Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DB
Microsoft Windows XP SP3 - 'BthPan.sys' Arbitrary Write Privilege Escalation
CVE-2014-4971localwindows21 jul 2014
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RISCO
abrir
Exploit-DBVexDay Proof
IBM GCM16/32 1.20.0.22575 - Multiple Vulnerabilities
CVE-2014-3085remotephp21 jul 2014
systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote auth
23RISCO
abrir
Exploit-DBVexDay Proof
IBM GCM16/32 1.20.0.22575 - Multiple Vulnerabilities
CVE-2014-3080remotephp21 jul 2014
Multiple cross-site scripting (XSS) vulnerabilities on IBM GCM16 and GCM32 Global Console Manager switches with firmware
23RISCO
abrir
Exploit-DBVexDay Proof
IBM GCM16/32 1.20.0.22575 - Multiple Vulnerabilities
CVE-2014-3081remotephp21 jul 2014
prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote aut
23RISCO
abrir
Exploit-DB
Linux Kernel < 3.2.0-23 (Ubuntu 12.04 x64) - 'ptrace/sysret' Local Privilege Escalation
CVE-2014-4699locallinux_x86-6421 jul 2014
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved
23RISCO
abrir
Exploit-DB
Microsoft Windows XP SP3 - 'MQAC.sys' Arbitrary Write Privilege Escalation
CVE-2014-4971localwindows19 jul 2014
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RISCO
abrir
Exploit-DB
ACME micro_httpd - Denial of Service
CVE-2014-4927doslinux18 jul 2014
Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 router
28RISCO
abrir
Exploit-DB
WordPress Plugin Gallery Objects 0.4 - SQL Injection
CVE-2014-5201webappsphp18 jul 2014
SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Fonality trixbox - 'index.php' Directory Traversal
CVE-2014-5111webappsphp17 jul 2014
Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a ..
43RISCO
abrir
Exploit-DBVexDay Proof
Fonality trixbox - 'index.php' Remote Code Execution
CVE-2014-5112webappsphp17 jul 2014
maint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacha
23RISCO
abrir
Exploit-DBVexDay Proof
OL-Commerce - '/OL-Commerce/affiliate_signup.php?a_country' SQL Injection
CVE-2014-5104webappsphp17 jul 2014
Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
Exploit-DBVexDay Proof
Fonality trixbox - 'asterisk_info.php' Directory Traversal
CVE-2014-5111webappsphp17 jul 2014
Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a ..
43RISCO
abrir
Exploit-DBVexDay Proof
OL-Commerce - '/OL-Commerce/create_account.php?country' SQL Injection
CVE-2014-5104webappsphp17 jul 2014
Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
Exploit-DBVexDay Proof
Fonality trixbox - 'endpointcfg.php' Directory Traversal
CVE-2014-5111webappsphp17 jul 2014
Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a ..
43RISCO
abrir
Exploit-DBVexDay Proof
Fonality trixbox - 'endpoint_generic.php' SQL Injection
CVE-2014-5109webappsphp17 jul 2014
SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attacker
23RISCO
abrir
Exploit-DBVexDay Proof
Fonality trixbox - 'repo.php' Directory Traversal
CVE-2014-5111webappsphp17 jul 2014
Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a ..
43RISCO
abrir
Exploit-DBVexDay Proof
OL-Commerce - '/OL-Commerce/admin/create_account.php?entry_country_id' SQL Injection
CVE-2014-5104webappsphp17 jul 2014
Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
Exploit-DBVexDay Proof
Omeka 2.2 - Cross-Site Request Forgery / Persistent Cross-Site Scripting
CVE-2014-5100webappsphp17 jul 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the au
23RISCO
abrir
Exploit-DBVexDay Proof
OL-Commerce - '/OL-Commerce/affiliate_show_banner.php?affiliate_banner_id' SQL Injection
CVE-2014-5104webappsphp17 jul 2014
Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
Exploit-DB
BitDefender GravityZone 5.1.5.386 - Multiple Vulnerabilities
CVE-2014-5350webappslinux16 jul 2014
Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read
35RISCO
abrir
Exploit-DB
Boat Browser 8.0/8.0.1 - Remote Code Execution
CVE-2014-4968remoteandroid16 jul 2014
The WebView class and use of the WebView.addJavascriptInterface method in the Boat Browser application 8.0 and 8.0.1 for
23RISCO
abrir
Exploit-DBVexDay Proof
Alfresco - '/cmisbrowser?url' Server-Side Request Forgery
CVE-2014-9302remotemultiple16 jul 2014
Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Servi
23RISCO
abrir
Exploit-DBVexDay Proof
Alfresco - '/proxy?endpoint' Server-Side Request Forgery
CVE-2014-9301remotemultiple16 jul 2014
Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows
23RISCO
abrir
Exploit-DB
Node Browserify 4.2.0 - Remote Code Execution
CVE-2014-7192dosmultiple16 jul 2014
Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rat
28RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Youtube Gallery 4.1.7 - SQL Injection
CVE-2014-4960webappsphp16 jul 2014
Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x throu
23RISCO
abrir
Exploit-DB
Shopizer 1.1.5 - Multiple Vulnerabilities
CVE-2014-4964webappsphp14 jul 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to hijac
23RISCO
abrir
Exploit-DB
Shopizer 1.1.5 - Multiple Vulnerabilities
CVE-2014-4962webappsphp14 jul 2014
Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number
23RISCO
abrir
Exploit-DBVexDay Proof
HP Data Protector Manager 8.10 - Remote Command Execution
CVE-2014-2623remotewindows14 jul 2014
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown
60RISCO
abrir
Exploit-DB
Shopizer 1.1.5 - Multiple Vulnerabilities
CVE-2014-4963webappsphp14 jul 2014
Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.cu
23RISCO
abrir
Exploit-DB
Shopizer 1.1.5 - Multiple Vulnerabilities
CVE-2014-4965webappsphp14 jul 2014
Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to inject arbit
23RISCO
abrir
anteriorpágina 221 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.