Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DB
D-Link DIR-100 - Multiple Vulnerabilities
CVE-2013-7053webappshardware05 fev 2014
D-Link DIR-100 4.03B07: cli.cgi CSRF
23RISCO
abrir
Exploit-DB
VideoLAN VLC Media Player 2.1.2 - '.asf' Crash (PoC)
CVE-2014-1684dosmultiple05 fev 2014
The ASF_ReadObject_file_properties function in modules/demux/asf/libasf.c in the ASF Demuxer in VideoLAN VLC Media Playe
23RISCO
abrir
Exploit-DB
D-Link DIR-100 - Multiple Vulnerabilities
CVE-2013-7055webappshardware05 fev 2014
D-Link DIR-100 4.03B07 has PPTP and poe information disclosure
23RISCO
abrir
Exploit-DBVexDay Proof
Apache Struts - Developer Mode OGNL Execution (Metasploit)
CVE-2012-0394remotejava05 fev 2014
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers
60RISCO
abrir
Exploit-DB
D-Link DIR-100 - Multiple Vulnerabilities
CVE-2013-7052webappshardware05 fev 2014
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
28RISCO
abrir
Exploit-DB
D-Link DIR-100 - Multiple Vulnerabilities
CVE-2013-7054webappshardware05 fev 2014
D-Link DIR-100 4.03B07: cli.cgi XSS
23RISCO
abrir
Exploit-DBVexDay Proof
Apache Tomcat Manager - Application Upload (Authenticated) Code Execution (Metasploit)
CVE-2009-3548remotemultiple05 fev 2014
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RISCO
abrir
Exploit-DB
ownCloud 6.0.0a - Multiple Vulnerabilities
CVE-2014-1665webappsphp05 fev 2014
Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary
23RISCO
abrir
Exploit-DB
D-Link DIR-100 - Multiple Vulnerabilities
CVE-2013-7051webappshardware05 fev 2014
D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters
28RISCO
abrir
Exploit-DBVexDay Proof
Skybluecanvas CMS - Remote Code Execution (Metasploit)
CVE-2014-1683remotelinux05 fev 2014
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248
50RISCO
abrir
Exploit-DB
TopicsViewer 3.0 Beta 1 - Multiple Vulnerabilities
CVE-2014-10023webappsphp05 fev 2014
Multiple SQL injection vulnerabilities in TopicsViewer 3.0 Beta 1 allow remote attackers to execute arbitrary SQL comman
23RISCO
abrir
Exploit-DBVexDay Proof
XnView 1.92.1 - Command-Line Arguments Buffer Overflow
CVE-2008-1461remotewindows05 fev 2014
Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename arg
28RISCO
abrir
Exploit-DBVexDay Proof
Seowon Intech WiMAX SWC-9100 Router - '/cgi-bin/diagnostic.cgi?ping_ipaddr' Remote Code Execution
CVE-2013-7179remotecgi03 fev 2014
The ping functionality in cgi-bin/diagnostic.cgi on Seowon Intech SWC-9100 routers allows remote attackers to execute ar
23RISCO
abrir
Exploit-DBVexDay Proof
Seowon Intech WiMAX SWC-9100 Router - '/cgi-bin/reboot.cgi' Remote Reboot (Denial of Service)
CVE-2013-7183doscgi03 fev 2014
cgi-bin/reboot.cgi on Seowon Intech SWC-9100 routers allows remote attackers to (1) cause a denial of service (reboot) v
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.4 < 3.13.2 (Ubuntu 13.10) - 'CONFIG_X86_X32' Arbitrary Write (2)
CVE-2014-0038locallinux02 fev 2014
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.4 < 3.13.2 (Ubuntu 13.04/13.10 x64) - 'CONFIG_X86_X32=y' Local Privilege Escalation (3)
CVE-2014-0038locallinux_x86-6402 fev 2014
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RISCO
abrir
Exploit-DBVexDay Proof
MediaWiki 1.22.1 PdfHandler - Remote Code Execution
CVE-2014-1610webappsmultiple01 fev 2014
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is
50RISCO
abrir
Exploit-DB
Linux Kernel 3.4 < 3.13.2 - recvmmsg x32 compat (PoC)
CVE-2014-0038doslinux31 jan 2014
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RISCO
abrir
Exploit-DB
ManageEngine Support Center Plus 7916 - Directory Traversal
CVE-2014-100002webappsphp29 jan 2014
Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arb
50RISCO
abrir
Exploit-DB
Oracle Forms and Reports 11.1 - Arbitrary Code Execution
CVE-2012-3152CRITICALsob ataqueremotejsp29 jan 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
100RISCO
abrir
Exploit-DBVexDay Proof
PCMan FTP Server 2.07 - 'CWD' Remote Buffer Overflow
CVE-2013-4730remotewindows29 jan 2014
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISCO
abrir
Exploit-DB
Oracle Forms and Reports 11.1 - Arbitrary Code Execution
CVE-2012-3153remotejsp29 jan 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
60RISCO
abrir
Exploit-DBVexDay Proof
PCMan FTP Server 2.07 - 'ABOR' Remote Buffer Overflow
CVE-2013-4730remotewindows29 jan 2014
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISCO
abrir
Exploit-DBVexDay Proof
Eventum 2.3.4 - 'hostname' Remote Code Execution
CVE-2014-1632webappsphp28 jan 2014
htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the
28RISCO
abrir
Exploit-DBVexDay Proof
Eventum 2.3.4 - 'hostname' Remote Code Execution
CVE-2014-1631webappsphp28 jan 2014
Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
23RISCO
abrir
Exploit-DBVexDay Proof
Eventum - Insecure File Permissions
CVE-2014-1631webappsphp27 jan 2014
Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
23RISCO
abrir
Exploit-DB
Oracle Outside In MDB - File Parsing Stack Buffer Overflow (PoC)
CVE-2013-5791doswindows27 jan 2014
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.4.1 allo
23RISCO
abrir
Exploit-DB
Mozilla Thunderbird 17.0.6 - Input Validation Filter Bypass
CVE-2013-6674dosmultiple27 jan 2014
Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.1
23RISCO
abrir
Exploit-DBVexDay Proof
MP3Info 0.8.5a - Buffer Overflow
CVE-2006-2465doslinux27 jan 2014
Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. NOTE: if
23RISCO
abrir
Exploit-DB
Ammyy Admin 3.2 - Authentication Bypass
CVE-2013-5582localwindows24 jan 2014
Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assiste
23RISCO
abrir
anteriorpágina 236 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.