Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.557exploits catalogados
37.313CVEs com exploração pública
24.695testados em laboratório
24.478 exploits
Exploit-DBVexDay Proof
Yokogawa CENTUM CS 3000 - 'BKHOdeq.exe' Remote Buffer Overflow (Metasploit)
CVE-2014-0783remotewindows12 mar 2014
Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow
75RISCO
abrir
Exploit-DBVexDay Proof
FreePBX 2.11.0 - Remote Command Execution
CVE-2014-1903webappsphp12 mar 2014
admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12
50RISCO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox - 3D Acceleration Multiple Vulnerabilities
CVE-2014-0982dosmultiple12 mar 2014
20RISCO
abrir
Exploit-DBVexDay Proof
vTiger CRM 5.4.0/6.0 RC/6.0.0 GA - 'browse.php' Local File Inclusion
CVE-2014-1222webappsphp12 mar 2014
Directory traversal vulnerability in kcfinder/browse.php in Vtiger CRM before 6.0.0 Security patch 1 allows remote authe
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox - 3D Acceleration Multiple Vulnerabilities
CVE-2014-0983dosmultiple12 mar 2014
Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/s
38RISCO
abrir
Exploit-DBVexDay Proof
QNX 6.4.x/6.5.x ifwatchd - Local Privilege Escalation
CVE-2014-2533localqnx10 mar 2014
/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arb
38RISCO
abrir
Exploit-DBVexDay Proof
ownCloud 4.0.x/4.5.x - 'upload.php?Filename' Remote Code Execution
CVE-2014-2044webappsmultiple10 mar 2014
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote aut
28RISCO
abrir
Exploit-DBVexDay Proof
SolidWorks Workgroup PDM 2014 - 'pdmwService.exe' Arbitrary File Write (Metasploit)
CVE-2014-100015remotewindows10 mar 2014
Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write t
50RISCO
abrir
Exploit-DBVexDay Proof
Apple iOS 4.2.1 - 'facetime-audio://' Security Bypass
CVE-2013-6835remoteios10 mar 2014
TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime au
23RISCO
abrir
Exploit-DBVexDay Proof
HP Data Protector - Backup Client Service Remote Code Execution (Metasploit)
CVE-2013-2347remotewindows10 mar 2014
The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary
50RISCO
abrir
Exploit-DBVexDay Proof
QNX 6.4.x/6.5.x pppoectl - Information Disclosure
CVE-2014-2534localqnx10 mar 2014
/sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by rea
23RISCO
abrir
Exploit-DBVexDay Proof
GetGo Download Manager 4.9.0.1982 - HTTP Response Header Buffer Overflow Remote Code Execution
CVE-2014-2206remotewindows09 mar 2014
Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attac
50RISCO
abrir
Exploit-DBVexDay Proof
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0114remotemultiple06 mar 2014
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RISCO
abrir
Exploit-DBVexDay Proof
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0112remotemultiple06 mar 2014
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which all
60RISCO
abrir
Exploit-DBVexDay Proof
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0094remotemultiple06 mar 2014
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RISCO
abrir
Exploit-DB
OpenDocMan 1.2.7 - Multiple Vulnerabilities
CVE-2014-1945webappsphp05 mar 2014
SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQ
23RISCO
abrir
Exploit-DB
OpenDocMan 1.2.7 - Multiple Vulnerabilities
CVE-2014-2317webappsphp05 mar 2014
SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQ
23RISCO
abrir
Exploit-DBVexDay Proof
ALLPlayer - '.m3u' Local Buffer Overflow (Metasploit)
CVE-2013-7409localwindows05 mar 2014
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISCO
abrir
Exploit-DB
Ilch CMS 2.0 - Persistent Cross-Site Scripting
CVE-2014-1944webappsphp05 mar 2014
Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web scr
23RISCO
abrir
Exploit-DB
SpagoBI 4.0 - Arbitrary Cross-Site Scripting / Arbitrary File Upload
CVE-2013-6234webappsphp03 mar 2014
Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users
23RISCO
abrir
Exploit-DB
SpagoBI 4.0 - Persistent Cross-Site Scripting
CVE-2013-6232webappsphp03 mar 2014
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web
23RISCO
abrir
Exploit-DB
SpagoBI 4.0 - Persistent HTML Script Insertion
CVE-2013-6233webappsphp03 mar 2014
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web
23RISCO
abrir
Exploit-DBVexDay Proof
couponPHP CMS 1.0 - Multiple Persistent Cross-Site Scripting / SQL Injections
CVE-2014-10034webappsphp03 mar 2014
Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execut
23RISCO
abrir
Exploit-DBVexDay Proof
ALLPlayer 5.8.1 - '.m3u' Local Buffer Overflow (SEH)
CVE-2013-7409localwindows03 mar 2014
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISCO
abrir
Exploit-DBVexDay Proof
couponPHP CMS 1.0 - Multiple Persistent Cross-Site Scripting / SQL Injections
CVE-2014-10035webappsphp03 mar 2014
Multiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrat
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle Demantra 12.2.1 - Database Credentials Disclosure
CVE-2013-5795webappswindows01 mar 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RISCO
abrir
Exploit-DBVexDay Proof
Oracle Demantra 12.2.1 - Persistent Cross-Site Scripting
CVE-2014-0379webappswindows01 mar 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle Demantra 12.2.1 - Arbitrary File Disclosure
CVE-2013-5877webappswindows01 mar 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RISCO
abrir
Exploit-DBVexDay Proof
Oracle Demantra 12.2.1 - SQL Injection
CVE-2014-0372webappswindows01 mar 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
23RISCO
abrir
Exploit-DBVexDay Proof
GE Proficy CIMPLICITY - 'gefebt.exe' Remote Code Execution (Metasploit)
CVE-2014-0750remotewindows28 fev 2014
GE Proficy HMI/SCADA Path Traversal
78RISCO
abrir
anteriorpágina 234 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.