Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DB
SolidWorks Workgroup PDM 2014 SP2 Opcode 2001 - Denial of Service
CVE-2014-100014doswindows19 fev 2014
Multiple stack-based buffer overflows in pdmwService.exe in SolidWorks Workgroup PDM 2014 SP2 allow remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
Dassault Systemes Catia - Remote Stack Buffer Overflow
CVE-2014-2072remotemultiple19 fev 2014
Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks
23RISCO
abrir
Exploit-DB
Open Web Analytics 1.5.4 - 'owa_email_address' SQL Injection
CVE-2014-1206webappsphp18 fev 2014
SQL injection vulnerability in the password reset page in Open Web Analytics (OWA) before 1.5.5 allows remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
Ultra Mini HTTPd 1.21 - 'POST' Remote Stack Buffer Overflow (1)
CVE-2013-5019remotewindows18 fev 2014
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RISCO
abrir
Exploit-DBVexDay Proof
Oracle Forms and Reports - Remote Code Execution (Metasploit)
CVE-2012-3152CRITICALsob ataqueremotewindows18 fev 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
100RISCO
abrir
Exploit-DBVexDay Proof
i-doit Pro - 'objID' SQL Injection
CVE-2014-1597webappsphp17 fev 2014
SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remot
23RISCO
abrir
Exploit-DB
HP Data Protector - 'EXEC_BAR' Remote Command Execution
CVE-2013-2347remotewindows16 fev 2014
The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary
50RISCO
abrir
Exploit-DB
ImageMagick 6.8.8-4 - Local Buffer Overflow (SEH)
CVE-2014-1947localwindows16 fev 2014
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote
23RISCO
abrir
Exploit-DB
ImageMagick 6.8.8-4 - Local Buffer Overflow (SEH)
CVE-2014-2030localwindows16 fev 2014
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remot
28RISCO
abrir
Exploit-DBVexDay Proof
Eudora Qualcomm WorldMail 9.0.333.0 - IMAPd Service UID Buffer Overflow
CVE-2014-10031remotewindows16 fev 2014
Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary
23RISCO
abrir
Exploit-DB
CA 2E Web Option 8.1.2 - Authentication Bypass
CVE-2014-1219webappsmultiple13 fev 2014
CA 2E Web Option r8.1.2 accepts a predictable substring of a W2E_SSNID session token in place of the entire token, which
23RISCO
abrir
Exploit-DBVexDay Proof
Easy CD-DA Recorder - '.pls' Local Buffer Overflow (Metasploit)
CVE-2010-2343localwindows13 fev 2014
Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbi
50RISCO
abrir
Exploit-DBVexDay Proof
Apache Commons FileUpload and Apache Tomcat - Denial of Service
CVE-2014-0050dosmultiple12 fev 2014
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products,
60RISCO
abrir
Exploit-DBVexDay Proof
KingScada - kxClientDownload.ocx ActiveX Remote Code Execution (Metasploit)
CVE-2013-2827remotewindows11 fev 2014
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before
50RISCO
abrir
Exploit-DB
WordPress Plugin BuddyPress 1.9.1 - Privilege Escalation
CVE-2014-1889webappsphp11 fev 2014
The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain
28RISCO
abrir
Exploit-DB
Linux Kernel < 3.4.5 (Android 4.2.2/4.4 ARM) - Local Privilege Escalation
CVE-2013-6282HIGHsob ataquelocalarm11 fev 2014
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - TrackPopupMenuEx Win32k NULL Page (MS13-081) (Metasploit)
CVE-2013-3881localwindows11 fev 2014
win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to ga
43RISCO
abrir
Exploit-DB
Titan FTP Server 10.32 Build 1816 - Directory Traversal
CVE-2014-1842webappswindows11 fev 2014
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RISCO
abrir
Exploit-DB
Titan FTP Server 10.32 Build 1816 - Directory Traversal
CVE-2014-1843webappswindows11 fev 2014
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RISCO
abrir
Exploit-DB
Titan FTP Server 10.32 Build 1816 - Directory Traversal
CVE-2014-1841webappswindows11 fev 2014
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RISCO
abrir
Exploit-DBVexDay Proof
Tableau Server < 8.0.7 / < 8.1.2 - Blind SQL Injection
CVE-2014-1204webappswindows11 fev 2014
SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated user
23RISCO
abrir
Exploit-DB
ZTE ZXV10 W300 Router - Hard-Coded Credentials
CVE-2014-0329webappshardware09 fev 2014
The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account
23RISCO
abrir
Exploit-DBVexDay Proof
Publish-It 3.6d - '.pui' Local Buffer Overflow (SEH)
CVE-2014-0980localwindows08 fev 2014
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RISCO
abrir
Exploit-DB
CTERA 3.2.29.0/3.2.42.0 - Persistent Cross-Site Scripting
CVE-2013-2639webappsphp07 fev 2014
Cross-site scripting (XSS) vulnerability in CTERA Cloud Storage OS before 3.2.29.0, 3.2.42.0, and earlier allows remote
23RISCO
abrir
Exploit-DBVexDay Proof
osCommerce 2.3.3.4 - 'geo_zones.php?zID' SQL Injection
CVE-2014-10033webappsphp07 fev 2014
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3
23RISCO
abrir
Exploit-DB
doorGets CMS 5.2 - SQL Injection
CVE-2014-1459webappsphp07 fev 2014
SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administra
23RISCO
abrir
Exploit-DBVexDay Proof
Android Browser and WebView addJavascriptInterface - Code Execution (Metasploit)
CVE-2013-4710remotehardware07 fev 2014
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly imp
50RISCO
abrir
Exploit-DB
AuraCMS 2.3 - Multiple Vulnerabilities
CVE-2014-1401webappsphp07 fev 2014
Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Publish-It 3.6d - Buffer Overflow
CVE-2014-0980doswindows06 fev 2014
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RISCO
abrir
Exploit-DB
D-Link DIR-100 - Multiple Vulnerabilities
CVE-2013-7052webappshardware05 fev 2014
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
28RISCO
abrir
anteriorpágina 235 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.