allo
60RISCO
abrir
Exploit-DBVexDay Proof
Oracle MySQL (Windows) - FILE Privilege Abuse (Metasploit)
CVE-2012-5613remotewindows13 jan 2015
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RISCO
abrir
Exploit-DB
Gecko CMS 2.3 - Multiple Vulnerabilities
CVE-2015-1424webappsphp13 jan 2015
Cross-site request forgery (CSRF) vulnerability in Gecko CMS 2.2 and 2.3 allows remote attackers to hijack the authentic
23RISCO
abrir
Exploit-DB
D-Link DSL-2730B Modem - Cross-Site Scripting Injection Stored Wlsecrefresh.wl & Wlsecurity.wl
CVE-2015-1028webappshardware11 jan 2015
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remo
23RISCO
abrir
Exploit-DB
D-Link DSL-2730B Modem - Cross-Site Scripting Injection Stored DnsProxy.cmd
CVE-2015-1028webappshardware11 jan 2015
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remo
23RISCO
abrir
Exploit-DB
D-Link DSL-2730B Modem - 'Lancfg2get.cgi Persistent Cross-Site Scripting
CVE-2015-1028webappshardware11 jan 2015
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remo
23RISCO
abrir
Exploit-DB
Apple Mac OSX 10.9.x - sysmond XPC Privilege Escalation
CVE-2014-8835localosx10 jan 2015
The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes ke
23RISCO
abrir
Exploit-DBVexDay Proof
Pandora FMS 3.1 - Authentication Bypass / Arbitrary File Upload (Metasploit)
CVE-2010-4279remotephp08 jan 2015
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which al
50RISCO
abrir
Exploit-DB
WordPress Plugin Shopping Cart 3.0.4 - Unrestricted Arbitrary File Upload
CVE-2014-9308webappsphp08 jan 2015
Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka Wor
50RISCO
abrir
Exploit-DB
Pirelli ADSL2/2+ Wireless Router P.DGA4001N - Information Disclosure
CVE-2015-0554webappshardware07 jan 2015
The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6 does not properly rest
50RISCO
abrir
Exploit-DB
Sefrengo CMS 1.6.0 - SQL Injection
CVE-2015-0919webappsphp07 jan 2015
Multiple SQL injection vulnerabilities in the administrative backend in Sefrengo before 1.6.1 allow remote administrator
23RISCO
abrir
Exploit-DB
Microweber CMS 0.95 - SQL Injection
CVE-2014-9464webappsphp07 jan 2015
SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute ar
23RISCO
abrir
Exploit-DB
Nexus 5 Android 5.0 - Local Privilege Escalation
CVE-2014-4322localandroid06 jan 2015
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RISCO
abrir
Exploit-DBVexDay Proof
BulletProof FTP Client - BPS Buffer Overflow (Metasploit)
CVE-2014-2973localwindows06 jan 2015
35RISCO
abrir
Exploit-DB
AdaptCMS 3.0.3 - Multiple Vulnerabilities
CVE-2015-1060webappsphp06 jan 2015
Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect
23RISCO
abrir
Exploit-DB
AdaptCMS 3.0.3 - Multiple Vulnerabilities
CVE-2015-1059webappsphp06 jan 2015
Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute
23RISCO
abrir
Exploit-DB
AdaptCMS 3.0.3 - Multiple Vulnerabilities
CVE-2015-1058webappsphp06 jan 2015
Multiple cross-site scripting (XSS) vulnerabilities in AdaptCMS 3.0.3 allow remote attackers to inject arbitrary web scr
23RISCO
abrir
Exploit-DB
SkinCrafter3 vs2005 3.8.1.0 - Multiple ActiveX Buffer Overflows
CVE-2012-2271remotewindows05 jan 2015
Buffer overflow in the InitLicenKeys function in a certain ActiveX control in SkinCrafter3_vs2005.dll in SkinCrafter 3.0
23RISCO
abrir
anteriorpágina 204 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.