Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
Sophos Web Protection Appliance Interface - (Authenticated) Arbitrary Command Execution (Metasploit)
CVE-2014-2850remoteunix10 abr 2014
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrator
50RISCO
abrir
Exploit-DBVexDay Proof
Sophos Web Protection Appliance Interface - (Authenticated) Arbitrary Command Execution (Metasploit)
CVE-2014-2849remoteunix10 abr 2014
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users
50RISCO
abrir
Exploit-DBVexDay Proof
Vtiger - 'Install' Remote Command Execution (Metasploit)
CVE-2014-2268remotephp10 abr 2014
views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which all
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Word - RTF Object Confusion (MS14-017) (Metasploit)
CVE-2014-1761HIGHsob ataquelocalwindows10 abr 2014
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Offi
100RISCO
abrir
Exploit-DBVexDay Proof
OpenSSL 1.0.1f TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure (Multiple SSL/TLS Versions)
CVE-2014-0346remotemultiple09 abr 2014
20RISCO
abrir
Exploit-DBVexDay Proof
OpenSSL 1.0.1f TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure (Multiple SSL/TLS Versions)
CVE-2014-0160HIGHsob ataqueremotemultiple09 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure
CVE-2014-0160HIGHsob ataqueremotemultiple08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
Exploit-DB
Apple Mac OSX 10.9 - Hard Link Memory Corruption
CVE-2013-6799dososx08 abr 2014
Apple Mac OS X 10.9 allows local users to cause a denial of service (memory corruption or panic) by creating a hard link
23RISCO
abrir
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure
CVE-2014-0346remotemultiple08 abr 2014
20RISCO
abrir
Exploit-DBVexDay Proof
JIRA Issues Collector - Directory Traversal (Metasploit)
CVE-2014-2314remotewindows07 abr 2014
Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers t
43RISCO
abrir
Exploit-DBVexDay Proof
PHPFox - Access Control Security Bypass
CVE-2013-7196webappsphp05 abr 2014
static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restric
23RISCO
abrir
Exploit-DB
WordPress Plugin XCloner 3.1.0 - Cross-Site Request Forgery
CVE-2014-2340webappsphp04 abr 2014
Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
ibstat $PATH - Local Privilege Escalation (Metasploit)
CVE-2013-4011locallinux04 abr 2014
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, a
38RISCO
abrir
Exploit-DB
A10 Networks ACOS 2.7.0-P2 (Build 53) - Buffer Overflow (PoC)
CVE-2014-3976doshardware04 abr 2014
Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allow
28RISCO
abrir
Exploit-DB
Oracle Identity Manager 11g R2 SP1 (11.1.2.1.0) - Unvalidated Redirects
CVE-2014-2880webappsphp03 abr 2014
Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.
23RISCO
abrir
Exploit-DB
CIS Manager CMS - SQL Injection
CVE-2014-2847webappsasp02 abr 2014
SQL injection vulnerability in default.asp in CIS Manager CMS allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Exploit-DB
PhonerLite 2.14 SIP Soft Phone - SIP Digest Disclosure
CVE-2014-2560remotewindows01 abr 2014
The PhonerLite phone before 2.15 provides hashed credentials in a response to an invalid authentication challenge, which
23RISCO
abrir
Exploit-DB
WordPress Plugin Ajax Pagination 1.1 - Local File Inclusion
CVE-2014-2674webappsphp31 mar 2014
Directory traversal vulnerability in the Ajax Pagination (twitter Style) plugin 1.1 for WordPress allows remote attacker
28RISCO
abrir
Exploit-DBVexDay Proof
SePortal 2.5 - SQL Injection / Remote Code Execution (Metasploit)
CVE-2008-5191remotephp31 mar 2014
Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the
43RISCO
abrir
Exploit-DB
EMC Cloud Tiering Appliance 10.0 - XML External Entity Arbitrary File Read (Metasploit)
CVE-2014-0644webappsmultiple31 mar 2014
EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login reques
50RISCO
abrir
Exploit-DBVexDay Proof
Fitnesse Wiki - Remote Command Execution (Metasploit)
CVE-2014-1216remotewindows28 mar 2014
FitNesse Wiki 20131110, 20140201, and earlier allows remote attackers to execute arbitrary commands by defining a COMMAN
23RISCO
abrir
Exploit-DB
Dell SonicWALL EMail Security Appliance Application 7.4.5 - Multiple Vulnerabilities
CVE-2014-2879webappsmultiple27 mar 2014
Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote auth
23RISCO
abrir
Exploit-DBVexDay Proof
InterWorx Control Panel 5.0.13 build 574 - 'xhr.php?i' SQL Injection
CVE-2014-2531webappsphp26 mar 2014
SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx
23RISCO
abrir
Exploit-DBVexDay Proof
Katello (RedHat Satellite) - users/update_roles Missing Authorisation (Metasploit)
CVE-2013-2143remotelinux26 mar 2014
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update
50RISCO
abrir
Exploit-DB
IBM Tealeaf CX 8.8 - Remote OS Command Injection
CVE-2013-6719webappsphp26 mar 2014
delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2
28RISCO
abrir
Exploit-DBVexDay Proof
Apache CouchDB 1.5.0 - 'uuids' Denial of Service
CVE-2014-2668dosmultiple26 mar 2014
Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via t
28RISCO
abrir
Exploit-DB
Allied Telesis AT-RG634A ADSL Broadband Router - Web Shell
CVE-2014-1982webappshardware26 mar 2014
The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firm
23RISCO
abrir
Exploit-DB
IBM Tealeaf CX 8.8 - Remote OS Command Injection
CVE-2013-6720webappsphp26 mar 2014
Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX
28RISCO
abrir
Exploit-DBVexDay Proof
FreePBX - 'config.php' Remote Code Execution (Metasploit)
CVE-2014-1903remoteunix25 mar 2014
admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12
50RISCO
abrir
Exploit-DBVexDay Proof
Light Audio Player 1.0.14 - Memory Corruption (PoC)
CVE-2014-2671doswindows24 mar 2014
Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corrupt
35RISCO
abrir
anteriorpágina 231 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.