Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.902exploits catalogados
34.597CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
CVE-2012-5961remoteunix05 fev 2013
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RISCO
abrir
Exploit-DBVexDay Proof
Opera SVG - Use-After-Free
CVE-2013-1638doswindows05 fev 2013
Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document.
23RISCO
abrir
Exploit-DBVexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
CVE-2012-5963remoteunix05 fev 2013
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RISCO
abrir
Exploit-DBVexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
CVE-2012-5960remoteunix05 fev 2013
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RISCO
abrir
Exploit-DB
Linux Kernel 2.6.32-5 (Debian 6.0.5) - '/dev/ptmx' Key Stroke Timing Local Disclosure
CVE-2013-0160locallinux05 fev 2013
The Linux kernel through 3.7.9 allows local users to obtain sensitive information about keystroke timing by using the in
23RISCO
abrir
Exploit-DBVexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
CVE-2012-5962remoteunix05 fev 2013
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RISCO
abrir
Exploit-DB
FreeBSD 9.1 - 'ftpd' Remote Denial of Service
CVE-2011-0418dosfreebsd05 fev 2013
The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions cont
23RISCO
abrir
Exploit-DBVexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
CVE-2012-5959remoteunix05 fev 2013
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RISCO
abrir
Exploit-DBVexDay Proof
Cisco Unity Express - Multiple Vulnerabilities
CVE-2013-1114webappsjsp05 fev 2013
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unity Express before 8.0 allow remote attackers to inject a
28RISCO
abrir
Exploit-DBVexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
CVE-2012-5958remoteunix05 fev 2013
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RISCO
abrir
Exploit-DBVexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
CVE-2012-5964remoteunix05 fev 2013
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RISCO
abrir
Exploit-DBVexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
CVE-2012-5965remoteunix05 fev 2013
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RISCO
abrir
Exploit-DBVexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
CVE-2012-5858remoteunix05 fev 2013
Samsung Kies Air 2.1.207051 and 2.1.210161 relies on the IP address for authentication, which allows remote man-in-the-m
23RISCO
abrir
Exploit-DBVexDay Proof
Cisco Unity Express - Multiple Vulnerabilities
CVE-2013-1120webappsjsp05 fev 2013
Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow rem
23RISCO
abrir
Exploit-DBVexDay Proof
CADA 3S CoDeSys Gateway Server - Directory Traversal (Metasploit)
CVE-2012-4705localwindows02 fev 2013
Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitr
50RISCO
abrir
Exploit-DBVexDay Proof
DataLife Engine - 'preview.php' PHP Code Injection (Metasploit)
CVE-2013-1412remotephp01 fev 2013
DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/pr
50RISCO
abrir
Exploit-DBVexDay Proof
DataLife Engine - 'preview.php' PHP Code Injection (Metasploit)
CVE-2013-7387remotephp01 fev 2013
Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions v
23RISCO
abrir
Exploit-DBVexDay Proof
Novell Groupwise Client 8.0 - Multiple Remote Code Execution Vulnerabilities
CVE-2013-0804remotemultiple31 jan 2013
The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary
28RISCO
abrir
Exploit-DBVexDay Proof
Firebird - Relational Database CNCT Group Number Buffer Overflow (Metasploit)
CVE-2013-2492localwindows31 jan 2013
Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windo
50RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Audio Player - 'playerID' Cross-Site Scripting
CVE-2013-1464webappsphp31 jan 2013
Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress al
23RISCO
abrir
Exploit-DBVexDay Proof
Ruby on Rails - JSON Processor YAML Deserialization Code Execution (Metasploit)
CVE-2013-0333remotemultiple29 jan 2013
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly
60RISCO
abrir
Exploit-DBVexDay Proof
Multiple Hunt CCTV - Information Disclosure
CVE-2013-1391remotemultiple29 jan 2013
Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Wel
60RISCO
abrir
Exploit-DB
Fortinet FortiMail 400 IBE - Multiple Vulnerabilities
CVE-2013-1471webappshardware29 jan 2013
Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMai
23RISCO
abrir
Exploit-DBVexDay Proof
DataLife Engine 9.7 - 'preview.php' PHP Code Injection
CVE-2013-7387webappsphp28 jan 2013
Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions v
23RISCO
abrir
Exploit-DB
Microsoft Internet Explorer 8/9 - Steal Any Cookie
CVE-2013-1451webappswindows28 jan 2013
Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in
28RISCO
abrir
Exploit-DBVexDay Proof
DataLife Engine 9.7 - 'preview.php' PHP Code Injection
CVE-2013-1412webappsphp28 jan 2013
DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/pr
50RISCO
abrir
Exploit-DB
ImageCMS 4.0.0b - Multiple Vulnerabilities
CVE-2012-6290webappsphp25 jan 2013
SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL c
23RISCO
abrir
Exploit-DBVexDay Proof
Novell eDirectory 8 - Remote Buffer Overflow (Metasploit)
CVE-2012-0432remotemultiple24 jan 2013
Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote at
50RISCO
abrir
Exploit-DBVexDay Proof
Java Applet - Method Handle Remote Code Execution (Metasploit)
CVE-2012-5088remotemultiple24 jan 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
60RISCO
abrir
Exploit-DBVexDay Proof
SonicWALL Gms 6 - Arbitrary File Upload (Metasploit)
CVE-2013-1359remotemultiple24 jan 2013
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5
60RISCO
abrir
anteriorpágina 265 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.