Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
Top Games Script 1.2 - 'play.php?gid' SQL Injection
CVE-2013-4953webappsphp24 jun 2013
SQL injection vulnerability in play.php in Top Games Script 1.2 allows remote attackers to execute arbitrary SQL command
23RISCO
abrir
Exploit-DB
Linksys X3000 1.0.03 build 001 - Multiple Vulnerabilities
CVE-2013-3307HIGHwebappshardware24 jun 2013
Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command inj
53RISCO
abrir
Exploit-DB
Alienvault Open Source SIEM (OSSIM) 4.1 - Multiple SQL Injection Vulnerabilities
CVE-2013-5321webappsphp24 jun 2013
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remot
23RISCO
abrir
Exploit-DB
GLPI 0.83.8 - Multiple Vulnerabilities
CVE-2013-2226webappsphp21 jun 2013
Multiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir
Exploit-DB
GLPI 0.83.8 - Multiple Vulnerabilities
CVE-2013-2227webappsphp21 jun 2013
GLPI 0.83.7 has Local File Inclusion in common.tabs.php.
28RISCO
abrir
Exploit-DBVexDay Proof
FreeBSD 9.0 < 9.1 - 'mmap/ptrace' Local Privilege Escalation
CVE-2013-2171localfreebsd21 jun 2013
The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEAS
38RISCO
abrir
Exploit-DBVexDay Proof
Winamp 5.12 - '.m3u' Local Stack Buffer Overflow
CVE-2006-0720localwindows17 jun 2013
Stack-based buffer overflow in Nullsoft Winamp 5.12 and 5.13 allows user-assisted attackers to cause a denial of service
28RISCO
abrir
Exploit-DBVexDay Proof
Easy LAN Folder Share 3.2.0.100 - Buffer Overflow
CVE-2013-6079doswindows14 jun 2013
Buffer overflow in MostGear Soft Easy LAN Folder Share 3.2.0.100 allows local users to cause a denial of service (applic
23RISCO
abrir
Exploit-DBVexDay Proof
Monkey HTTP Daemon Mandril Security Plugin - Security Bypass
CVE-2013-2182remotemultiple14 jun 2013
The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restri
23RISCO
abrir
Exploit-DB
Airlive IP Cameras - Multiple Vulnerabilities
CVE-2013-3687webappshardware13 jun 2013
AirLive POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD, and possibly other camera models use cl
23RISCO
abrir
Exploit-DB
Airlive IP Cameras - Multiple Vulnerabilities
CVE-2013-3541webappshardware13 jun 2013
Directory traversal vulnerability in cgi-bin/admin/fileread in AirLive WL2600CAM and possibly other camera models allows
23RISCO
abrir
Exploit-DB
Airlive IP Cameras - Multiple Vulnerabilities
CVE-2013-3686webappshardware13 jun 2013
cgi-bin/operator/param in AirLive WL2600CAM and possibly other camera models allows remote attackers to obtain the admin
28RISCO
abrir
Exploit-DB
AXIS Media Control 6.2.10.11 - Unsafe ActiveX Method
CVE-2013-3543doswindows13 jun 2013
The AXIS Media Control (AMC) ActiveX control (AxisMediaControlEmb.dll) 6.2.10.11 for AXIS network cameras allows remote
23RISCO
abrir
Exploit-DB
Airlive IP Cameras - Multiple Vulnerabilities
CVE-2013-3540webappshardware13 jun 2013
Cross-site request forgery (CSRF) vulnerability in cgi-bin/admin/usrgrp.cgi in AirLive POE2600HD, POE250HD, POE200HD, OD
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - COALineDashStyleArray Integer Overflow (MS13-009) (Metasploit)
CVE-2013-2551HIGHsob ataqueransomwareremotewindows13 jun 2013
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary co
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - COALineDashStyleArray Integer Overflow (MS13-009) (Metasploit)
CVE-2013-1298remotewindows13 jun 2013
20RISCO
abrir
Exploit-DB
Airlive IP Cameras - Multiple Vulnerabilities
CVE-2013-3691webappshardware13 jun 2013
AirLive POE-2600HD allows remote attackers to cause a denial of service (device reset) via a long URL.
23RISCO
abrir
Exploit-DBVexDay Proof
Grandstream Multiple IP Cameras - Cross-Site Request Forgery
CVE-2013-3963remotehardware12 jun 2013
Cross-site request forgery (CSRF) vulnerability in goform/usermanage in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD
23RISCO
abrir
Exploit-DBVexDay Proof
Ubiquiti airCam RTSP Service 1.1.5 - Buffer Overflow (PoC)
CVE-2013-1606doshardware12 jun 2013
Buffer overflow in the ubnt-streamer RTSP service on the Ubiquiti UBNT AirCam with airVision firmware before 1.1.6 allow
28RISCO
abrir
Exploit-DBVexDay Proof
Sony CH / DH Series IP Cameras - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2013-3539remotehardware12 jun 2013
Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH2
23RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin NextGEN Gallery - 'upload.php' Arbitrary File Upload
CVE-2013-3684webappsphp12 jun 2013
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
28RISCO
abrir
Exploit-DBVexDay Proof
Brickcom Multiple IP Cameras - Cross-Site Request Forgery
CVE-2013-3690remotehardware12 jun 2013
Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100A
28RISCO
abrir
Exploit-DBVexDay Proof
Weathermap 0.97c - 'mapname' Local File Inclusion
CVE-2013-3739webappsphp11 jun 2013
Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel < 3.8.9 (x86-64) - 'perf_swevent_init' Local Privilege Escalation (2)
CVE-2013-2094HIGHsob ataquelocallinux_x86-6411 jun 2013
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RISCO
abrir
Exploit-DB
Simple PHP Agenda 2.2.8 - 'edit_event.php?eventid' SQL Injection
CVE-2013-3961webappsphp11 jun 2013
SQL injection vulnerability in edit_event.php in Simple PHP Agenda before 2.2.9 allows remote authenticated users to exe
23RISCO
abrir
Exploit-DB
Java - Web Start Double Quote Injection Remote Code Execution (Metasploit)
CVE-2012-1533remotemultiple11 jun 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and
50RISCO
abrir
Exploit-DBVexDay Proof
Java Applet - Driver Manager Privileged 'toString()' Remote Code Execution (Metasploit)
CVE-2013-1488remotemultiple11 jun 2013
The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remo
60RISCO
abrir
Exploit-DB
Cisco ASA < 8.4.4.6 < 8.2.5.32 - Ethernet Information Leak
CVE-2003-0001doshardware10 jun 2013
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote att
45RISCO
abrir
Exploit-DBVexDay Proof
HP Insight Diagnostics - Remote Code Injection
CVE-2013-3574webappsphp10 jun 2013
Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.
23RISCO
abrir
Exploit-DBVexDay Proof
HP Insight Diagnostics 9.4.0.4710 - Local File Inclusion
CVE-2013-3575webappsphp10 jun 2013
hpdiags/frontend2/help/pageview.php in HP Insight Diagnostics 9.4.0.4710 does not properly restrict PHP include or requi
23RISCO
abrir
anteriorpágina 255 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.