Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DB
PhpOnlineChat 3.0 - Cross-Site Scripting
CVE-2014-100017webappsphp07 set 2014
Cross-site scripting (XSS) vulnerability in canned_opr.php in PhpOnlineChat 3.0 allows remote attackers to inject arbitr
23RISCO
abrir
Exploit-DBVexDay Proof
BulletProof FTP Client 2010 - Buffer Overflow (SEH)
CVE-2014-2973doswindows05 set 2014
35RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox 9.0.1 / Thunderbird 3.1.20 - Information Disclosure
CVE-2014-1564remotemultiple02 set 2014
Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize m
23RISCO
abrir
Exploit-DB
Syslog LogAnalyzer 3.6.5 - Persistent Cross-Site Scripting
CVE-2014-6070webappsmultiple02 set 2014
Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject
23RISCO
abrir
Exploit-DB
WordPress Plugin Huge-IT Image Gallery 1.0.1 - (Authenticated) SQL Injection
CVE-2014-7153webappsphp02 set 2014
SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.
23RISCO
abrir
Exploit-DB
ManageEngine Desktop Central - Arbitrary File Upload / Remote Code Execution
CVE-2014-5007webappsjsp01 set 2014
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop
35RISCO
abrir
Exploit-DB
ManageEngine EventLog Analyzer - Multiple Vulnerabilities (1)
CVE-2014-6037webappsjsp01 set 2014
Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8
60RISCO
abrir
Exploit-DBVexDay Proof
Mulitple WordPress Themes - 'admin-ajax.php?img' Arbitrary File Download
CVE-2014-9734webappsphp01 set 2014
Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote att
28RISCO
abrir
Exploit-DB
ManageEngine EventLog Analyzer - Multiple Vulnerabilities (1)
CVE-2014-6043webappsjsp01 set 2014
ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database
28RISCO
abrir
Exploit-DB
WordPress Plugin Slideshow Gallery 1.4.6 - Arbitrary File Upload
CVE-2014-5460webappsphp01 set 2014
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remot
60RISCO
abrir
Exploit-DB
ManageEngine Desktop Central - Arbitrary File Upload / Remote Code Execution
CVE-2014-5006webappsjsp01 set 2014
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers
28RISCO
abrir
Exploit-DB
ManageEngine Desktop Central - Arbitrary File Upload / Remote Code Execution
CVE-2014-5005webappsjsp01 set 2014
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers
60RISCO
abrir
Exploit-DB
ManageEngine Desktop Central - Arbitrary File Upload / Remote Code Execution
CVE-2013-7390webappsjsp01 set 2014
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before buil
60RISCO
abrir
Exploit-DBVexDay Proof
Wing FTP Server - (Authenticated) Command Execution (Metasploit)
CVE-2015-4107remotewindows01 set 2014
20RISCO
abrir
Exploit-DBVexDay Proof
Mulitple WordPress Themes - 'admin-ajax.php?img' Arbitrary File Download
CVE-2015-1579webappsphp01 set 2014
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RISCO
abrir
Exploit-DB
F5 Big-IP - rsync Access
CVE-2014-2927remotehardware29 ago 2014
The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before
23RISCO
abrir
Exploit-DB
NRPE 2.15 - Remote Code Execution
CVE-2014-2913remotemultiple29 ago 2014
Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote atta
28RISCO
abrir
Exploit-DB
XRms - Blind SQL Injection / Command Execution
CVE-2014-5520webappsphp28 ago 2014
SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox - WebIDL Privileged JavaScript Injection (Metasploit)
CVE-2014-1510remotemultiple28 ago 2014
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and Se
60RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox - WebIDL Privileged JavaScript Injection (Metasploit)
CVE-2014-1511remotemultiple28 ago 2014
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remo
60RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin ShortCode 0.2.3 - Local File Inclusion
CVE-2014-5465webappsphp28 ago 2014
Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress
28RISCO
abrir
Exploit-DB
Plogger 1.0-RC1 - (Authenticated) Arbitrary File Upload
CVE-2014-2223webappsphp28 ago 2014
Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authen
28RISCO
abrir
Exploit-DB
Microsoft Internet Explorer - Memory Corruption (PoC) (MS14-029)
CVE-2014-1815doswindows28 ago 2014
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
28RISCO
abrir
Exploit-DB
ManageEngine DeviceExpert 5.9 - User Credential Disclosure
CVE-2014-5377webappsmultiple28 ago 2014
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user acc
50RISCO
abrir
Exploit-DB
PhpWiki - Remote Command Execution
CVE-2014-5519webappsphp28 ago 2014
The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a dev
50RISCO
abrir
Exploit-DB
XRms - Blind SQL Injection / Command Execution
CVE-2014-5521webappsphp28 ago 2014
plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary co
23RISCO
abrir
Exploit-DBVexDay Proof
glibc - NUL Byte gconv_translit_find Off-by-One
CVE-2014-5119locallinux27 ago 2014
Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-depe
28RISCO
abrir
Exploit-DB
ntopng 1.2.0 - Cross-Site Scripting Injection
CVE-2014-5464webappsmultiple26 ago 2014
Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 al
23RISCO
abrir
Exploit-DBVexDay Proof
VTLS Virtua InfoStation.cgi - SQL Injection
CVE-2014-2081webappscgi26 ago 2014
Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua bef
23RISCO
abrir
Exploit-DBVexDay Proof
Granding MA300 - Weak Pin Encryption Brute Force
CVE-2014-5381remotemultiple26 ago 2014
Grand MA 300 allows a brute-force attack on the PIN.
23RISCO
abrir
anteriorpágina 218 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.