Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
HP Intelligent Management Center - Arbitrary File Upload (Metasploit)
CVE-2012-5201remotewindows26 mar 2013
Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Netw
50RISCO
abrir
Exploit-DBVexDay Proof
vBulletin 5.0.0 Beta 11 < 5.0.0 Beta 28 - SQL Injection
CVE-2013-3522webappsphp25 mar 2013
SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier
43RISCO
abrir
Exploit-DBVexDay Proof
Atmail WebMail - 'INBOX.Trash?mailId' Reflected Cross-Site Scripting
CVE-2013-6229webappsphp25 mar 2013
Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote attackers to inject arbi
23RISCO
abrir
Exploit-DBVexDay Proof
Atmail WebMail - 'searchResultsTab5?filter' Reflected Cross-Site Scripting
CVE-2013-6229webappsphp25 mar 2013
Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote attackers to inject arbi
23RISCO
abrir
Exploit-DBVexDay Proof
Atmail WebMail - Message Attachment File Name Reflected Cross-Site Scripting
CVE-2013-6229webappsphp25 mar 2013
Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote attackers to inject arbi
23RISCO
abrir
Exploit-DBVexDay Proof
Mitsubishi MX ActiveX Component 3 - 'ActUWzd.dll' 'WzTitle' Remote Heap Spray
CVE-2013-3075remotewindows25 mar 2013
Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3, as distributed in Citect CitectFacilities
28RISCO
abrir
Exploit-DBVexDay Proof
KingView - Log File Parsing Buffer Overflow (Metasploit)
CVE-2012-4711remotewindows25 mar 2013
Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView
50RISCO
abrir
Exploit-DBVexDay Proof
Mutiny - Remote Command Execution (Metasploit)
CVE-2012-3001remotelinux25 mar 2013
Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, re
43RISCO
abrir
Exploit-DBVexDay Proof
OpenCart 1.5.5.1 - 'FileManager.php' Directory Traversal Arbitrary File Access
CVE-2013-1891webappsphp22 mar 2013
In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.
23RISCO
abrir
Exploit-DBVexDay Proof
Cool PDF Image Stream - Remote Buffer Overflow (Metasploit)
CVE-2012-4914remotewindows22 mar 2013
Stack-based buffer overflow in the reader in CoolPDF 3.0.2.256 allows remote attackers to execute arbitrary code via a P
43RISCO
abrir
Exploit-DB
GnuTLS libgnutls - Double-Free Certificate List Parsing Remote Denial of Service
CVE-2012-1663doslinux22 mar 2013
Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (app
23RISCO
abrir
Exploit-DBVexDay Proof
Apache Struts - 'ParametersInterceptor' Remote Code Execution (Metasploit)
CVE-2011-3923remotemultiple22 mar 2013
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class an
60RISCO
abrir
Exploit-DB
ViewGit 0.0.6 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-2294webappsphp19 mar 2013
Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbi
23RISCO
abrir
Exploit-DB
Verizon Fios Router MI424WR-GEN3I - Cross-Site Request Forgery
CVE-2013-0126webappshardware19 mar 2013
Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I rout
23RISCO
abrir
Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
CVE-2013-1646webappsjava15 mar 2013
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and
23RISCO
abrir
Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
CVE-2013-1645webappsjava15 mar 2013
Directory traversal vulnerability in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev
23RISCO
abrir
Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
CVE-2013-1647webappsjava15 mar 2013
Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 befo
23RISCO
abrir
Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
CVE-2013-1648webappsjava15 mar 2013
The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does
23RISCO
abrir
Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
CVE-2013-1651webappsjava15 mar 2013
OXUpdater in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not verify X.509
23RISCO
abrir
Exploit-DB
Cisco Video Surveillance Operations Manager 6.3.2 - Multiple Vulnerabilities
CVE-2013-3431webappsjsp15 mar 2013
Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages,
23RISCO
abrir
Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
CVE-2013-1650webappsjava15 mar 2013
Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses weak permissions (group "othe
23RISCO
abrir
Exploit-DB
WordPress Plugin LeagueManager 3.8 - SQL Injection
CVE-2013-1852webappsphp15 mar 2013
SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote at
23RISCO
abrir
Exploit-DB
Cisco Video Surveillance Operations Manager 6.3.2 - Multiple Vulnerabilities
CVE-2013-3429webappsjsp15 mar 2013
Multiple directory traversal vulnerabilities in Cisco Video Surveillance Manager (VSM) before 7.0.0 allow remote attacke
28RISCO
abrir
Exploit-DB
Cisco Video Surveillance Operations Manager 6.3.2 - Multiple Vulnerabilities
CVE-2013-3430webappsjsp15 mar 2013
Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive,
23RISCO
abrir
Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
CVE-2013-1649webappsjava15 mar 2013
Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses the crypt and SHA-1 algorithm
23RISCO
abrir
Exploit-DB
Linux Kernel 3.7.10 (Ubuntu 12.10 x64) - 'sock_diag_handlers' Local Privilege Escalation (2)
CVE-2013-1763locallinux_x86-6413 mar 2013
Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows l
23RISCO
abrir
Exploit-DB
Apache Rave 0.11 < 0.20 - User Information Disclosure
CVE-2013-1814webappsmultiple13 mar 2013
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain s
60RISCO
abrir
Exploit-DBVexDay Proof
Honeywell HSC Remote Deployer - ActiveX Remote Code Execution (Metasploit)
CVE-2013-0108remotewindows13 mar 2013
An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R
43RISCO
abrir
Exploit-DB
Linux Kernel - 'SCTP_GET_ASSOC_STATS()' Stack Buffer Overflow (PoC)
CVE-2013-1828doslinux13 mar 2013
The sctp_getsockopt_assoc_stats function in net/sctp/socket.c in the Linux kernel before 3.8.4 does not validate a size
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Silverlight - ScriptObject Unsafe Memory Access (MS13-022/MS13-087) (Metasploit)
CVE-2013-3896MEDIUMsob ataquelocalwindows12 mar 2013
Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, wh
90RISCO
abrir
anteriorpágina 262 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.