Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.557exploits catalogados
37.313CVEs com exploração pública
24.695testados em laboratório
24.478 exploits
Exploit-DBVexDay Proof
Kingsoft Office Writer 2012 8.1.0.3385 - '.wps' Local Buffer Overflow (SEH)
CVE-2013-3934localwindows30 nov 2013
Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allow
23RISCO
abrir
Exploit-DB
Scientific-Atlanta_ Inc. DPR2320R2 - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2013-7043webappshardware30 nov 2013
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader - ASLR + DEP Bypass with Sandbox Bypass
CVE-2013-0640HIGHsob ataquelocalwindows28 nov 2013
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute
93RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CardSpaceClaimCollection ActiveX Integer Underflow (MS13-090) (Metasploit)
CVE-2013-3918HIGHsob ataqueremotewindows27 nov 2013
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - COALineDashStyleArray Unsafe Memory Access (MS12-022) (Metasploit)
CVE-2013-0074HIGHsob ataqueransomwareremotewindows27 nov 2013
Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML obj
100RISCO
abrir
Exploit-DBVexDay Proof
Apache Roller - OGNL Injection (Metasploit)
CVE-2013-4212remotejava27 nov 2013
Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - COALineDashStyleArray Unsafe Memory Access (MS12-022) (Metasploit)
CVE-2012-0016remotewindows27 nov 2013
Untrusted search path vulnerability in Microsoft Expression Design; Expression Design SP1; and Expression Design 2, 3, a
28RISCO
abrir
Exploit-DBVexDay Proof
DesktopCentral AgentLogUpload - Arbitrary File Upload (Metasploit)
CVE-2013-7390remotewindows25 nov 2013
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before buil
60RISCO
abrir
Exploit-DBVexDay Proof
Netgear ReadyNAS - Perl Code Evaluation (Metasploit)
CVE-2013-2751remotehardware25 nov 2013
Eval injection vulnerability in frontview/lib/np_handler.pl in the FrontView web interface in NETGEAR ReadyNAS RAIDiator
60RISCO
abrir
Exploit-DBVexDay Proof
DesktopCentral AgentLogUpload - Arbitrary File Upload (Metasploit)
CVE-2014-5007remotewindows25 nov 2013
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop
35RISCO
abrir
Exploit-DB
ALLPlayer 5.7 - '.m3u' UNICODE Buffer Overflow (SEH)
CVE-2013-7409localwindows24 nov 2013
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISCO
abrir
Exploit-DBVexDay Proof
MyBB Ajaxfs 2 Plugin - SQL Injection
CVE-2013-6936webappsphp24 nov 2013
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletin
23RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Blue Wrench Video Widget - Cross-Site Request Forgery
CVE-2013-6797webappsphp23 nov 2013
Cross-site request forgery (CSRF) vulnerability in bluewrench-video-widget.php in the Blue Wrench Video Widget plugin be
23RISCO
abrir
Exploit-DBVexDay Proof
Thomson Reuters Velocity Analytics - Remote Code Injection
CVE-2013-5912remotehardware22 nov 2013
VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute
35RISCO
abrir
Exploit-DBVexDay Proof
Light Alloy 4.7.3 - '.m3u' Local Buffer Overflow (SEH Unicode)
CVE-2013-6874localwindows22 nov 2013
Stack-based buffer overflow in Vortex Light Alloy before 4.7.4 allows remote attackers to execute arbitrary code via a l
23RISCO
abrir
Exploit-DBVexDay Proof
PineApp MailSecure - Remote Command Execution
CVE-2013-6831remotelinux20 nov 2013
PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict
23RISCO
abrir
Exploit-DBVexDay Proof
PineApp MailSecure - Remote Command Execution
CVE-2013-6829remotelinux20 nov 2013
admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacha
60RISCO
abrir
Exploit-DBVexDay Proof
PineApp MailSecure - Remote Command Execution
CVE-2013-6830remotelinux20 nov 2013
admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attacker
23RISCO
abrir
Exploit-DBVexDay Proof
DeepOfix SMTP Server 3.3 - Authentication Bypass
CVE-2013-6796remotelinux19 nov 2013
The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, whic
23RISCO
abrir
Exploit-DBVexDay Proof
Nginx 1.1.17 - URI Processing SecURIty Bypass
CVE-2013-4547remotemultiple19 nov 2013
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescap
35RISCO
abrir
Exploit-DB
Ruckus Wireless Zoneflex 2942 Wireless Access Point - Authentication Bypass
CVE-2013-5030webappshardware19 nov 2013
Ruckus Wireless Zoneflex 2942 devices with firmware 9.6.0.0.267 allow remote attackers to bypass authentication, and sub
23RISCO
abrir
Exploit-DB
ManageEngine Desktop Central 8.0.0 build < 80293 - Arbitrary File Upload
CVE-2013-7390webappsjsp18 nov 2013
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before buil
60RISCO
abrir
Exploit-DB
ManageEngine Desktop Central 8.0.0 build < 80293 - Arbitrary File Upload
CVE-2014-5007webappsjsp18 nov 2013
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop
35RISCO
abrir
Exploit-DB
Dahua DVR 2.608.0000.0/2.608.GV00.0 - Authentication Bypass (Metasploit)
CVE-2013-3612webappshardware18 nov 2013
Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which
28RISCO
abrir
Exploit-DB
Dahua DVR 2.608.0000.0/2.608.GV00.0 - Authentication Bypass (Metasploit)
CVE-2013-3615webappshardware18 nov 2013
Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent
23RISCO
abrir
Exploit-DB
Avira Secure Backup 1.0.0.1 Build 3616 - '.reg' Buffer Overflow
CVE-2013-6356doswindows18 nov 2013
20RISCO
abrir
Exploit-DB
Dahua DVR 2.608.0000.0/2.608.GV00.0 - Authentication Bypass (Metasploit)
CVE-2013-3614webappshardware18 nov 2013
Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to o
23RISCO
abrir
Exploit-DB
Dahua DVR 2.608.0000.0/2.608.GV00.0 - Authentication Bypass (Metasploit)
CVE-2013-6117webappshardware18 nov 2013
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RISCO
abrir
Exploit-DB
LiveZilla 5.0.1.4 - Remote Code Execution
CVE-2013-6225webappsphp18 nov 2013
LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability
28RISCO
abrir
Exploit-DBVexDay Proof
Supermicro Onboard IPMI - 'close_window.cgi' Remote Buffer Overflow (Metasploit)
CVE-2013-3623remotehardware18 nov 2013
Multiple stack-based buffer overflows in cgi/close_window.cgi in the web interface in the Intelligent Platform Managemen
60RISCO
abrir
anteriorpágina 243 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.