Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DB
kitForm CRM Extension 0.43 - 'sorter.ph?sorter_value' SQL Injection
CVE-2014-3757webappsphp22 abr 2014
SQL injection vulnerability in sorter.php in the phpManufaktur kitForm extension 0.43 and earlier for the KeepInTouch (K
23RISCO
abrir
Exploit-DB
Sixnet Sixview 2.4.1 - Web Console Directory Traversal
CVE-2014-2976webappshardware22 abr 2014
Directory traversal vulnerability in Sixnet SixView Manager 2.4.1 allows remote attackers to read arbitrary files via a
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX - Local Security Bypass
CVE-2014-1322localosx22 abr 2014
The kernel in Apple OS X through 10.9.2 places a kernel pointer into an XNU object data structure accessible from user s
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - Regular Expression Heap Overflow (Metasploit)
CVE-2013-0634remotewindows21 abr 2014
Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x
60RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - Regular Expression Heap Overflow (Metasploit)
CVE-2013-0633remotewindows21 abr 2014
Buffer overflow in Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10
28RISCO
abrir
Exploit-DB
Teracom Modem T2-B-Gawv1.4U10Y-BI - Cross-Site Request Forgery
CVE-2014-10019webappshardware20 abr 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in webconfig/wlan/country.html/country in the Teracom T2-B-Ga
23RISCO
abrir
Exploit-DB
Linux Kernel - 'group_info' refcounter Overflow Memory Corruption
CVE-2014-2851doslinux18 abr 2014
Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users
23RISCO
abrir
Exploit-DB
NRPE 2.15 - Remote Command Execution
CVE-2014-2913remotemultiple18 abr 2014
Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote atta
28RISCO
abrir
Exploit-DBVexDay Proof
SAP Router - Timing Attack Password Disclosure
CVE-2014-0984remotehardware17 abr 2014
The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation
23RISCO
abrir
Exploit-DBVexDay Proof
Jzip - Buffer Overflow (PoC) (SEH Unicode)
CVE-2010-5300doswindows16 abr 2014
Stack-based buffer overflow in Jzip 1.3 through 2.0.0.132900 allows remote attackers to cause a denial of service (crash
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CMarkup Use-After-Free (MS14-012) (Metasploit)
CVE-2014-0322HIGHsob ataqueremotewindows16 abr 2014
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code v
100RISCO
abrir
Exploit-DBVexDay Proof
Adobe Reader for Android 11.1.3 - Arbitrary JavaScript Execution
CVE-2014-0514localandroid15 abr 2014
The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows r
60RISCO
abrir
Exploit-DBVexDay Proof
lxml - 'clean_html' Security Bypass
CVE-2014-3146MEDIUMremotelinux15 abr 2014
Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct
33RISCO
abrir
Exploit-DB
Unitrends Enterprise Backup 7.3.0 - Root Remote Code Execution (Metasploit)
CVE-2014-3139remoteunix15 abr 2014
recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by s
23RISCO
abrir
Exploit-DB
Unitrends Enterprise Backup 7.3.0 - Root Remote Code Execution (Metasploit)
CVE-2014-3008remoteunix15 abr 2014
Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacte
23RISCO
abrir
Exploit-DB
Xerox DocuShare - SQL Injection
CVE-2014-3138webappshardware15 abr 2014
SQL injection vulnerability in Xerox DocuShare before 6.53 Patch 6 Hotfix 2, 6.6.1 Update 1 before Hotfix 24, and 6.6.1
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 10 - CMarkup Use-After-Free (MS14-012)
CVE-2014-0322HIGHsob ataqueremotewindows14 abr 2014
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code v
100RISCO
abrir
Exploit-DBVexDay Proof
Xangati - '/servlet/Installer?file' Directory Traversal
CVE-2014-0358webappsjsp14 abr 2014
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read ar
23RISCO
abrir
Exploit-DBVexDay Proof
Xangati XSR / XNR - 'gui_input_test.pl' Remote Command Execution
CVE-2014-0358webappscgi14 abr 2014
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read ar
23RISCO
abrir
Exploit-DBVexDay Proof
Xangati - '/servlet/MGConfigData' Multiple Directory Traversals
CVE-2014-0358webappsjsp14 abr 2014
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read ar
23RISCO
abrir
Exploit-DB
WordPress Plugin Quick Page/Post Redirect 5.0.3 - Multiple Vulnerabilities
CVE-2014-2598webappsphp14 abr 2014
Cross-site request forgery (CSRF) vulnerability in the Quick Page/Post Redirect plugin before 5.0.5 for WordPress allows
23RISCO
abrir
Exploit-DB
WordPress Plugin Twitget 3.3.1 - Multiple Vulnerabilities
CVE-2014-2995webappsphp14 abr 2014
Multiple cross-site scripting (XSS) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allo
23RISCO
abrir
Exploit-DB
WordPress Plugin Twitget 3.3.1 - Multiple Vulnerabilities
CVE-2014-2559webappsphp14 abr 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPre
23RISCO
abrir
Exploit-DB
CubeCart 5.2.8 - Session Fixation
CVE-2014-2341webappsphp13 abr 2014
Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID
23RISCO
abrir
Exploit-DB
Sendy 1.1.9.1 - SQL Injection
CVE-2014-100011webappsphp11 abr 2014
SQL injection vulnerability in /send-to in Sendy 1.1.9.1 allows remote attackers to execute arbitrary SQL commands via t
23RISCO
abrir
Exploit-DBVexDay Proof
Sophos Web Protection Appliance Interface - (Authenticated) Arbitrary Command Execution (Metasploit)
CVE-2014-2850remoteunix10 abr 2014
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrator
50RISCO
abrir
Exploit-DBVexDay Proof
Sophos Web Protection Appliance Interface - (Authenticated) Arbitrary Command Execution (Metasploit)
CVE-2014-2849remoteunix10 abr 2014
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Word - RTF Object Confusion (MS14-017) (Metasploit)
CVE-2014-1761HIGHsob ataquelocalwindows10 abr 2014
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Offi
100RISCO
abrir
Exploit-DBVexDay Proof
Vtiger - 'Install' Remote Command Execution (Metasploit)
CVE-2014-2268remotephp10 abr 2014
views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which all
50RISCO
abrir
Exploit-DB
XCloner Standalone 3.5 - Cross-Site Request Forgery
CVE-2014-2579webappsphp10 abr 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers
23RISCO
abrir
anteriorpágina 230 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.