Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.583exploits catalogados
34.507CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
Cisco Unified Communications Manager - TFTP Service
CVE-2013-7030HIGHlocalhardware12 dez 2013
The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sens
41RISCO
abrir
Exploit-DBVexDay Proof
HP LoadRunner EmulationAdmin - Web Service Directory Traversal (Metasploit)
CVE-2013-4837remotewindows11 dez 2013
Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arb
50RISCO
abrir
Exploit-DBVexDay Proof
Adobe ColdFusion 9 - Administrative Authentication Bypass (Metasploit)
CVE-2013-0632CRITICALsob ataqueremotemultiple11 dez 2013
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and pos
100RISCO
abrir
Exploit-DBVexDay Proof
IcoFX 2.5.0.0 - '.ico' Buffer Overflow (PoC)
CVE-2013-4988doswindows11 dez 2013
Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCoun
50RISCO
abrir
Exploit-DBVexDay Proof
eduTrac - 'showmask' Directory Traversal
CVE-2013-7097webappsphp11 dez 2013
Directory traversal vulnerability in 7 Media Web Solutions eduTrac before 1.1.2 allows remote attackers to read arbitrar
23RISCO
abrir
Exploit-DBVexDay Proof
vBulletin 5 - 'index.php/ajax/api/reputation/vote?nodeid' SQL Injection (Metasploit)
CVE-2013-3522remotephp11 dez 2013
SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier
43RISCO
abrir
Exploit-DB
EMC Data Protection Advisor DPA Illuminator - EJBInvokerServlet Remote Code Execution
CVE-2012-0874remotewindows11 dez 2013
The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP)
28RISCO
abrir
Exploit-DBVexDay Proof
eFront 3.6.14 (build 18012) - Multiple Persistent Cross-Site Scripting Vulnerabilities
CVE-2013-7194webappsphp11 dez 2013
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote
23RISCO
abrir
Exploit-DBVexDay Proof
RedHat Piranha - Remote Security Bypass
CVE-2013-6492remotelinux11 dez 2013
The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attac
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.0.5 - 'ath9k_htc_set_bssid_mask()' Information Disclosure
CVE-2013-4579remotelinux10 dez 2013
The ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12
28RISCO
abrir
Exploit-DBVexDay Proof
GOM Player 2.2.53.5169 - '.reg' Local Buffer Overflow (SEH)
CVE-2013-6356localwindows09 dez 2013
20RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Download Manager Free & Pro 2.5.8 - Persistent Cross-Site Scripting
CVE-2013-7319webappsphp08 dez 2013
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attacke
23RISCO
abrir
Exploit-DBVexDay Proof
Enorth Webpublisher CMS - 'thisday' SQL Injection
CVE-2013-6985webappsphp06 dez 2013
SQL injection vulnerability in m_worklog/log_searchday.jsp in Enorth Webpublisher CMS, possibly 5.0 and earlier, allows
23RISCO
abrir
Exploit-DB
D-Link DSR Router Series - Remote Command Execution
CVE-2013-5945webappshardware06 dez 2013
Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.0
23RISCO
abrir
Exploit-DBVexDay Proof
Zimbra 2009-2013 - Local File Inclusion
CVE-2013-7091webappslinux06 dez 2013
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RISCO
abrir
Exploit-DB
SonicWALL Gms 7.x - Filter Bypass / Persistent
CVE-2013-7025webappsjsp05 dez 2013
Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell So
23RISCO
abrir
Exploit-DBVexDay Proof
Steinberg MyMp3PRO 5.0 - Local Buffer Overflow (SEH) (DEP Bypass + ROP)
CVE-2013-7186localwindows04 dez 2013
Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long
28RISCO
abrir
Exploit-DBVexDay Proof
MySQL 5.0.x - IF Query Handling Remote Denial of Service
CVE-2007-2583doslinux04 dez 2013
The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-depen
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft - Tagged Image File Format '.TIFF' Integer Overflow (Metasploit)
CVE-2013-3906HIGHsob ataqueremotewindows03 dez 2013
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compati
100RISCO
abrir
Exploit-DBVexDay Proof
Cisco Prime Data Center Network Manager - Arbitrary File Upload (Metasploit)
CVE-2013-5486remotejava03 dez 2013
Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager
60RISCO
abrir
Exploit-DBVexDay Proof
Chamilo Lms 1.9.6 - 'profile.php?password' SQL Injection
CVE-2013-6787webappsphp03 dez 2013
SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlie
23RISCO
abrir
Exploit-DB
Dokeos 2.2 RC2 - 'index.php?language' SQL Injection
CVE-2013-6341webappsphp03 dez 2013
SQL injection vulnerability in Dokeos 2.2 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'NDPROXY' SYSTEM Privilege Escalation (MS14-002)
CVE-2013-5065HIGHsob ataquelocalwindows03 dez 2013
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges
98RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Formcraft - SQL Injection
CVE-2013-7187webappsphp02 dez 2013
SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers
23RISCO
abrir
Exploit-DB
TVT TD-2308SS-B DVR - Directory Traversal
CVE-2013-6023webappshardware01 dez 2013
Directory traversal vulnerability in the TVT TD-2308SS-B DVR with firmware 3.2.0.P-3520A-00 and earlier allows remote at
28RISCO
abrir
Exploit-DBVexDay Proof
Kingsoft Office Writer 2012 8.1.0.3385 - '.wps' Local Buffer Overflow (SEH)
CVE-2013-3934localwindows30 nov 2013
Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allow
23RISCO
abrir
Exploit-DB
Scientific-Atlanta_ Inc. DPR2320R2 - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2013-7043webappshardware30 nov 2013
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader - ASLR + DEP Bypass with Sandbox Bypass
CVE-2013-0640HIGHsob ataquelocalwindows28 nov 2013
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute
93RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - COALineDashStyleArray Unsafe Memory Access (MS12-022) (Metasploit)
CVE-2013-0074HIGHsob ataqueransomwareremotewindows27 nov 2013
Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML obj
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CardSpaceClaimCollection ActiveX Integer Underflow (MS13-090) (Metasploit)
CVE-2013-3918HIGHsob ataqueremotewindows27 nov 2013
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server
100RISCO
abrir
anteriorpágina 241 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.