Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
Fortinet FortiAnalyzer - Cross-Site Request Forgery
CVE-2013-6826remotehardware12 out 2013
cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate th
23RISCO
abrir
Exploit-DBVexDay Proof
IBM Cognos Business Intelligence - XML External Entity Information Disclosure
CVE-2013-4034remotemultiple11 out 2013
IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 befor
23RISCO
abrir
Exploit-DB
ALLPlayer 5.6.2 - '.m3u' Local Buffer Overflow (PoC)
CVE-2013-7409doswindows10 out 2013
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISCO
abrir
Exploit-DBVexDay Proof
Bugzilla 4.2 - Tabular Reports Cross-Site Scripting
CVE-2013-1743webappscgi09 out 2013
Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x before 4.2.7 and 4.3.x and
23RISCO
abrir
Exploit-DBVexDay Proof
Bugzilla - 'editflagtypes.cgi' Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-1742webappscgi09 out 2013
Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11;
23RISCO
abrir
Exploit-DBVexDay Proof
davfs2 1.4.6/1.4.7 - Local Privilege Escalation
CVE-2013-4362locallinux08 out 2013
WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1
23RISCO
abrir
Exploit-DB
Apple Motion 5.0.7 - Integer Overflow
CVE-2013-6114dososx08 out 2013
Integer overflow in the OZDocument::parseElement function in Apple Motion 5.0.7 allows remote attackers to cause a denia
23RISCO
abrir
Exploit-DBVexDay Proof
HP LoadRunner - 'magentproc.exe' Remote Overflow (Metasploit)
CVE-2013-4800remotewindows08 out 2013
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown ve
50RISCO
abrir
Exploit-DBVexDay Proof
Apache Tomcat/JBoss EJBInvokerServlet / JMXInvokerServlet (RMI over HTTP) Marshalled Object - Remote Code Execution
CVE-2013-4810CRITICALsob ataqueremotephp04 out 2013
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle
100RISCO
abrir
Exploit-DBVexDay Proof
FreeBSD 9.0 - Intel SYSRET Kernel Privilege Escalation
CVE-2012-0217localfreebsd04 out 2013
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and
50RISCO
abrir
Exploit-DBVexDay Proof
HylaFAX+ 5.2.4 > 5.5.3 - Buffer Overflow
CVE-2013-5680doslinux02 out 2013
Heap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when using LDAP authentication, might allow remote
23RISCO
abrir
Exploit-DBVexDay Proof
GLPI 0.84.1 - Multiple Vulnerabilities
CVE-2013-5696webappsphp02 out 2013
inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installati
38RISCO
abrir
Exploit-DB
Gnew 2013.1 - Multiple Vulnerabilities (2)
CVE-2013-5639webappsphp02 out 2013
Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrar
23RISCO
abrir
Exploit-DB
Gnew 2013.1 - Multiple Vulnerabilities (2)
CVE-2013-7349webappsphp02 out 2013
Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (
23RISCO
abrir
Exploit-DBVexDay Proof
Micorosft Internet Explorer - SetMouseCapture Use-After-Free (Metasploit)
CVE-2013-3893HIGHsob ataqueremotewindows02 out 2013
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 throug
100RISCO
abrir
Exploit-DBVexDay Proof
PinApp Mail-SeCure 3.70 - Access Control Failure
CVE-2013-4987locallinux02 out 2013
PineApp Mail-SeCure before 3.70 allows remote authenticated users to gain privileges by leveraging console access and pr
23RISCO
abrir
Exploit-DBVexDay Proof
Alienvault Open Source SIEM (OSSIM) 3.1 - 'date_from' Multiple SQL Injections
CVE-2013-5967webappsphp02 out 2013
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier
43RISCO
abrir
Exploit-DB
Gnew 2013.1 - Multiple Vulnerabilities (2)
CVE-2013-5640webappsphp02 out 2013
Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (
23RISCO
abrir
Exploit-DB
XAMPP 1.8.1 - 'lang.php?WriteIntoLocalDisk method' Local Write Access
CVE-2013-2586webappsphp30 set 2013
XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp
23RISCO
abrir
Exploit-DB
mod_accounting Module 0.5 - Blind SQL Injection
CVE-2013-5697webappslinux30 set 2013
SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote at
23RISCO
abrir
Exploit-DB
glibc and eglibc 2.5/2.7/2.13 - Local Buffer Overflow
CVE-2013-4788locallinux30 set 2013
The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLI
28RISCO
abrir
Exploit-DB
SimpleRisk 20130915-01 - Multiple Vulnerabilities
CVE-2013-5748webappsphp30 set 2013
Cross-site request forgery (CSRF) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001
23RISCO
abrir
Exploit-DBVexDay Proof
Nodejs - 'js-yaml load()' Code Exec (Metasploit)
CVE-2013-4660localmultiple30 set 2013
The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, whic
43RISCO
abrir
Exploit-DB
Hewlett-Packard (HP) 2620 Switch Series. Edit Admin Account - Cross-Site Request Forgery
CVE-2013-6852webappshardware26 set 2013
Cross-site request forgery (CSRF) vulnerability in html/json.html on HP 2620 switches allows remote attackers to hijack
23RISCO
abrir
Exploit-DB
Good for Enterprise 2.2.2.1611 - Cross-Site Scripting
CVE-2013-5118webappshardware25 set 2013
Cross-site scripting (XSS) vulnerability in the Good for Enterprise app before 2.2.4.1659 for iOS allows remote attacker
23RISCO
abrir
Exploit-DB
X2CRM 3.4.1 - Multiple Vulnerabilities
CVE-2013-5693webappsphp25 set 2013
Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web sc
23RISCO
abrir
Exploit-DB
X2CRM 3.4.1 - Multiple Vulnerabilities
CVE-2013-5692webappsphp25 set 2013
Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and
23RISCO
abrir
Exploit-DBVexDay Proof
IBM AIX 6.1/7.1 - Local Privilege Escalation
CVE-2013-4011localaix24 set 2013
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, a
38RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Theme File Handling - Arbitrary Code Execution (MS13-071) (Metasploit)
CVE-2013-0810HIGHremotewindows23 set 2013
Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, and Windows Server 2008 SP2 allow remote a
68RISCO
abrir
Exploit-DBVexDay Proof
GLPI - 'install.php' Remote Command Execution (Metasploit)
CVE-2013-5696remotephp23 set 2013
inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installati
38RISCO
abrir
anteriorpágina 245 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.